Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

321–330 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#321
post #259

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

They may have just intended to get money, but they definitely spread terror. I had to have like an hour long phone call with my mother on Monday explaining why she had to go to 4 gas stations before she could get any gas, and that no the pipeline was not going to explode.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#322

Earlier quoted context omitted.

I mean, the pipeline in question provides half of the gas to the US East coast. You don’t have to love oil to see that losing 40% of the supply to more than 100m people overnight would be a public safety (what if emergency vehicles can’t buy fuel?) and economic risk. The number of people reliant on this pipeline is several orders of magnitude greater than would be impacted by taking a single hospital offline. You’d n…

Yeah, I understand this and agree with you. Compare one of the biggest oil pipelines in the country with one hospital, of course one will be worse than the other. But if you instead compare 40% of the hospitals going offline VS 40% loosing access to gas, with similar conditions, I think the mortality will be higher by attacking hospitals. I think the government could probably somehow logistically ration oil if shit r…

I guarantee if a ransomware attack shut down 40 percent of the hospitals in the United States at the same time, we'd have an Iraq War situation on our hands.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#323
post #183

Earlier quoted context omitted.

They paid $5 million, if "it was cheaper for them," that's solid math that ignores some really important stuff though, LOL. What is the externalized cost of this crisis on the entire country? The $5 million dollar ransom is a worse deal if you can convince your board to consider that externality. The criminal penalties for executives in leadership and board positions (and I'm not saying this is my preferred approach)…

> What is the externalized cost of this crisis on the entire country? If a business externalizes the cost, does it matter to them? Civil penalties levied by regulators will drive the change that matters.

> If a business externalizes the cost, does it matter to them?

I mean, yes? Maybe not before next quarter's revenue statement, but eventually it will have to start to matter?

If your dog goes and craps in the yard every day, you eventually have to clean it up or you will get flies in the yard, and if you have to open the door or leave the house at all then sooner or later you will have flies in the house, it matters, yes. It's really not any more complicated than that.

If you are responsible for dumping toxic waste out the back door of your factory, it's only a matter of time before it's in your drinking water at your house, a couple of miles down the road. Externalizing a problem doesn't really get rid of it, just makes it someone else's problem (for now at least.) Those other people are real people, and they will find you.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#324

Why should I believe this? They can shut down their servers, move their crypto to different wallets, and pop up again in a few weeks, right?

They know that they can and will be found, and are running scared. In general ransomware works because it takes a lot of resources to find the criminals behind it. And generally there's not enough resources to do this. But once it hits a level where it creates a widespread national problem, it becomes more of an act of war. Then you get people involved that aren't just law enforcement and have tools that aren't avail…

I don’t understand how ransom ware works at all. The address is known well in advance, so a miner knows they might face sanction of their own coins for including it in their block. Not worth it.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#325
post #259

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

On the high seas of the Internet there is a thin line between pirates and state actors. There could even be "privateer" (https://en.wikipedia.org/wiki/Privateer) attackers who work for a nation and for profit at the same time.

From the victim's perspective it matters less who is attacking you or why they are attacking you and much more what the results of the attack are, how you can mitigate and recover from the damage, and what needs to be done to prevent future attacks.

For the case of DarkSide and Colonial Pipeline, the attackers did not claim to have a political motive, but the resulting fuel shortages and panic buying might as well have been a form of terrorism.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#326
post #237

Earlier quoted context omitted.

I think parent may mean infrastructure side. If it had just attacked the office side of things, it would be the usual 'company infected with ransomware' story without affecting the public.

The truly cynical take is that they managed to take down Colonial's billing . In response, Colonial shut down the pipeline - because obviously delivering oil without getting paid is out of the question. Yes, it's guesswork and pretty extreme conjecture but it has just the right amount of coldheartedness to it: https://zetter.substack.com/p/biden-declares-state-of-emerge...

While watching the USSR collapse in real time, I noted a reporter say the core of the breakdown was inability to issue paychecks to bureaucrats. No pay = no bureaucracy = no government.

I've long wondered if that really was the case, seemed absolutely sensible...

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#327
"So Sergey has pulled the inevitable exit scam, proving yet again, that there really is no honour amongst thieves.

I sincerely hope that no companies had paid the Tsar’s ransom before Sergey headed off for his dacha in the Urals. Forking out millions and still having your network out would be a bitter pill indeed to swallow."

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#328

Earlier quoted context omitted.

You dont do it that way. Just drop it in Tornado.cash and a few days later withdraw to a virgin crypto address. The virgin crypto address just pumps a token that you bought in another clean address with clean money prior. You sell the token in the clean address at a massive profit and cash out under your real name and ID and even pay taxes . Go look at any highly pumped token on Uniswap/Sushiswap/Pancakeswap and you’…

You could even send ETH to the Secret Network and perform token swaps and then send it back to a clean address.

Yes, even better because the smart contract execution is private and all the variables (receiver, quantity) are only temporarily stored with the validator’s SGX chips and not onchain.

Less liquidity there, for now. Meaning the exits would more likely be the same beneficial owner, but definitely an additional route for liquidity.

Similarly, I think there should be a version of Tornado.cash that stores notes in SGX and Secure Enclaves, as enough devices have this now. (Although that forces only one device to have the note. Instead of a transferable IOU)

How well does Keplr or Cosmos wallets work over Tor? Are their any onion nodes that can resolve broadcasted transactions?

Post reply on HN