I think that the people here speculating about the FBI and private keys are greatly overestimating the competency of these hackers. While it's possible this it he FBI flexing some muscle that they have a backdoor into bitcoin's hashing algorithm, what seems much more likely (to me) is: There is a more sophisticated hacking group which created this particular ransomware package. They sell this ransomware package to le…
I mean we know the hack wasn’t sophisticated at all. It seems to me the hackers are opportunists, scanning for vulnerabilities and weak VPNs. People are confusing grunt work with sophistication. They would’ve used ransomware against any target that they breached that they thought could pay. Too young or too stupid to think through the consequences. Thread below indicates what happened is they were incredibly naive an…
DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
251–260 of 296 posts
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#252Earlier quoted context omitted.
A private key is not needed if the funds are on an exchange. Apparently there is a warrant to seize property on Northern California so I guess it might be Coinbase. And yeah... if the crackers sent the funds to an exchange they were comically dumb.
The press release specifically mentions that the cryptocurrency was seized through FBI having posession of the private key.
for which the FBI has the “private key,” or the rough equivalent of a password needed to access assets accessible from the specific Bitcoin address.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#253Earlier quoted context omitted.
The US Judicial system which tries to flex its "unlimited" reach.
„ If sanctioned the US government could almost certainly 51% attack any given crypto and redirect funds to whoever they want” 51% attacks don’t allow for withdrawing funds from an account - only for rolling back recent transactions
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#254Earlier quoted context omitted.
If the private key was hashed, and they only had the hash, then they could not crack it. Hashing is not the same as encryption.
Second reply: I saw that you work in applied cryptography and blockchain technology @ Cryptography Services (NCC Group) so you might be familiar with somewhat Grey Hat russian forum InsidePro; back in the day I saw people there requesting Bitcoin private key recovery for their lost private keys or if they encrypted and/or hashed wallet private keys and couldn't recover plaintext anymore and I can say that amateur cra…
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#255Earlier quoted context omitted.
Our "respected authorities" have been "predicting" this since last year [1]. [1] https://www.youtube.com/watch?app=desktop&v=0DKRvS-C04o
I love viewing comment histories of people who write posts like the above. They're always fun.
You might find it interesting to know that, irl, I never talk about anything remotely conspiratorial. I live life like a normal person, and talk like this on forums as a hedge.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#256Earlier quoted context omitted.
If the FBI has broke any of Secp256k1, SHA256, or RIPE160, (they have not) they’re not going to blow that on a $3M haul.
They just mention they had access to the private key of the account so that makes sense how they got access. If FBI has broken SHA256, then Bitcoin is a done deal. I hope they share how they got access to the private key.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#257Earlier quoted context omitted.
Completely agree but it could be perceived as a show of strength.
Still stupid. As soon as some entity reveals they have the power to crack one of these algorithms, everyone scrambles to migrate to something orders of magnitude harder. It's a weapon you'd only be able to use for maybe a few weeks or months before all the worthwhile targets immunize themselves against you. We already have quantum safe asymmetric cryptography, just no incentive to move fast to deploy it.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#258Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#259Earlier quoted context omitted.
The connections need to pass through the US just once in order to give the US a chance to attack it. Since they created the internet, they have field advantage. It's almost impossible not to use a US based provider, it goes as deep as ipv4 distribution.
> The connections need to pass through the US just once in order to give the US a chance to attack it. Less than once if the US were, purely hypothetically , to have a well-funded foreign sigint operation that might cooperate with domestic law enforcement on priority issues.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#260The most interesting and unknown question is how the DOJ/FBI came to be in possession of the private key.
I don't understand why so many people are jumping to the conclusion that the FBI broke sha-256. Theres so many other lower hanging fruit posibilities... 1: they served the server provider with a warrant they provided physical access. 2: their server infra was running vulnerable code for another service. 3. weak passwords / weak security in general 4. they cut a deal with the upstream ransomware providers and were pro…
A very odd conclusion because that's not the crypto you need to break to steal some coins.