Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

271–280 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#271
post #66

Earlier quoted context omitted.

It is absolutely trivial for an attacker in the US or anywhere to make their ransomware attack appear to come from Russia (to someone who doesn’t know that).

I don't see how that's relevant to the incentives of foreign enemies attacking us. As I said, there are many. It basically stops being criminal activity. Do you really think that's not the case, or that that isn't going to considerably skew where these attacks come from?

I think he's making the point that the attributions of "This came from " are without any evidence. How exactly do you determine that a hack originated in Russia when Russian ips will not hand over their traffic to US authorities? Just because a lot of illicit web traffic originates from Israeli servers, for example, does not mean that it originated in Israel. In reality, our cyber security agencies have no idea where these guys are coming from: it COULD very well be from Russia, sure, but it could also be from your neighbor next door who vpn'd in through a chain of servers starting in france and ending in mali.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#272
post #196

Earlier quoted context omitted.

That might be easier to believe if these ransomware strains didn't do things like automatically disable themselves on computers with Russian language support installed.

Yes, nobody in the west using a compromised russian box for c&c would ever put such code in their ransomware payload. That would obfuscate its origin, and we all know criminals aren't clever enough for that sort of thing. There can only be one explanation: russian hackers operating with Putin's tacit approval. Us in the west should add this to the mounting pile of "evidence" supporting going into another cold war, be…

Exactly, people do not understand how trivially easy it is to completely halt US investigations into internet traffic origins just by pivoting off of a box in a country which doesn't hand over its ip logs to the United States. I would imagine that, should you choose to hack a russian target, you would pivot off of an american box (or would the US hand those logs over? I actually think they might even if Russia wouldn't reciprocate).

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#273
post #35

Earlier quoted context omitted.

It always struck me as improbable that all these high profile (and notoriously hard/impossible to attribute) attacks on “critical infrastructure” or whatever are always instantly and authoritatively pinned (by US authorities) on groups operating in the US’s geopolitical enemies. “Russian hackers” once again, eh?

There are only a few countries which don't extradite cybercriminals to the west and don't prosecute them for foreign attacks - so these few countries are very attractive from which to run such operations; and even for international crime organizations it's good to have the "dirty work" done from such places, where the grunts won't get arrested and be motivated to sell you out for a plea deal.

The problem is you don't even have to run your operation from the country: you just have to pivot off of a box in that country as part of your obfuscation chain. In Cyber Security land, a lot of bad actors originate out of Israel, but that doesn't mean they originated there.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#274

Earlier quoted context omitted.

Exactly. Until DOJ provides proof, this is pure FUD. Anyone competent enough to extort a foreign company out of millions is not going to attempt to cash out through an exchange.

Are you saying the government didn’t actually recover the money that they claim to have recovered?

I think, at this point, doubting anything the government claims without hard evidence proving their case is the wiser play based on pure pattern recognition.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#275

Earlier quoted context omitted.

They send it to another wallet/account that they control. Not hard to understand.

That would require a hard fork or the key to the sending utxo.

I was assuming they are able to obtain the key. Nobody believes hard forking is a practical solution to seizure.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#276

Earlier quoted context omitted.

It'd be a big blow but not the end of the Bitcoin

what do you mean? if they broke sha256 in any meaningful way then people can skip (or significantly game) the whole mining thing...

The mining algorithm can just be changed with a hard fork.

The only think that would irrevocably kill Bitcoin is breaking private keys (ie discovering others private keys, or signing transactions without private keys). A fork could not solve it as there'd be no way to prove which coins you actually owned before the fork.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#277

Earlier quoted context omitted.

Still stupid. As soon as some entity reveals they have the power to crack one of these algorithms, everyone scrambles to migrate to something orders of magnitude harder. It's a weapon you'd only be able to use for maybe a few weeks or months before all the worthwhile targets immunize themselves against you. We already have quantum safe asymmetric cryptography, just no incentive to move fast to deploy it.

How would quantum solve any problems here? I thought the benefit of quantum crypto was the ability to send information while detecting eavesdroppers. I don't think quantum computers have outclassed traditional cpus in processing power.

I believe he's talking about encryption algorithms that are safe from quantum computers

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#278
post #185

Earlier quoted context omitted.

Completely agree but it could be perceived as a show of strength.

Still stupid. As soon as some entity reveals they have the power to crack one of these algorithms, everyone scrambles to migrate to something orders of magnitude harder. It's a weapon you'd only be able to use for maybe a few weeks or months before all the worthwhile targets immunize themselves against you. We already have quantum safe asymmetric cryptography, just no incentive to move fast to deploy it.

And who decides when it's time to make the switch? Because it's not a random government. It will most likely be the us putting pressure on technology companies to switch

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#279

Earlier quoted context omitted.

Second reply: I saw that you work in applied cryptography and blockchain technology @ Cryptography Services (NCC Group) so you might be familiar with somewhat Grey Hat russian forum InsidePro; back in the day I saw people there requesting Bitcoin private key recovery for their lost private keys or if they encrypted and/or hashed wallet private keys and couldn't recover plaintext anymore and I can say that amateur cra…

Can they travel faster than light?

I never heard of any criminal that's fast as light so they do not need to be faster than light in order to catch him.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#280
post #150

I think that the people here speculating about the FBI and private keys are greatly overestimating the competency of these hackers. While it's possible this it he FBI flexing some muscle that they have a backdoor into bitcoin's hashing algorithm, what seems much more likely (to me) is: There is a more sophisticated hacking group which created this particular ransomware package. They sell this ransomware package to le…

They seized private key and if it was encrypted/hashed they cracked it. It could've Bitcoin brain wallet and they cracked the actual ASCII password of the wallet.

It could've been*
Post reply on HN