6 ms·
Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 y
by alksjdalkj 5y ago
Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.
- xkyf 5y agoThat gets discussed every time, hackers were using prepaid cash services. Ransomware predates cryptocurrencies by decades.
- viraptor 5y agoIt's a bit of the "we have X at home" meme situation. Sure, ransomware existed before, but the scale was not even close to that. You can't move hundreds of millions in gift / prepaid cards without getting found. It's a completely different level of comfort for the operators.
- anonymousDan 5y agoDo you have evidence for this claim? I'm almost certain it's no longer true.
- mandelbrotwurst 5y agoHow do you know that we’re not less secure? It wouldn’t surprise me at all if our systems are on average far less secure simply because so much more is online now, to speak nothing of increases in the complexity of and opportunities for errors and misconfigurations in today’s systems.
- user-the-name 5y agoBecause twenty years ago computer security was an absolute and utter shambles. Exploiting a vulnerability today is orders of magnitude harder than it was twenty years ago. Massive strides have been made.
- mannerheim 5y agoJust a couple years ago, the largest botnet in history infected IOT devices using default passwords in order to DDOS Minecraft servers, so perhaps these strides haven't been so massive.
- Grimm1 5y agoIOT isn't datacenter server technology. IOT is basically in the state of software security from 20 years ago. Often running crappy proprietary stuff. Your average server running a recent Linux kernel is Fort Knox comparatively. There have been massive strides in many places in software security but IOT and embedded security in general is very lacking unless your talking things going into space or military.
- dopidopHN 5y agoThe S in IOT stands for security, after all.
- rurban 5y agoThe S in Linux ditto. Linux has a far wider attack surface than my baremetal embedded firmware. Like 10^6 wider. There's a single mqtts service mostly, or just passive senders (sensors, controllers). Zero attack surface. Linux is way too big, with thousands of drivers, services and patches.
- tartoran 5y ago> Because twenty years ago computer security was an absolute and utter shambles. Exploiting a vulnerability today is orders of magnitude harder than it was twenty years ago. Massive strides have been made. Yes but once an exploit is found it can be tried on a whole lot more systems and the weakest link becomes a target. There is also a lot more interest hence brains in hacking/ransomware. I lot of critical systems should simply be airgapped
- DharmaPolice 5y ago
- karaterobot 5y agoGranting your premise, but: what is there to discuss about it? Cryptocurrencies are good for this, yes. I am inferring (perhaps incorrectly) that you're saying this is an argument against cryptocurrencies. I think that's beside the the point: even outright outlawing cryptocurrencies wouldn't stop the technology from existing, and wouldn't discourage extortionists from using it to anonymously receive payments. It would make it harder to pay, since you'd have to go outside of safe, legal channels to get money into the system. If the best strategy when being extorted is to never pay or negotiate, then I suppose that could be a benefit. But, in that case it would be more efficient to just make it illegal to cooperate with extortion in the first place. For all I know, this is already true. If not, let's try that first. If it is, it doesn't seem to matter, since people are paying ransomware hackers. Still, if paying at all is illegal, but people still do it, then making paying less convenient probably won't make much of a difference: they'll still ask for payment in crypto, and leave the logistics up to the victim.
- lvs 5y agoBut the genie is out of the bottle now. It's not going back in.
- dopidopHN 5y agoI always wondered if it’s was possible. Without looking. Now, I know?
- f38zf5vdt 5y agoThis level of corporate hacking existed prior to cryptocurrencies, the difference is that it was used for stock market manipulation and profiting on short or long positions. It appears that this is even more profitable than ransomware, in the hundreds of millions or possibly even billions of dollars. [1][2] [1] https://www.wired.com/2010/03/manipulated-stock-prices/ https://www.wired.com/2010/03/manipulated-stock-prices/ [2] https://www.reuters.com/article/us-cybercybersecurity-hacking-stocks-arr-idUSKCN0QG1EY20150811 https://www.reuters.com/article/us-cybercybersecurity-hackin...
- goatsi 5y agoYour comment makes it sound like stock markets were manipulated by hacking the companies that issued the stock. In one of your stories brokerage accounts were compromised and used to pump penny stocks. In the other someone hacked a few companies that distributed press releases to get early access to them and traded on the information. Stocks weren't even manipulated in that case, they simply placed trades based on how they thought the market would react to the news. That was a targeted attempt to get information, not a destructive attack on the entire company network.
- f38zf5vdt 5y agoYes, so both manipulation and put/calls were leveraged by hacking as I specified. I think there is a disconnect in my communications. In these cases the penetration (hacking) was the same but there was no data destruction. Ransomware appears to be a less profitable and less clever use of hacking.
- lmm 5y agoFrom my memory the profits from such attacks were remarkably low. In particular it's very striking that the hackers who compromised JP Morgan couldn't find anything more profitable to do with that access than send basic scam emails to their client lists.