This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…
DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
261–270 of 296 posts
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#262This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…
The reason why this story doesn't make sense is because it's most likely a lie. Think about it for a second. If they wanted to discourage copycat criminals, the easiest way to do it would be to claim they seized the crypto, right? But what proof do we have that the feds actually seized anything? Is the bitcoin transaction publicly listed anywhere where we can audit what happened? And even if you see the coins were mo…
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#263Earlier quoted context omitted.
They just mention they had access to the private key of the account so that makes sense how they got access. If FBI has broken SHA256, then Bitcoin is a done deal. I hope they share how they got access to the private key.
It'd be a big blow but not the end of the Bitcoin
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#264This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…
It always struck me as improbable that all these high profile (and notoriously hard/impossible to attribute) attacks on “critical infrastructure” or whatever are always instantly and authoritatively pinned (by US authorities) on groups operating in the US’s geopolitical enemies. “Russian hackers” once again, eh?
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#265Earlier quoted context omitted.
They just mention they had access to the private key of the account so that makes sense how they got access. If FBI has broken SHA256, then Bitcoin is a done deal. I hope they share how they got access to the private key.
It'd be a big blow but not the end of the Bitcoin
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#266This story makes absolutely no sense at all. The errors present by these hackers are so comical it's simply unbelievable. I'm supposed to believe some elite Russian hacking group keeps their crypto wallets running on a US host where the FBI just logs right in and snatches the private key? I'm starting to entertain the conspiracies that the future of commodities price manipulation is fake ransomware attacks. There nee…
Computer security is hard. That's why ransomware attacks exist. It's just as hard for ransomware attackers as for their victims. If they were good at computer security, they'd be working a legitimate job. I find your incredulity strange, it's like hearing about the Valentine's day massacre and being shocked that mobsters could be at the receiving end of a Thompson for once.
Um, what? Did you do a survey of all people who are good at computer security?
Furthermore, maybe the attackers _are_ working a legitimate job. Do we know attacker's life details?
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#267Earlier quoted context omitted.
It'd be a big blow but not the end of the Bitcoin
It surely depends on which aspect of SHA they would have broken, but the whole point of Bitcoin is the hash being completely unpredictable and requiring brute force. That's the Work in Proof of Work.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#268Earlier quoted context omitted.
If the private key was hashed, and they only had the hash, then they could not crack it. Hashing is not the same as encryption.
Second reply: I saw that you work in applied cryptography and blockchain technology @ Cryptography Services (NCC Group) so you might be familiar with somewhat Grey Hat russian forum InsidePro; back in the day I saw people there requesting Bitcoin private key recovery for their lost private keys or if they encrypted and/or hashed wallet private keys and couldn't recover plaintext anymore and I can say that amateur cra…
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#269Earlier quoted context omitted.
> what proof do we have that the feds actually seized anything? I'm sure the feds will sell the bitcoin in the fullness of time, like this: https://www.usmarshals.gov/assets/2020/febbitcoinauction/
Won't they hand them back to the pipeline owner who paid the ransom?
Not saying that’s what they will do, just that I think it would make sense to me.
Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside
#270Earlier quoted context omitted.
I think you are assigning too much “us vs them” to the ransomware marketplace. With ransomware criminals, “us” is the attacker, and “them” is everyone with a computer who might pay. Political boundaries don’t factor in to it at all. It is by nature an anonymous attack, hence the term “ransom”. It is strange to me that almost all high-profile ransomware attacks that have been publicized in the US are claimed by the FB…
> I think you are assigning too much “us vs them” to the ransomware marketplace. Attacking things in a foreign jurisdiction is massively appealing from a "what will get me thrown in jail by my own government if things go wrong" perspective. You don't need any political loyalty for that calculation.