Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

261–270 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#261
post #128

Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…

Yeah, same issue with Nobel inventing the dynamite. Just because some people are going to use it for unethical purposes, it doesn't mean that we have to stop the advance of science and technology. Besides, it seems that Bitcoin was inevitable, the internet needs its own decentralized currency.

> The internet needs its own decentralized currency

Why?

Re: US travel firm $4.5M ransom negotiation open chat

#262
post #205

Earlier quoted context omitted.

1. Passing keys around risks the original sender (or anyone listening in) grabbing the money after 'payment', and voids any guarantees Bitcoin etc. might be able to make - the transaction isn't even listed on the chain. This would turn a 'trustless blockchain' to a 'non-blockchain relying on trust'. Assuming this transition can even be done (what would be the point of cryptocurrency in that case?), the result would b…

That implementation of offline transactions is a poor one, so the rebuttal would be too, but the reality is that bitcoin can work with offline transactions. You can create the transaction object and hand that over. Transferrable literally as a file. Instead of having over notes with the private key on them. Eventually that transaction will need to be settled onchain. This can work in a world without a familiar lookin…

Well, that was a simple scenario with a simple answer. But there are many other things powerful adversaries could do. For example, what happens when miner traffic itself is disrupted and the network is forcibly split between China and the rest of the world? Leaving everyone at risk of having their transactions overwritten when the network is allowed to reintegrate?

Anyway, we don't need a 100% effective ban to get an effect. A 90% ban may well be good enough for any practical purpose. Your example is a good one - sure, there are ways to get around 'internet kill switches' several countries have, but in practice these (unfortunately) work.

The fact that some people in a cafe can get one cryptocurrency transfer going is no defeat for a ban, so long as the ban is effective enough to reach its intended effects (e.g. making ransomware useless).

Re: US travel firm $4.5M ransom negotiation open chat

#263

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

The people releasing terrible software (that has a default-open admin port with no login credentials and no filtering, as just one of many examples) are not usually the ones who end up paying the ransoms.

I'd argue on the scale of a company like in this example and other high-profile example that if you're integrating software with such glaring holes in your network then you're the one who is culpable.

Obviously if there are unknown vulnerabilities that is one thing, but there is a level of due diligence you should practice as the operator.

Re: US travel firm $4.5M ransom negotiation open chat

#264

Earlier quoted context omitted.

Bug bounties rising to their actual market price is not a negative value for society.

Market price? Interesting way to put it. You could say that the ransomware issuer has a monopoly to the data and will price it to the level where the company owners have higher return paying and continuing it than closing the company down.

its two order of magnitude better than the unilateral pricing set by companies to their white hack programs, which white hat people have to fight for.

Re: US travel firm $4.5M ransom negotiation open chat

#265
post #223

Earlier quoted context omitted.

I imagine you'd get caught on the off-ramps, since you'd most certainly be reported (by the exchange and/or your bank) to FinCEN. At that point you'd have to contend with the "the money came from bags of cash that just landed in my back yard" problem if federal agents come knocking. As for whether the federal agents will show up at all, I'm not sure. There probably aren't too many criminals who would openly admit tha…

Would fincen show up in Russia? And tumblers can hide the source easily. 4m$ is a lot to clean but it’s not impossible.

Cash can hide the source just as easily. Laundering is the real problem. Yes, even in Russia.

Unless you're best friends with an oligarch, and if that's the case, you can always get Deutsche Bank to do it for you.

Re: US travel firm $4.5M ransom negotiation open chat

#266

Earlier quoted context omitted.

I would not split your transaction between mixers, but instead mix your entire amount through one, then mix all of the outputs through others. Use multiple mixers in series, not in parallel. Compromising one mixer there would associate the inputs and outputs of that step but wouldn’t associate your initial input with your final output. You’d also want to conceal your ip at every step so you don’t get compromised that…

Would there not be a huge danger that a mixer operator, if they received $4m+ of BTC in one big transfer, could simply shut down immediately and pull what's known as an 'exit scam'? They would be in possession of the BTC and could themselves then launder it through other mixers. Perhaps they might do this if the saw keeping the entire 4m as much more lucrative than many years of taking the percentage skimmed off the…

You’d only want to use a mixer where your transaction represents a small fraction of the total volume (otherwise it doesn’t provide much anonymity). An exit scam isn’t so appealing in that case. If a mixer charges a 1% fee, with an average delay of 1 hour, the ongoing fee earns more than a one-time exit scam of all transactions in flight after just four or five days. It takes time to establish a reputable mixer and scale up, so your wouldn’t ruin it just to get under a week of profit early. Maybe they’d choose to do the exit scam if a really anomalous huge sum showed up, which is so large they can’t mix it effectively anyway. I don’t know if $4M is a lot by those standards.

Re: US travel firm $4.5M ransom negotiation open chat

#267
post #262

Earlier quoted context omitted.

That implementation of offline transactions is a poor one, so the rebuttal would be too, but the reality is that bitcoin can work with offline transactions. You can create the transaction object and hand that over. Transferrable literally as a file. Instead of having over notes with the private key on them. Eventually that transaction will need to be settled onchain. This can work in a world without a familiar lookin…

Well, that was a simple scenario with a simple answer. But there are many other things powerful adversaries could do. For example, what happens when miner traffic itself is disrupted and the network is forcibly split between China and the rest of the world? Leaving everyone at risk of having their transactions overwritten when the network is allowed to reintegrate? Anyway, we don't need a 100% effective ban to get an…

sure yeah, a deflationary currency crashes back to $2.50 and institutions are turned off of it for good

but the utility stays the same at $2.50 or $25,000 (offline-for-most, stateless monetary system with managed/predictable supply)

the same utility is inherited by most of other blockchain technologies

Re: US travel firm $4.5M ransom negotiation open chat

#268
post #203

I found it interesting none of these sites actually provided the alleged bitcoin wallet address. I found it @ https://www.blockchain.com/btc/address/13nmJ3SsNB5pSyQrmX3e6...

clicked through the transactions and found this wallet: https://www.blockchain.com/btc/address/17A16QmavnUfCW11DAApi... a balance of 16m and over 1.4 trillon usd has passed through this account. the oldest transaction i could find was 2019-11-02 14:19: https://www.blockchain.com/btc/address/17A16QmavnUfCW11DAApi...

I would assume one address with 377k transactions that has seen over 131 million BTC move through it strongly implies it's some sort of tumbler address. I'm not sure why reusing one address like this would make any sense though...

Re: US travel firm $4.5M ransom negotiation open chat

#270
post #144

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cryptocurrency_tumbler

What happens when crypto tumblers run away with the money

There are projects like Miximus, which is an Eth tumbler with no operator. Participants deposit funds into a smart contract, then when they want to withdraw later, they use zero-knowledge proofs to show that they know one of the private keys without revealing which one.

There's also Zcash, which applies similar logic to all shielded transactions.

Post reply on HN