Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

541–550 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#541

Earlier quoted context omitted.

Just causing terror doesn't make it terrorism. Causing terror as a means to further some political (or religious) goal would make it terrorism.

Money is pure politics. The attacker becoming rich can legally be considered a political goal as the nature of money is political. If they endanger an entity or someone else’s resources to gain that political goal they are guilty of terrorism as they used fear to enact political change.

> Money is pure politics.

That only true when right is up and down is left.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#542
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

A single hospital is not major infrastructure. We can operate medical services out of tents if necessary.

Oil pipelines that serve everything from energy to transportation to manufacturing are far more integral to keeping all aspects of society running for magnitudes more people.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#543
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

> seem to point to ransomware activities being far more coordinated and "business-like" than they often get credit for. This is a business that actually provides better support than a regular business. From conversations with friends in the Infragard side of this, and the agencies that collaborate, they have 24/7 English support available before and after payment, as well as decryption remote support if you can't get…

That's not support. You're not a customer. They're not providing any value. This isn't some glorified version of business, it's just organized crime.

They're available for their interests, not yours. They're actively robbing you and will be highly available to keep things moving efficiently, the same way physical bank robbers used to make sure staff were comfortable enough to open the safe and provide cover.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#544
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

> I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to.

Terrorism has a legal definition, and something affecting national security is not the determining factor in calling something terrorism.

"Terrorism includes the unlawful use of force and violence against persons or property to intimidate or coerce a government, the civilian population, or any segment thereof, in furtherance of political or social objectives." [1]

[1] https://www.law.cornell.edu/cfr/text/28/0.85

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#545
post #354

Earlier quoted context omitted.

HN is full of assholes who practice deprecating others to find their own worth. Set yourself free of their dogma and change the world the way you see it!

Some downvoting can be truly surprising, and one factor may be because HN is much more international, while I think of it as "American". It is Y-Combinator, after all. Funny fact - one way to get down votes on HN is to say something negative about that shit-tier human Peter Thiel. Apparently becoming rich off of venture capital makes you automatically a good human being.

Truth! Fuck that guy and all the “VC” that follows. Shit bags, all of them!

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#546
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

Yup. This falls under the idea of “optics”. Often HN tends to dismiss it in favor of logics “well, the problem is actually quite small”. What matters is the perception of the problem.

Just like with The Silk Road. Once it became large enough and Ross started to taunt the authorities to find him, the police had no choice. It’s continuing existence chipped away the legitimacy of the authorities, they had to shut it down just to maintain appearances.

Just like this ransom ware. Keep it small, it’s not worth going after. Start screwing with the economy and the govt goes from 0 to 10 very quickly.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#547
post #529

Earlier quoted context omitted.

No, money is inherently political as a matter of observable fact. It is created by governments and its value is driven by taxation.

> It is created by governments and its value is driven by taxation. How does taxation drive value? Which taxation? There are governments that don't charge income taxes, there are governments that don't charge property taxes, there are governments that don't charge sales taxes.

There are many different types of taxation, but there is no currency that doesn’t derive its value from taxation. People call things like Bitcoin currency but until a sovereign runs their financial system of federal settlement payments on the Bitcoin blockchain it is only a commodity like gold or silver or corn.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#548
post #259

Earlier quoted context omitted.

Maybe people didn't like your use of the term "terrorism" for national security threats? A common understanding is that terrorism is intended to frighten people or make them feel unsafe, while various official definitions of terrorism include the idea that it's intended to coercively achieve some particular political goal. If attackers just intend to get money, they're probably well-described as extortionists (or in…

Would the same apply for someone who physically took something essential to national security hostage and then demanded money? Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?

"Would that change if they, for example, demanded the release of prisoners of a specific political persuasion?"

Yes.

"Terrorism is, in the broadest sense, the use of intentional violence to achieve political aims." https://en.wikipedia.org/wiki/Terrorism

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#549

Earlier quoted context omitted.

Shouldn’t they have a paper-based/offline downtime procedure for this? (Oh shit, everything just went down, turn on the generator, go plug that printer and laptop in, and print off all the reports of where we were from the offsite/offline/whatever backup). What did they do before computers? Failing to plan is planning to fail and all. I like the idea of monthly planned downtimes where possible so people don’t run aro…

> Shouldn’t they have a paper-based/offline downtime procedure for this? If they did, I would expect their employees to be out of practice with such methods since they weren't working that way day-to-day. Unless they're running regular "all computers are down"-drills to keep their employees sharp, downtime was probably inevitable.

Hence the monthly planned downtimes. Some organizations require you to take your vacation time every year, and it’s partly because they want to make sure they know how to operate without you.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#550

Earlier quoted context omitted.

I got downvoted for saying that maybe it's time to treat serious ransomware attacks (infrastructure, security, health, etc.) as terrorism - as in the sense that they're a threat to the national security. But this kinda shows the response I was referencing to. A lot of people like to think of ransomware attacks as the ultimate stress test as far as security goes, and thus a good thing - but let's not get too blinded b…

FWIW in June of 2011 the Pentagon issued a report that defined how 'cyber attacks' can be classified as an act of war. Part of the defense department review of threats against the US. However, they have to be plausibly tied to a state actor such as Russia or North Korea (to give two examples) The net result was that the Pentagon considers military response (both kinetic and cyber) as legal and sanctioned ways to resp…

Reading about the Letter of Marque was fascinating! Can you share your evidence of the Russian version in use today?
Post reply on HN