Live data from Hacker News

Tally of Cyber Extortion Attacks on Tech Companies Grows

bits.blogs.nytimes.com

31–40 of 45 posts

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#31
post #26

Earlier quoted context omitted.

Yup. Except straight cash still needs someone to physically collect it which leaves a point of failure in the crime and a good place for authorities to catch the bad guys. Bitcoin removes that.

But gives another ways to track the money that was paid. It's a matter of authorities catching up with the technology.

The very nature of it makes it much easier for criminals to avoid authorities once payment is made though. Sure you can screw up and do something stupid like send it to coinbase and cash out but there are lots of ways to use it without the authorities being able to determine your identity or location.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#33
post #29

Earlier quoted context omitted.

> NSA didn't even know about Heartbleed Source?

http://icontherecord.tumblr.com/post/82416436703/statement-o... But also, straight from the mouth of a USCYBERCOM strategist speaking to our class the other week. And also, just plain logic. I pointed out here on HN even before the ODNI released the statement I linked above that Heartbleed is far more damaging to the USG itself than any intel value NSA could have hoped to achieve from it. With the other vulns NSA wou…

> This Administration takes seriously its responsibility to help maintain an open, interoperable, secure and reliable Internet.

> When Federal agencies discover a new vulnerability in commercial and open source software – a so-called “Zero day” vulnerability because the developers of the vulnerable software have had zero days to fix it – it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose.

> This process is called the Vulnerabilities Equities Process. Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities.

Nothing about this statement makes me believe that they were unaware of Heartbleed, specifically because it seems to imply that they don't stockpile vulns that they find, which we know that they do.

> The Federal government relies on OpenSSL to protect the privacy of users of government websites and other online services.

The only damage that seems to be claimed specifically in their report is that not fixing Heartbleed would compromise public interface security, and not necessarily any government internal security.

> I pointed out here on HN even before the ODNI released the statement I linked above that Heartbleed is far more damaging to the USG itself than any intel value NSA could have hoped to achieve from it.

I suspect that this isn't true, especially if the US government isn't using OpenSSL for their internal security.

> would have hurt a lot of USG (and just as importantly, private US) infrastructure, so even going by crazy USG logic the right thing to do would have been to disclose it

This didn't seem to be a paramount concern with their other spying activities, which have hurt the security of the US infrastructure and compromised us tech companies (both hardware and internet services) trying to compete internationally.

> But also, straight from the mouth of a USCYBERCOM strategist speaking to our class the other week.

If we're going with anecdotes, I've met a couple of military contractors who claimed to have known of Heartbleed ahead of the public disclosure by non-trivial periods of time.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#34
It's amazing to me that people would screw around with this for 2 or 3 hundred dollars.

I realize wages are low in many parts of the world and this might represent a significant amount of money, but anyone with access to the resources and possessing the technological know how, to pull this off maybe could make that in a legitimate way.

I have no idea, but maybe state actors are involved. Maybe it is a low level warning of what "could" be done. Probably not... but maybe. $300 doesn't seem like it would be worth the trouble and risk but maybe it is.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#35
post #5

And one that resulted in a full shut down: http://www.codespaces.com/

Looking at the armchair post-mortems on HN, they had it coming, one way or another. Putting your only backups the same place you host your full product? Priceless foolhardiness!

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#36
post #35
post #5

And one that resulted in a full shut down: http://www.codespaces.com/

Looking at the armchair post-mortems on HN, they had it coming, one way or another. Putting your only backups the same place you host your full product? Priceless foolhardiness!

Tough call. S3 is supposed to have 99.999999999 (or whatever) reliability (not uptime, just storage reliability). It's hard to justify backing up to somewhere else when they give you that figure.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#37
post #24
post #21

Earlier quoted context omitted.

Bitcoin is only pseudoanonymous. At some point, the 'bad actor' has to access 'legitimate' banking institutions to exchange the Bitcoins to fiat and that is the weakest link. It requires reporting to relevant tax or other authorities based on arbitrary (and secret) amounts, but targets money laundering, drug trade, gamlbing, etc. I suppose if I had to throw a potentially disruptive idea out there, you could create a…

People have suggested this before. A bad actor then just takes 100 illicit bitcoins and sprinkles them in random amounts across many addresses, 11 to himself at another address, 6 to a non-profit, and 14 to you. You are now indistinguishable from the bad guy.

I can't say I would complain if thousands of dollars was given to my address, but you are right... it would represent a difficult problem for enforcement and creative people would come up with clever workarounds.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#38
post #35

Earlier quoted context omitted.

Looking at the armchair post-mortems on HN, they had it coming, one way or another. Putting your only backups the same place you host your full product? Priceless foolhardiness!

Tough call. S3 is supposed to have 99.999999999 (or whatever) reliability (not uptime, just storage reliability). It's hard to justify backing up to somewhere else when they give you that figure.

All your family jewels in one place? Accessible from a common front-panel? Abso-f-ing-lutely NO offline backups that count? Like I said, they had it coming.

Seriously, if you don't have the code-and-data backup that will enable you to switch service providers, even with a downtime penalty, then you and your SAAS truly have it coming. If these guys had any real backups, they could have let the clusterfuck at AWS play out the way it did and still be able to upload everything to DigitalOcean or a colo or whatever and still come back alive a month later. Now that 99.999999999999999 (ad nauseaum) ain't worth squat, is it?

I mean, basic (Dev)-Ops-(Sec), real basic. But, then again, I'm just another armchair, after-the-fact, analyst-dude on the internet.

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#39
One thing I don't quite understand - wouldn't it be possible to unravel a botnet? If you acquire one of the infected machines, a bit of reverse engineering (or perhaps just monitoring its network traffic) should presumably be able to reveal where it gets instructions from. It would probably take the cooperation of law enforcement, but assuming that, wouldn't it be possible - even practical - to do?

Re: Tally of Cyber Extortion Attacks on Tech Companies Grows

#40
post #21
post #2

I posted this because I found it of particular interest that the blackmailers ask for payment in Bitcoin. It makes you think if Bitcoin is turning into a giant example of "be careful what you wish for". We have exchange after exchange get hacked and legit Bitcoin users losing their money, and now Bitcoin enables extortion schemes that couldn't work so effortlessly before. Where is this going?

Bitcoin is only pseudoanonymous. At some point, the 'bad actor' has to access 'legitimate' banking institutions to exchange the Bitcoins to fiat and that is the weakest link. It requires reporting to relevant tax or other authorities based on arbitrary (and secret) amounts, but targets money laundering, drug trade, gamlbing, etc. I suppose if I had to throw a potentially disruptive idea out there, you could create a…

> "At some point, the 'bad actor' has to access 'legitimate' banking institutions to exchange the Bitcoins to fiat and that is the weakest link."

And on the contrary they can do the exchange in, say, Nigeria. So Bitcoin's weakest link is also the law enforcement weakest link, because no one has authority over the entire world, and there are plenty of spots where you can do the exchange without trace.

Post reply on HN