Live data from Hacker News

DarkSide ransomware gang quits after servers, Bitcoin stash seized

krebsonsecurity.com

91–100 of 623 posts

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#91
post #69

Earlier quoted context omitted.

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Oil does require infrastructure. What you put in your car is several steps removed from what is pumped out of the ground.

I think the parent's point was that if oil infrastructure is completely disrupted, consumers won't even be affected for a few days and the short-term consequences will be somewhat minor (some percentage of drivers won't be able to drive, deliveries may be delayed).

If a hospital is shut down, then people will start dying immediately. The consequences are much more direct and severe.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#92
post #55

Earlier quoted context omitted.

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)

I know you're saying this in jest, but that's the calculus.

The outcome here shows that executives made the right call. The $5MM fee was easily paid, less than the costs of security, and the insurance company will probably cover it anyway. And the government/people were so outraged that the attackers were met with fucking swift justice.

The company will probably get some grants or something to cover the cost of "securing their infrastructure." Never let a good crisis go to waste.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#93
post #60

Earlier quoted context omitted.

Until someone cracks it, that is. If it becomes the crypto of choice for some of the bigger fish, you can bet the government will find a way to trace it.

>Until someone cracks it This is certainly not a given. The government isn’t going to be cracking signal messages within any reasonable timeframe either.

There are ways to crack encryption that have nothing to do with math. It doesn't matter how good your crypto is. You could probably get by plain text as far as the FBI's effort to crack your crypto are concerned as they won't waste their time checking if you are that stupid.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#94
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Oil is flowing constantly and continuously into every corner of the country. The storage capacity is negligible and the need is critical. Unlike a single hospital there is very little room to shift excess capacity relative to usage and the knock on effects are potentially catastrophic (we lose power to every hospital in 500 miles and nobody can run the generator).

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#95
post #55
post #43

> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…

When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."

TBH I was shocked $5 million was all it cost.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#96
post #15

Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…

One way I've seen discussed on HN is by sending varying amounts to N different accounts, where some are owned by you / affiliates and others are not. In a sense, paying for obfuscation of which accounts are actually owned by you.

Until one of those people buys a Tesla with bitcoin (yeah, I know they just stopped doing that) from a wallet that can be traced to that payment, and then its just the authorities following up the chain.

People like to seem like all these crypto's are totally anonymous, but every transaction ends up in some sort of public blockchain. So unless you have air-tight OPSEC and people that will never talk, no matter what kind of jail time they are facing, its always going to be traceable with enough interest.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#97
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Destroying logistic infrastructure is how you defeat a country. Petroleum is critical to the functioning of modern economies, if you cut that off things go badly. They really kicked the hornets nest on this one.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#98
post #69
post #45

It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

I agree with you that an attack on a hospital is an attack on infrastructure, though I disagree with your arguments regarding oil infrastructure.

The difference is response is a matter of impact scale. Usually, the infrastructure of a small group of hospitals is at stake. This time an entire state is hoarding gasoline. Both are infrastructure but the latter is causing nationwide effects.

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#99
post #69

Earlier quoted context omitted.

I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…

Oil does require infrastructure. What you put in your car is several steps removed from what is pumped out of the ground.

Nor can you store gasoline for long unless you stabilize it (and even then), and certainly not safely in most residences. Classic car owners run into this issue, as do the diesel tanks for generators in datacenters (diesel is much more stable than gasoline)

Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized

#100
post #90
post #77

Earlier quoted context omitted.

I think you're spot-on here - the ransom is seen as a "cost of doing business", and until recently security was seen as "a problem that happens to other people". Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior secur…

Even better, they will take the cost of their Insurance Deductible, and then do those calculations. Most businesses have insurance for this stuff.

Interestingly, it looks like (some) insurers may be responding to this.

> In an apparent industry first, the global insurance company AXA said Thursday it will stop writing cyber-insurance policies in France that reimburse customers for extortion payments made to ransomware criminals.

https://www.insurancejournal.com/news/international/2021/05/...

Post reply on HN