Live data from Hacker News

Tally of Cyber Extortion Attacks on Tech Companies Grows

bits.blogs.nytimes.com

21–30 of 45 posts

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#21
post #2

I posted this because I found it of particular interest that the blackmailers ask for payment in Bitcoin. It makes you think if Bitcoin is turning into a giant example of "be careful what you wish for". We have exchange after exchange get hacked and legit Bitcoin users losing their money, and now Bitcoin enables extortion schemes that couldn't work so effortlessly before. Where is this going?

Bitcoin is only pseudoanonymous. At some point, the 'bad actor' has to access 'legitimate' banking institutions to exchange the Bitcoins to fiat and that is the weakest link. It requires reporting to relevant tax or other authorities based on arbitrary (and secret) amounts, but targets money laundering, drug trade, gamlbing, etc.

I suppose if I had to throw a potentially disruptive idea out there, you could create a database of 'blacklisted addresses.' Let's say when Bitlocker came out, you entered that address into a database and it was verified as being associated with this scam, well it is trivial to track those coins between addresses and every address it enters is blacklisted until it enters a mixer or exchange, at which point you have a potentially complicit corporation that you could actually target with the subpoena or other legal action for discovery of IPs, login, etc.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#22

i dont get it...why not just switch your dns to cloudflare or a similiar service and run under their protection?

Because centralization is bad for the internet. CloudFlare unwraps every single SSL connection, they see every cookie, they can modify every response. It is a goldmine for a bad actor to compromise.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#24
post #21
post #2

I posted this because I found it of particular interest that the blackmailers ask for payment in Bitcoin. It makes you think if Bitcoin is turning into a giant example of "be careful what you wish for". We have exchange after exchange get hacked and legit Bitcoin users losing their money, and now Bitcoin enables extortion schemes that couldn't work so effortlessly before. Where is this going?

Bitcoin is only pseudoanonymous. At some point, the 'bad actor' has to access 'legitimate' banking institutions to exchange the Bitcoins to fiat and that is the weakest link. It requires reporting to relevant tax or other authorities based on arbitrary (and secret) amounts, but targets money laundering, drug trade, gamlbing, etc. I suppose if I had to throw a potentially disruptive idea out there, you could create a…

People have suggested this before. A bad actor then just takes 100 illicit bitcoins and sprinkles them in random amounts across many addresses, 11 to himself at another address, 6 to a non-profit, and 14 to you. You are now indistinguishable from the bad guy.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#25
post #8

DDoS attacks like this wouldn't be so easy if governments actively fixed backdoors in hardware and software instead of creating and stockpiling them. Much harder to build a botnet if there are fewer vulnerable systems to recruit via exploits.

So the governments are responsible for every bug now? I'm not so quick to absolve guilt from shitty development. There are many developers that take a lot of shortcuts, with hardcoded passwords and the like.

If we were talking a handful of bugs, your argument would make sense. But we're talking about tens of thousands.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#26
post #18

Earlier quoted context omitted.

You mean like straight cash has been up until now?

Yup. Except straight cash still needs someone to physically collect it which leaves a point of failure in the crime and a good place for authorities to catch the bad guys. Bitcoin removes that.

But gives another ways to track the money that was paid. It's a matter of authorities catching up with the technology.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#27

Anyone want to start a registry of threatening bitcoin addresses, so we can prevent funds from these transactions from being used? (aside from paying other organized criminals)

Isn't that difficult to enforce, unless you also blacklist the public mixers? It's easy to launder moderate amounts of Bitcoins through the mixers, after which blacklisting the original wallets would no longer impede the money being spent. Though if the major mixers were willing to go along with such a blacklist it'd get considerably more effective.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#28
post #8

DDoS attacks like this wouldn't be so easy if governments actively fixed backdoors in hardware and software instead of creating and stockpiling them. Much harder to build a botnet if there are fewer vulnerable systems to recruit via exploits.

So the governments are responsible for every bug now? I'm not so quick to absolve guilt from shitty development. There are many developers that take a lot of shortcuts, with hardcoded passwords and the like. If we were talking a handful of bugs, your argument would make sense. But we're talking about tens of thousands.

>>> There are many developers that take a lot of shortcuts, with hardcoded passwords and the like.

This.

Last year worked at a huge, multinational,privately held company. After being at my job less than two days, I found out they store all of their server passwords in plaintext, on the server, together, in one file.

It took me about an hour to compose myself. It was like having a dream where you come to work and you suddenly realize you left your pants at home.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#29
post #9

Earlier quoted context omitted.

> DDoS attacks like this wouldn't be so easy if governments actively fixed backdoors in hardware and software instead of creating and stockpiling them. The same thing keeping government from regulating the Internet is the same thing keeping government from simultaneously fixing every flaw in every router, switch, and TCP/IP stack. Stockpiling has nothing to do with it by itself, as they are stockpiling individual num…

> NSA didn't even know about Heartbleed Source?

http://icontherecord.tumblr.com/post/82416436703/statement-o...

But also, straight from the mouth of a USCYBERCOM strategist speaking to our class the other week.

And also, just plain logic. I pointed out here on HN even before the ODNI released the statement I linked above that Heartbleed is far more damaging to the USG itself than any intel value NSA could have hoped to achieve from it.

With the other vulns NSA would have stockpiled they don't need Heartbleed, and leaving Heartbleed open would have hurt a lot of USG (and just as importantly, private US) infrastructure, so even going by crazy USG logic the right thing to do would have been to disclose it, just as NSA has fixed other open source security flaws over the years.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#30

Anyone want to start a registry of threatening bitcoin addresses, so we can prevent funds from these transactions from being used? (aside from paying other organized criminals)

Isn't that difficult to enforce, unless you also blacklist the public mixers? It's easy to launder moderate amounts of Bitcoins through the mixers, after which blacklisting the original wallets would no longer impede the money being spent. Though if the major mixers were willing to go along with such a blacklist it'd get considerably more effective.

You can track the amount through the transaction logs though, and mixers don't want to get stuck with bitcoins which will eventually be invalidated by other parts of the ecosystem.

Not a perfect idea at this point though, it'd require considerable organization to get this done, certainly better than throwing away Bitcoin or waiting for it to become criminalized. IMHO

Post reply on HN