14 ms·
Massachusetts Steamship Authority hit by ransomware attack; ferries delayed
- user-the-name 5y agoTime to ban bitcoin. https://newrepublic.com/article/162589/ban-bitcoin-cryptocurrencies-stop-hacker-ransomware https://newrepublic.com/article/162589/ban-bitcoin-cryptocur...
- mnd999 5y agoNope, no point banning the thing the criminals use, because they don’t follow the law anyway. Ban paying ransoms, the corporations are much more likely to follow the law.
- x86_64Ubuntu 5y agoThey don't have to ban BTC, they will just squeeze any company that provides a fiat off-ramp for BTC. The government has done this for decades, just ask the legal MJ business or sex adjacent workers.
- user-the-name 5y agoIf the victim has no way to pay the ransom, there will be no point in trying to blackmail them. If you ban paying ransoms, desperate people will just do it in secret, something bitcoin works hard to enable.
- meltedcapacitor 5y agoFor large companies "paying in secret" is pretty difficult given public accounts. The typical CFO would rather get a new job elsewhere rather than risk prison because his CTO colleague did a poor job securing the IT. They just work there. A ban on ransomware payment also has the nice side effect of banning ransomware insurance, which has been making the problem worse so far.
- OminousWeapons 5y agoI don't think this is going to work. Time is on the side of the attackers. All the attackers have to do is wait and repeatedly restate that they will fully restore operations if the victim pays a small fee and when losses grow large enough investors / shareholders will apply enough pressure to management to make it happen, whether it is legal or not. No one is going to eat massive losses for the greater good. There are plenty of policies against negotiating with kidnappers and terrorists, and yet people still do it for this exact reason. Banning crypto exchanges is actually a much more effective solution to the problem because it at least forces someone to show up in person to collect the money.
- meowface 5y agoOf the three most common ransomware-combating suggestions I've been observing over the past few months, I'm strongly opposed to the first two (banning cryptocurrencies or banning ransom payments) and would instead strongly advocate for the third: reinstitute letters of marque for privateers. Enable activity instead of futilely trying to ban activity. Instead of focusing on punishing the victims and unrelated third parties, focus on punishing and disrupting the perpetrators. Or if not letters of marque, they could at least just issue a notice that certain activity will have a blind eye turned towards it, to mirror the policy of some of the governments that bear most of the responsibility for ransomware activity.
- boomboomsubban 5y agoSo your answer to the problem is to encourage more ransomware attacks? You don't think ransomware itself is bad, you just take issue with the idea that you may be the victim? Training more people to use it's probably going to backfire on you then.
- meowface 5y agoNo, I'm definitely not suggesting deploying ransomware or legalizing deployment of ransomware. Apologies if I wasn't clear enough in my post. By "enable activity" I just mean "instead of taking a general approach of trying to ban things to solve a problem, take a general approach of trying to enable certain other kinds of things to solve a problem". Not "enable ransomware activity".
- bdamm 5y agoIsn't this like banning cash to stop muggings?
- cduzz 5y agoThey banned enormous denomination bills to prevent this sort of crime. By "Ban" I mean they no longer make them, and possibly destroy them once they get circulated back to the central bank. They're still legal tender. See also 500 euro note... (edited to clarify "ban" meaning)
- coolspot 5y agoCrypto is realistically the only way to accept a payment for high-profile ransomware attack. Imagine encypting whole Maersk network and then asking ransom in cash? Wherever you decide to do the exchange there will be couple Apache/Eurocopters/Mis hovering around and watching you. With crypto just send them your XMR address, then wait couple years for heat to come down before mixing/cashing out.
- mrweasel 5y agoIt is, and it has proven very effective. Robberies against banks and stores have been cut in half during the last ten years, as cash is getting harder to access. Many store open after 19:00 don't have much cash on hand so robbing them is not really attractive any more. There are almost no bank robberies, as even banks doesn't actually have cash. The people who get mugged are normally forced to go to an ATM to withdraw cash. I'm not suggesting we just randomly ban stuff to avoid the criminals from exploiting it, but it is working.
- Workaccount2 5y agoThat's not a function of banning cash however, its on account of the rise of credit cards. No one sacrificed or was inconvenienced to get here, it was just natural progression with good side effects.
- creato 5y agoOf course, but it doesn't invalidate the point, banning cash would have similarly reduced muggings. Just like banning bitcoin will reduce ransomware activity.
- COGlory 5y agoI have to wonder: Are there CTOs or IT heads going into board meetings or other meetings, and telling people that these systems are secure? Because if so, they need to be tried for fraud. If it's on the internet, it is not secure.
- gilbetron 5y agoI think more often it is the rest of executives demanding CTOs and IT heads prove to them in absolute terms that more security is needed when nothing bad has happened yet.
- OminousWeapons 5y agoSo your solution to transient disruptions in availability is to make your services permanently unavailable?
- COGlory 5y agoServices can be available, and not reliant on internet connected services. Imagine if all the hacks we've seen in the last year happened all at once. We'd be screwed.
- OminousWeapons 5y agoHow are you going to sell customers tickets remotely without an internet presence? How are you going to field customer service complaints or general inquiries without email? How are your employees going to do work at multiple sites without VPNs? If you pitch "lets do everything by phone" you will be laughed out of the room. I agree that things should be kept off the internet unless they absolutely need to be there, but realistically companies need to have internet connected services to be able to do business.
- COGlory 5y agoHow are they going to sell tickets with their infrastructure offline to a ransomware attack? I'm not sure a perfect solution, but the standard of living was pretty good before the internet. Doing away with reliance on infrastructure for critical things like food processing, energy, and transit does not seem like a high price to pay to avoid a Thanksgiving turkey conundrum. All these services are going to go unhacked, until they're hacked. And it's a complete skewed problem. We get minor conveniences for having them online. We suffer massively when they go offline.
- endisneigh 5y agoHow exactly are the ransoms even paid out? I would assume cryptocurrencies, but before those existed how did they pay out? I'm not sure what it would be called, but has there been any investigation in a sort of "transparent by default" database system? Ideally if this were possible people wouldn't need to care about data being stolen (though in this case it's unclear what the attack did, but many times it's more like we'll reveal/block your data unless you pay up)
- ocdtrekkie 5y agoRansomware wasn't nearly as prevalent prior to cryptocurrency because moving that kind of money was much harder. Another interesting shift is that complete administrative takeover is often less compelling: Software is more secure covering administrative functions, but users, which have access to all of your business data, are vulnerable as ever.
- exhilaration 5y agoBefore cryptocurrency you had to buy things from shady online pharmacies or send/fund Visa gift cards. Source: https://www.varonis.com/blog/a-brief-history-of-ransomware/ https://www.varonis.com/blog/a-brief-history-of-ransomware/ Crypto is really what's made ransomware at the scale we see it now possible.
- stevemk14ebr 5y agoCrypto makes it more efficient. It would still occur without crypto just fine. Your talking about a black market worthy many millions, maybe billions.
- livueta 5y agoI suspect it changes the profile of who gets hit. Individual-level targets would get extorted for maybe a couple hundred bucks - sums that are reasonable to transact in iTunes cards or whatever. Those numbers are low both because it's what that category of target is willing/able to cough up financially, and what they were able to transact irreversibly. Conversely, your meat-packing CEO isn't going down to the corner store for $11m in phone credits, so it was less worth it to go for targets with deep pockets, that might be better-protected, instead of casting a wide net for a lot of easy small hits. The ability to irreversibly and kinda-anonymously transact large amounts definitely incentivizes going for institutional targets.
- JumpCrisscross 5y agoA federal ban on paying ransomeware would reduce the incentive to commit these attacks.
- user-the-name 5y agoIt would cause companies to pay secretly and illegally instead, something which cryptocurrencies enable. Ban cryptocurrencies. They are the cause of the ransomware epidemic.
- COGlory 5y agoUnless they were globally banned, companies could secretly and illegally pay ransoms in them anyways.
- ghaff 5y agoThey possibly could but a lot of executives would probably prefer that their soon to be ex-company took a hit than that they became personally liable for breaking a federal law.
- sokoloff 5y ago“We purchased security consulting services who were able to decrypt our ransomware-infected files. We’re not sure of the exact method they used but it worked.”
- ncallaway 5y agoLawmakers have dealt with this problem for a long time. It’s well solved. If they wanted to prevent this kind of behavior there are two straightforward approaches: - make it also illegal for the consulting company to pay a ransom. - attach Strict Liability to any ransom payment, even if made through an intermediary. The executives quoted above from the paying company could still face criminal liability for such a payment disguised with plausible deniability https://en.m.wikipedia.org/wiki/Strict_liability https://en.m.wikipedia.org/wiki/Strict_liability
- mrweasel 5y agoI continue to wonder why more companies aren't utilizing application whitelisting. Most, if not all, of the attacked companies run Windows, and Windows have been able to restrict system to only running whitelisted application for ages. Sure, whitelisting is annoying to say the least, but these are critical systems, you don't need to install new software daily or even monthly.
- nradov 5y agoThere's no real reason except for basic incompetence and lack of resources. I expect that over the next few years most small and medium enterprises will essentially be forced to outsource their IT infrastructure to a few huge cloud vendors with the scale to build and maintain secure systems.
- PeterisP 5y agoThe initial foothold exploits - where application whitelisting would help the most - generally are not "critical systems", they are the daily workstations of random employees. By the time the attackers reach your critical systems, they most likely can attack them with stolen credentials without running any exploits that whitelisting would prevent. To protect your company, application whitelisting needs enough usability to be easily supportable for the workstations of your accountant, office receptionist, and the VP of Marketing (those three are all good examples of valuable entry points for targeted attacks), which all may get management approval to throw out application whitelisting if it inconveniences them enough - there's no reasonable tradeoff between security and usability, you must get both as usability is mandatory and usability deficiencies will result in security features getting removed in all but the most critical circumstances.
- bagacrap 5y agoWhat makes app whitelisting hard to use on an employee's corporate issue laptop? They shouldn't install anything that doesn't have a business purpose, and these days there are hardly any native apps people want to install anyway.
- 5y ago
- arduinomancer 5y agoI'm curious if seeing headlines like this causes other companies to invest more in security. Or is it more like "well as long as it doesn't hit us we don't care"
- madcows 5y agoCompanies should be lobbying the federal government for protection. Otherwise the government is as complicit as they would be for "looking the other way" while the mafia extorts local businesses. And in this case, that mafia may even be an arm of foreign adversaries, making this ever more urgent and damaging.
- bluGill 5y agoI'm sure the government is already feeling pressure. However the criminals are good at hiding their tracks. There is reason to believe they are being protected by Russia (or other country that nobody wants to go to war with).
- madcows 5y agoWith the US under a constant barrage of attacks it makes sense to trash the "space force" and create a legitimate "cyber security force." This may be our last chance to maintain global power through the use of force at all, given that so many competitors are gaining foothold in every other area. We need bullet proof IT infrastructure, instant backtracing, and effective retaliatory responses ready to deploy, yesterday! Why the hell isn't the attacker's computer compromised when they access the data? (rhetorical)
- dicomdan 5y agoWhat does it have to do with space force? These are two separate issues.
- madcows 5y agoConservation of energy. I'd love to suggest that we just do everything all of the time, but that's unsustainable and fodder for another dissenting comment, so instead I suggest reallocation instead of creation.
- nradov 5y agoMerging the Space Force back into the Air Force wouldn't conserve any energy. It's still the same people doing the same things with the same equipment.
- willcipriano 5y agoWhy is the space force the first thing off the table and not say the endless wars in the middle east?
- deleted 5y ago[deleted]
- tomp 5y agoGreat example of short-term thinking! Your enemies distract you and make you fight the current fight to make you miss the next war.
- RobRivera 5y agothis is getting a little out of hand
- FridayoLeary 5y agoBut entirely predictable. I might as well have bought shares in popcorn. It's almost a weekly occurrence now, and those are just the ones we hear about.
- SyzygistSix 5y agoWasn't it around 2010 when there were tons of cyber bank robberies and databases being held for ransom? I don't think this is really anything new. Just different targets.
- Decabytes 5y agoI wonder if this will mean an increase in cyber security related postings in industries that have otherwise not had to worry about cyber security before (I.E the Steamship Authority, Meat industry etc)
- walrus01 5y agoI saw a badly written headline yesterday that combined the meat industry hack with something about colonial pipeline, and it briefly brought to mind a mental image of a liquefied meat slurry/pink goo pipeline.
- swiley 5y agohttps://xkcd.com/1649/ https://xkcd.com/1649/
- walrus01 5y agoimagine the retail value in dollars per liter of an HP inkjet printer ink pipeline
- FridayoLeary 5y agoImagine how much a leak would cost them! Printer ink is among the most expensive liquids in the world.
- swiley 5y agoThe pessimist in me thinks it will mean an increase in McAffee sales and pen tester fees followed by regulation that makes them mandatory.
- causality0 5y agoCybersecurity is not a technology problem. It's a policy and enforcement problem. Ground and mid-level operating convenience will always destroy any attempt to create security unless strong standards of behavior are created and ruthlessly enforced. I've never seen it happen successfully outside of technology corporations staffed by nerds who actually care or the military. All it takes is one guy who knows a guy and then the admin password is on a notepad on the desk. All it takes is one guy who doesn't get a 4G signal in one room so he brings a router from home and plugs it into the network.
- 1970-01-01 5y agoThis isn't news anymore, its weather. If your company does not have a full time cybersecurity team, they soon will, even if they say they don't need it.
- walrus01 5y agoand as a parallel to modern industry standard infosec best practices, a good offsite/off-line backup system, disaster recovery program, tested backups/recovery methodology. A lot of the companies I've seen badly affected by a cryptolocker malware would have been equally in a dire situation if their head office/datacenter had burned down.
- Ekaros 5y agoDefined process to run things without systems, if at all possible. That would sound obvious to me. May take lot of effort but with critical sectors such plans should be mandatory.
- nradov 5y agoMost companies should really outsource their IT infrastructure instead of hiring a full-time cyber security team. It will be cheaper in the long run.
- deleted 5y ago[deleted]
- Ekaros 5y agoSeeing some of the mess that IT-support is for enterprise customers I wonder would they really do better. On other hand SLA could be a real thing and kill the incompetent providers.
- joe_the_user 5y agoIn a lot of situations we've heard about, the cybersecurity team could consist of one person with a bullhorn walking around shouting "don't connect critical infrastructure to the Internet". Whether they'd listen to them still is another matter but that's the same with a regular cybersecurity team. And that is to say we have institutional standards where unsafe practices are considered OK and will be followed because they save X dollars and time now.
- tibbydudeza 5y agoClearly they are messing with the wrong people from Martha's Vineyard :).
- burkaman 5y agoThe rich people on Martha's Vineyard don't use the ferries, they have their own yachts or helicopters to get there.
- dredmorbius 5y agoAt some point they're affected. Staff, service workers, guests, neighbours.
- tibbydudeza 5y agoYes who is going to serve the champagne and canapes ???.
- dredmorbius 5y agoI understand the sentiment. But the logistical and support tail is large, and too large to chopper over. The point remains that a ferry service cut will be felt. Snark-infested waters or not.
- throwaway0a5e 5y agoMost of Worcester county and Bristol county would probably disagree. Just like when they hit the vehicle inspection system in March, the wealthy hemmed and hawed about how nobody should get away with thumbing their nose at state authority but the little guys were just happy it wasn't them getting the shaft for once.
- uses 5y agoI'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber criminals? * Is this an issue that can only be solved at the geopolitical level because of the role states play in enabling this activity? * Will the hardening brought about by this eventually outpace the crappy attacker software? * Is this a phase or the new reality? * How much of this is enabled by technology vs the geopolitical situation?
- mannerheim 5y ago> Historical analogues? 'Don't negotiate with terrorists' or: > It is wrong to put temptation in the path of any nation, > For fear they should succumb and go astray; > So when you are requested to pay up or be molested, > You will find it better policy to say:— > "We never pay any-one Dane-geld, > No matter how trifling the cost; > For the end of that game is oppression and shame, > And the nation that plays it is lost!"'
- alksjdalkj 5y agoAnother issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.
- xkyf 5y agoThat gets discussed every time, hackers were using prepaid cash services. Ransomware predates cryptocurrencies by decades.
- viraptor 5y agoIt's a bit of the "we have X at home" meme situation. Sure, ransomware existed before, but the scale was not even close to that. You can't move hundreds of millions in gift / prepaid cards without getting found. It's a completely different level of comfort for the operators.
- owlbynight 5y agoThe US is going to end up tracking and assassinating these people, if we're not already. Messing with the old money usually doesn't turn out well for whoever's doing it.
- bluGill 5y agoNot just the US. A lot of countries care. Western Europe (not sure about the east) does as well and will do something even if they aren't as violent as the US. (In fact they are probably going to claim the moral high ground of not assassinating people only because they give evidence to the US and look the other way). South America, South Asia, and Africa will all have at least some helping out, though it isn't clear who will do what. Most of the blame is going to Russia, though North Korea is a possible source of this, as are a few random countries scattered around. Most stand to lose more than they gain from allowing such crime. (their military might be interested in the ability, but those will be more careful about who they target)
- tobesure 5y agoWhy not China? I always have problems with these attributions - they inevitably depend on "signatures" like timestamps and language encodings that would be trivial to deliberately fake by a competent team - and some of these hacks indicate competence.
- vecter 5y agoAre there actual examples of the US "assassinating" bad actors in this way? That seems farfetched, as opposed to just going after them in the judicial system.
- dredmorbius 5y agoThere are threats which emerge when a viability threshold is crossed and realised. For cities, recurring plauges began occurring during Roman times and limited maximum city populations to about 1 million until the advent of modern sanitation, hygiene, public health, waste removal, and food quality. (Actual medical care and treatment had little to do with this, though vaccines and antibiotics helped.) Industrial pollution lagged industrial development by about 50--100 years, with air and water quality and material contamination (heavy metals, asbestos, organic solvents, synthetic hormone disruptors and other bio-active contaminants, etc.). Increases in travel, transport, and communications almost always directly facilitate fraud. The Greek/Roman gods Hermes/Mercury represented communication, messages, travel, transportation, commerce, trickery, and theives. The term "Confidence Man" arose from Herman Melville's novel of the same name, set on the first great highway of the United States, the steamboat-plied Mississippi. Mail begat mail fraud. Telegraph and telephones begat wire fraud. Cheap broadcast radio and television, payola and game-show fraus. Email begat spam and phishing. The 1990s and 2000s computerised business practices employed computers with shitty security, but those systems were saved by the general lack of networking, the relatively small size of global computer networks, limited disk storage, limited network bandwidth, and the effectual air-gapping of paper-driven steps in processing. Billing might be submitted or computed electronically, but a paper check still had to be cut and signed. Draining accounts or data simply wasn't possibly without running up against the inherent limitations of computer infrastructure at the time even had a payment mechanism similar to today's cryptocurrencies been available. If my assessment is correct, we'll be seeing much more of this. Attackers have low costs. Victims have highly-interconnected, but poorly-defended systems, comprised of multiple components, each complex on its own, and lacking any effective overall security accountability. End-to-end automation exists, facilitating both productive work and effective attacks. A viable and tracking-resistant payment mechanism exists. Regions from which attacks can be made with impunity exist, and are well-connected to global data networks. Backups alsone are not an effective defence as these protect against data loss but not data disclosure. Full defence will require radically different thinking, protection, risk assessment, and law-enforcement capabilities. Until then, get used to more of this, at both large and small scales. There are some potential bright lights. - I suspect attackers aren't targeting specific facilities but are instead conducting automated and scripted attacks against vulnerable facilities. - For data-encryption ransom attacks, this means that the decryption key is all but certainly derivable from information on the attacked system, perhaps encoded as filenames or contents. Determining this mechanism may at least allow for data recovery. (It of course does nothing against data disclosure, long-term surveillance, or access denial attacks.) The likelihood that attackers have some database of victims + passwords seems low. - Attackers are themselves subject to trust and suspicion attacks, and turning members or safe-harbours against attackers is probably a useful countermeasure. - State-level sanctions, flling short of military attacks, may also prove effective.
- Animats 5y agoOh, that's going to annoy some rich people.
- tobesure 5y agoDo these recent attacks (pipeline, meat plants, steamship) have anything in common? Do they share exploits? Are they related to or enabled by the solar winds hack? Or is this just media amplifying what are otherwise routine events now?
- sebyx07 5y agoMS Windows is 100% to blame. How can a worm spread that easily in 2021 to pcs across the network? 0day trash windows exploits
- the-dude 5y agoWell, the Steamship Authority, what did you expect?
- king_magic 5y agoRansomware attacks against the United States should be met with covert assassinations against these hacking groups on foreign soil. Enough of this insanity - these are acts of war, and those responsible should be dealt with through covert, proportional military strikes.
- sonofhans 5y agoWhen was the last time covert assassinations or military strikes actually solved a problem? Mostly they inflict further suffering. Mostly they affect people other than the perpetrators. These are unlikely to be acts of war. War requires state-level actors, who are interested in geopolitical changes, not piddling little ransoms. What you’re talking about is revenge, not justice. Each of those done well breeds more of itself. Successful revenge breeds more violence and hatred, leading to more revenge; look up the history of vendettas. Successful justice breeds more justice. Societies should choose the virtuous cycle, not the vicious one.
- king_magic 5y agoYeah, sorry, I don’t buy that line of thinking. These are most likely state actors operating on behalf of the Russian & Chinese governments. These are absolutely acts of war, and I wouldn’t lose a second of sleep if American lead ended up in these actors. Covert assassinations here aren’t justice. They are deterrence.
- LatteLazy 5y agoHas anyone looked at or tried to quantify the effects of paying ransoms for kidnap victims in the middle east and north africa? That's the most comperable thing I can think of...
- VectorLock 5y agoCyber privateers sounds like an interesting idea. Except instead of hunting criminals they hunt for victims. The government pays them bounties, then goes to the victims and says "We're fining you $X, and $Y per day until you fix this."
- joebergeron 5y agoInteresting -- I was just in Woods Hole earlier today, and in fact saw this article pop up on Hacker News while walking by the Steamship Authority. Always strange to see your small slice of the world crop up in places like this. On that note, the Steamship Authority is such a fascinating choice of target for such an attack. Probably very low friction, as I can't imagine they have any sort of sophistication behind their technology stack.
- tacosaretasty 5y agoAs someone who works specifically in this subgenera of computer security (ir) I can say a few things that might add to conversation in a meaningful way. 1.) There is a cottage industry in this space that sells kits for these randomware compromises. Everything provided is off the shelf, this is why you’re seeing such an emergence in this space. It’s not that the barrier to exit from a ransomware attack cost decreased (cryptocurrency). The barrier to entry lowered, any jerk can pay a small amount of funds to buy a software kit and instructions on how to do it. Furthermore this is also why you’re seeing so many public defacement go politically neutral (ironic given the times). It’s simply a relatively lucrative, with a low amount of risk, and only requires the technical aptitude of someone capable of using BitTorrent/Tor/Warez. 2.) Hiring / Managing security teams - unless you’re in technology or selling security as a part of a product you can’t afford a quality team/tools. Most business are trying to optimize their cost centers to maximize their profits. As such most of the time that means it’s a race to the bottom to get them to be “insurable”. Salary + Software is expensive. 500k minimum investment for an meat processing company or whatever is not the easiest pill to swallow. 3.) companies that pay this are not good judges of security talent. They don’t know if the herjavec group really is an effective detection company. They judge almost entirely on feeling. Same with that one fast talking hoodie wearing self proclaimed hacker talking out of their ass. Not understanding what you’re hiring for also creates friction, since any deviation from the fantasy security hire they imagined will be met with extreme resistance. “I thought they were going to sure up our servers, why do we have to log in on our email every 8 hours now”. Often times when an executive leader does not understand why security trade offs are made they just make the decision themselves (pro tip they’ll accept the risk) and you’ve failed regardless as an employer and employee. 4.) the industry does very little in a practical sense in preparing people for these job functions (with a few exceptions). Security engineers often have technical skills in spades.However, if they don’t understand anything outside of security they are going to fail. Civil Communication/ debate, the ability to navigate political issues, understanding the business etc are actually super important. The biggest tragedy was that someone internally probably saw this coming but couldn’t actually get the messaging across. When you combine all of these elements you have a confluence of shit. It’s once again getting less expensive to perform a wide attack with little know how intersecting an industry that has yet to course correct.
- jacquesm 5y agoInteresting how everybody focuses on the things that they know about: technical solutions, legal solutions aiming at the victims, payment options and so on. When the real failure is somewhere else: bringing these perps to justice. The fact that they can get away with this over and over again hiding behind anonymity is what enables these crimes.
- creato 5y agoI think a big factor here is IT people jumping at the chance to say "I told you so! Triple my budget!" I agree the problem is that these criminals are sheltered from prosecution.
- biztos 5y agoShouldn't it at least be possible to identify them, by following the crypto addresses until someone cashes out? I get that you might not be able to do anything about it if they are sheltered from prosecution where they cash out. But I don't get why we can't at least, to some reasonable degree of accuracy, say Address A took the ransom and eventually it ended up with Address Z cashing out through Exchange B. Then if either Exchange B or Address Z has anything at all to do with the US-dominated international financial system, you've got serious leverage. If I'm Coinbase, am I not worried about unwittingly laundering money for terrorists? Don't I have a staff trying to prevent that?
- Gene_Parmesan 5y agoUnfortunately this is significantly harder than you might think. The perps tend to be citizens of countries who happily turn a blind eye to their activities so long as they aren't infecting their domestic systems. What interest do Russia or post-Soviet states have in prosecuting cybergangs that destabilize Western business and infrastructure? I mean, maybe we can create such interests/motivations, but now we are talking about a major geopolitical issue. If major infrastructure continues to be hit I think we will eventually see this happen, but we absolutely cannot count on foreign states to 'do the right thing.'
- dodobirdlord 5y ago
- jl2718 5y agoWell, I’ve been shouting this from the rooftops for a while now, and finally they got my lifeline. Ransomware in cryptocurrency could be easy to stop naturally. Miners just need to know that there is a nonzero chance of their blocks being forked off if they help them. It’s a technical problem of out-of-band governance protocols among miners, not unlike what is already being done for positive gain (MEV) by FlashBots. That’s the incredible possibility of cryptocurrency. It’s designed to turn selfishness into a public good, with no coercion, recognition, or good will. And sure, they could include a massive reward to convince miners to include the block, but then that also goes for every coinbase and transaction afterward, until there is nothing left, and no incentive at all for ransomware. The present reality, of course, is that miners are just not that sophisticated. For the most part they’re just aping the repos that are released by the foundations. But the foundations certainly should understand that it’s in their interest to protect their currency by at least giving the miners information about transactions in the mempool or utxos, and perhaps some kind of out-of-band signaling mechanism to indicate unwillingness to accept blocks that include them. Perhaps better yet, a price for inclusion demanded in the form of an MEV burn added to the next block, which would of course fetch its own price. There is some criticism of the foundations here, as there is also some criticism of some PoS implementations that do not allow fork selection, but ultimately I think that they can solve it. So that takes care of economic hackers. I’m far more concerned with non-economic or peri-economic agents. There is a doctrine of “unrestricted warfare” that everybody should know about. It explains many things about how and why things do not make sense. It is because we are under attack, and it’s a truly brilliant offensive, for which all of our defenses only work in their favor. I don’t have the answers for this. But it does give a warning. The effect they seek is not the damage they’ve done, but our reaction to it. Our reaction, by regulation that cripples our competitiveness, by restricting our own freedoms, could be disastrous to our country and our way of life, which is exactly what they want. And these attacks, although they may be carried out by economic agents, almost certainly find their roots in exploits created by long-standing programs of infiltration. Nature too, has learned this trick; SARS kills by turning the immune system against the host.
- rurban 5y agoSo why is HN steaming over this? It's the classic antagonist to the Colonial pipeline hysteria, which stopped their pumps because they would not be able to account for the exact gallons delivered to which customer. So they rather stopped a critical infrastructure. Hilarious. Plus Windows. Here again the Windows office PCs were affected, but the steamships themselves didn't care much. They kept going, you only had to pay for your ticket onboard, not online. Online reservations were not honored.