Live data from Hacker News

DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

justice.gov

291–296 of 296 posts

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#291

Earlier quoted context omitted.

The mining algorithm can just be changed with a hard fork. The only think that would irrevocably kill Bitcoin is breaking private keys (ie discovering others private keys, or signing transactions without private keys). A fork could not solve it as there'd be no way to prove which coins you actually owned before the fork.

many people speculate that quantum computing would crack private keys in no time. theres no speculation that this exists, but bitcoin wouldnt last in a commercial world of quantum algos

As long as there was some pre warning that such a quantum computer+algorithm was going to become available, Bitcoin would be able to fork, and users would be able to move their funds to quantum proofed (or at least hardened) wallets.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#292

Earlier quoted context omitted.

Still stupid. As soon as some entity reveals they have the power to crack one of these algorithms, everyone scrambles to migrate to something orders of magnitude harder. It's a weapon you'd only be able to use for maybe a few weeks or months before all the worthwhile targets immunize themselves against you. We already have quantum safe asymmetric cryptography, just no incentive to move fast to deploy it.

How would quantum solve any problems here? I thought the benefit of quantum crypto was the ability to send information while detecting eavesdroppers. I don't think quantum computers have outclassed traditional cpus in processing power.

If they FBI did actually crack a private key, it would almost certainly have to be with a top secret, insanely powerful quantum computer that's decades ahead of what is publicly known to exist. The existence of such a computer that could crack bitcoin private keys would also be a powerful tool against every organization on the planet and their ability to maintain secrets.

I'm referring for post quantum cryptography, https://en.wikipedia.org/wiki/Post-quantum_cryptography, which would negate the usefulness of such a quantum computer at cracking competitor secrets.

Bottom line, there are much more useful things you could use this computer for, like cracking all encrypted communications of a foreign power or hacking into their military or financial systems. Using it to crack a single bitcoin key to recover a few million dollars only serves to alert all your adversaries that it's time to upgrade their cryptography.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#293
post #278

Earlier quoted context omitted.

Still stupid. As soon as some entity reveals they have the power to crack one of these algorithms, everyone scrambles to migrate to something orders of magnitude harder. It's a weapon you'd only be able to use for maybe a few weeks or months before all the worthwhile targets immunize themselves against you. We already have quantum safe asymmetric cryptography, just no incentive to move fast to deploy it.

And who decides when it's time to make the switch? Because it's not a random government. It will most likely be the us putting pressure on technology companies to switch

I don't understand the question.

Who decided that we needed to migrate to HTTPs everywhere? Or that authentication for online bank accounts needed to be encrypted?

As cracking of traditional encryption becomes an obvious problem, systems will be upgraded or people will vote with their feet.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#294
post #243

Can someone explain simply why it is supposed to be so hard to track ransomware bitcoin payments, if all bitcoin transactions are in a shared public ledger? If the victim pays someone we know which account it goes to, right? Then we know that account is criminal. If bitcoins move from that account to other accounts we know that accounts that receive them are essentially "hiding stolen goods". So they are criminal acc…

>Can someone explain simply why it is supposed to be so hard to track ransomware bitcoin payments, if all bitcoin transactions are in a shared public ledger? Clearly, it's not. This is a pervasive misconception. Bitcoin is not, and is not even meant to be, private. Even with obfuscation attempts, nearly every ransomware gang has their bitcoin payments fully tracked, as this one did. There is a robust industry of bloc…

Good explanation thanks. I'm only a bit confused now. You say "Bitcoin is not account based". But if we send bitcoin to some address doesn't that address in effect equate to an "account"?

Just like if you put money into my bank-account you will need to know the account-number (i.e. "address") of my bank-account?

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#295
post #278

Earlier quoted context omitted.

And who decides when it's time to make the switch? Because it's not a random government. It will most likely be the us putting pressure on technology companies to switch

I don't understand the question. Who decided that we needed to migrate to HTTPs everywhere? Or that authentication for online bank accounts needed to be encrypted? As cracking of traditional encryption becomes an obvious problem, systems will be upgraded or people will vote with their feet.

Well HTTPS isn't used everywhere and governments have decided that banks need to meet an extremely strict set of rules to operate. As much as we'd like to think of the internet as the wild west, it is not.

Re: DOJ seizes $2.3M in cryptocurrency paid to the ransomware extortionists Darkside

#296
post #295

Earlier quoted context omitted.

I don't understand the question. Who decided that we needed to migrate to HTTPs everywhere? Or that authentication for online bank accounts needed to be encrypted? As cracking of traditional encryption becomes an obvious problem, systems will be upgraded or people will vote with their feet.

Well HTTPS isn't used everywhere and governments have decided that banks need to meet an extremely strict set of rules to operate. As much as we'd like to think of the internet as the wild west, it is not.

HTTPS is used almost everywhere. And it's not like a government decrees something and it's done. Laws involve multiple stakeholders, and there are multiple governments which converge on the same decision.

It is correct to state that security best practices are not decided by one entity but rather figured out organically and on a non centralized basis.

Post reply on HN