Apparent hackers behind Kia ransomware attack demand millions in Bitcoin
thedrive.com
thedrive.com
Cars had remote unlock and start decades ago (if not OEM, then aftermarket systems were and still are widely available), with zero dependence on what appears to be the company's servers. The only advantage I can fathom for being able to unlock and start a car over the Internet instead of only by being within radio range seems more oriented towards attackers and other user-hostile scenarios ("your car has now become a subscription, please pay to unlock it"). Have we gone backwards...?
The equation everywhere is "the cost of the security is always too high because the failure of security is always an unusual situation and something that usually works and is cheaper will win in the marketplace."
Have we gone backwards.
Yes, expect more of this.
When IKEA introduced cloud devices, IKEA hardly a company known for high prices or using expensive stuff in their products, they had local fallbacks. Their product is competing with the reliability of less expensive devices controlled with a light switch. Locks are another case where if you reinvent the wheel and get significantly less reliability people will be mad.
Yet... here we are. Entirely predictable.
The last one such event (also with blackouts) happened in 2011 and was generally called "1 in 10 years cold snap."[0]
Not weatherizing for 0.1% chance can be acceptable, not doing for 10% is not.
New technologies aren't nessecarily robust against misapplication
Never operated a fleet, though - so that's my speculation.
The first post-merger models like Sandero were based on a stretched Renault Clio 3 platform.
The new ones are built on the Renault-Nissan CMF-B, as are new Ladas.
Your car might be parked further away than the radio distance, especially if you're living in a big city with few parking spaces. There are also a lot of scenarios where you are not at home but want to preheat your car anyways.
I don't understand why after this people weren't in an uproar.
https://www.nytimes.com/2017/09/11/business/tesla-battery-ir...
When Tesla decided generously to temporarily grant residents fleeing a hurricane an upgrade that allowed full usage of their battery.
People's lives were literally in the hands of an optional, upsold firmware softlock.
The fact that it's come to that is completely appalling. When the manufacturer of your car has the power to save your life because if they didn't they'd suffer bad publicity is disgusting.
And the fact is, the only reason why hackers are able to gain access to vehicles, the only reason for any of it is because companies have decided cars need to be a service provided by them so they can keep making money after the initial purchase.
People buy cars so they can travel freely without relying on others. Making cars reliant on a third party server for something as basic as the ingition goes against the entire premise of owning a car.
People's lives are literally in the hands of optional firmware softlock all the time in medical devices that you can find in hospitals. If the hospital doesn't pay for x feature or for support technicians to service them, then some people could actually die.
Saving lives or not, you can't blame a company for not giving you for free features you haven't paid for.
A beautifully stated maxim I’ve never been able to articulate. As an immigrant from the USSR to the US, I believe this mentality is what separates the First World from the Second.
Damn this is heavy.
My workplace is currently struggling to sell a more expensive device, where in the majority of the cases it will offer no advantage over the original device, but in some cases it will be life saving.
Naturally, many health services are dragging their feet on wanting to buy our device.
I agree with the OP that it is a disgusting business practice at best, and totally indefensible.
[1] https://www.agriculture.com/machinery/repair-maintenance/rig...
Who's fault is it? The person who dies because they couldn't afford a firmware unlock which in most cases is a sunk-cost that's locked purely to produce profit?
Sorry -- that's too much of an ethical/moral opinion -- and honestly edges near victim-blaming; making lots of money in life isn't something that is guaranteed by any shot.
I'm of the opinion that anyone with actionable ability to change a situation -- and then chooses not to act on that ability -- is to blame for the situation progressing.
I hope and wish for public companies to attempt to act altruistically -- and the ones that don't should be held responsible by their audiences. The BioMed profit schemes out there are devious and for-profit-engineereed, no doubt about that; commonality doesn't make those practices morally appropriate, though.
Its plain rent seeking and frankly should be illegal.
Start producing two separate models of you product, greatly complicating supply chain and logistics
Discontinue old product and produce only improved version
Produce only new HW but introduce software switch, to allow users to keep purchasing cheaper product without new feature, while simultaneously allowing users who need new feature to pay premium to cover your development costsYeah, you can.
The batteries have been already manufactured and you physically have them in your possession as they are there in your car; they just chose to artificially cripple their capacity in software.
If not, then it is no different at all from someone dying in a Ford Focus that was only front wheel drive where all-wheel drive would have saved their lives.
If the FWD version also came with all the parts that the AWD one has, but they were simply disabled in software and only acted as dead weight, people would be just as furious (and no doubt someone would find a way to reenable it.)
Tesla restricts your battery usage for battery life purposes.
This allows them to sell you a vehicle that has a charge matching what they claim while also having a battery life matching what they want it to be.
SSDs work similarly. You don't sell 1 TB of SSD storage you sell slightly more than 1 TB worth. Then you wear level between cells to ensure the whole thing lasts a lot longer. (Batteries are nice because losing a cell isn't losing data but the fundamental strategy isn't anti-consumer)
Imagine cars came with governors for instance that could restrict speeds and acceleration to limit wear and tear on a vehicle and provide the consumer with a lower cost upfront thanks to less warranty work needed. Similar concept.
I thought on the checkout page Tesla was pretty explicit that they were selling a 75 kWh model with discounts thrown in for artificially software-restricted 60 kWh version.
If an ICE brand sold two trims of the same vehicle - the cheaper one with the smaller tank or worse fuel economy, is it as appalling and aren't they endangering the drivers of the budget version?
Consider how you would do this with a battery. The battery has to have extra cells in order to have extra capacity, and the software allows the user to use or not use the extra cells if you pay for the privilege. But if one of those extra cells fails, the entire battery pack does as well.
In your example, the hardware IS configured differently, and there's no sense of waste or increased failure therein. You bought a car with a crappier engine or a smaller tank, and that's what is in it. There's no software key to fix it. Something about the idea of software letting you access hardware you already paid for (even if you didn't pay for the software to use it), just feels wrong.
What kind of warranty does Tesla have on the batteries? Is it conceivable that a firmware change that prevents fully topping up or fully discharging the battery statistically saves Tesla money in its warranty costs?
But your argument suggests that auto manufacturers will be penalized for making premium features easily upgradable, and lauded (or at least given a free pass) for selling premium features that are pain in the butt to get upgraded, even when it’s artificial busywork.
E.g., the navigation maps on my 2013 Lexus can only be updated by the dealer and carry a $1,500 fee. There are obviously easier ways to make the navigation upgrades easier, but I suspect if Lexus made it too easy, that would land them in hot water with the same kind of argument (and probably generate quite a bit of wrath from the dealers).
isn't this what iPhones do, at the end of the day? in effect, by not being able to load applications of your own choosing, you accept the implicit limiting effect of the software you're given, similar to the bargain (?) described here.
I would like governments to make this clear in law, but I understand why some people feel might feel this is an overreach.
We can try and avoid buying hardware that has software restrictions, but without laws ensuring we can run whatever software we want on our hardware, manufacturers will take these rights away from us.
We are living in an age of environmental catastrophe, and I think we need to appreciate our physical things more, build them to last, and have laws that help us get the most out of the things we build.
Are the manufacturers benevolent in this? Not always. Sometimes an 8 core chip will be locked to 4 just to make more lower end SKU pieces available for purchase. Or Intel disabling overclocking so you have to buy a “K” processor that costs more.
But when people say things like:
> When you buy physical things, you should be paying the total cost for the hardware to be manufactured, distributed, and finally recycled or disposed of.
They’re ignoring the fact that soft limits actually can make manufacture cheaper. The reason Intel/AMD/etc don’t have a separate silicon template for every SKU is it’s too wasteful (money wise). Each run has a setup cost, and if that can be lowered by reusing the same wafer template, they do that. It’s cheaper to have less manufacturing SKUs and just disable features later.
In addition, when soft limits are used on chips, it actually prevents waste. Imagine if the yield on an 8 core wafer was 70%. That means only 70% of the produced chips works at spec. The other 30% would be tossed if binning didn’t happen. By binning, that 30% can be sold (with reduced feature sets).
I think you missed the point. If the chips are not stable or have a problem core, then fine, dial them down and sell them as capable of doing less.
But if a chip _can_ do x+y and but you lock y away because you don't want your customers doing y, then there is a problem we should address.
If they didn’t do this everyone would be returning the 6 core versions of a chip until they get lucky and get the 7 core. People already do this a little with overclocking capable chips.
Maybe you’d argue they should sell a 7 core chip as well for a slightly higher price but that also means having more product lines and increased manufacturing costs as a result.
Wastefulness may be distasteful, and you are welcome to boycott companies you feel are wasteful, but I don't think wastefulness should be a crime. If it's cheaper for Tesla to store unusable battery cell tech in your car than to throw it in a landfill, do we really want to make the landfill the cheaper option?
The end result is the same, isn't it? An unused battery cell that is driven around until the car is scrapped and goes to landfill. The case could even be made that carrying that extra weight for the lifetime of the car is more wasteful than throwing it away at the start.
I think more likely, if such wastage were a crime or at least financially discouraged, Tesla would do the obvious thing and just design a more modular battery with a way for them to either install or not install the extra battery cell, which is a much more desirable outcome than the current situation of wasting battery cells.
Wasting the planet's finite resources should be discouraged, either by law or financial disincentives.
A company produces an item with two features A and B. It costs the company $200 to build a fully featured item. It now builds two of them for the market but also realizes not everyone needs both A and B. Yet they'll still need to earn back the production cost of $400. So instead of selling fully featured items for $200 they sell one soft-locked version with only one feature for $100 and the fully featured one for $300. More people who can benefit from the product/more customers while still earning back the $400.
I made this point in another thread but this seems to be appropriate too.
If you use an iPhone or android you are under a similar regime. The hardware is capable of running any set of instructions that can exist. But it is artificially restricted to the subset found in the app store.
You can pay an extra fee to partially unlock it. You still cannot fully utilize it though.
Intel, AMD, and NVidia still do this. If anything, they're better at it today than they were back then.
In the 1970's Opel sold a model (the 'Kadett') that had an optional RPM indicator. But in reality all cars had that indicator installed, if you paid to buy the option the dealer would remove a blank plate that obscured the indicator.
Are these things bad? Maybe, but if you were the manufacturer would you rather source 2 (or 15) different components or just use 1 and modify it to fit the need and price point?
I wonder how long before there is a large enough backlash from customers that "works fully offline" becomes a marketing label.
The whole 'lets smartify everything', 'control everything' or even 'collect usage information' is exhausting. We have collectively given up our freedom in the name of 'comfort' and often for features that nobody really needed but became mainstream.
[1] https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
Do you mean buttons on key fobs? That's not what this is about. This is apps on phones that let you access the car. Why would you want to do that? Range of the signal, additional functionality (you can see the fuel level for example), and you don't need to have your key fob to use it.
Luckily now I live somewhere with good transit options, and haven’t owned a car in years.
There's still no need to make it go out through the Internet and back again --- even Bluetooth has more than adequate range.
In fact, I'd argue that the limited range is a benefit, because it prevents some hacker anywhere else in the world from manipulating your car.
The range of Bluetooth for consumer devices like phones is about 20m...
Lots of consumers disagree!
I find being to see the state of my car and control it remotely very useful. I’m happy to accept the downsides for the additional functionality. I think many consumers agree, given how much they’re willing to pay for it.
The downsides being full remote takeover in the worst case, which has the potential to kill you. It seems unlikely you're happy to accept the downsides.
I feel like there's a group of consumers like myself who do agree but aren't being given options.
I'm personally dreading buying my next car because everything is #internetofshit, software-locked features and shitty touchscreens that are totally unsuited for using while operating a vehicle.
My current car isn't connected to the internet and my next one won't be either. I'm hoping the companies come to their senses before my next purchase, but I'm not holding my breath.
I think techies need to understand that sometimes, it's better to be cold for five or ten minutes than find out the car's servers are down, or the battery in their fob is dead, or they are in a place where the car can't connect to the net. The high potential cost of convenience is there, even if it is rare.
I for one genuinely enjoy getting my arse in the warm vehicle rather than scraping the iceball of a car for 15 minutes.
As are ~90% of the features on the window sticker of any modern car.
Sort of. A lot of this is pushed by fleet sales, where it makes more sense (to the customer).
This would only break the mobile app's ability to unlock the car, for example if you misplace your keys.
It's kind of an annoying solution, but it sounds like a bit of a security risk to just let someone permanently stay logged in to an app like that without requiring authentication every once in a while.
Unlocking and starting from the app make sense, but that doesn’t mean it will allow you to put it in gear without a hardware transponder.
Systems designed by and for users lose control to business interests.
Leading to streaming over media ownership, as we become renters in every domain.
Movies, shows, music, video games. “To improve the consumer experience” reads ever closer to “with DRM we can charge subscriptions in perpetuity (telemetry’s just a bonus!)”.
Why would I want or require internet to play a single player computer game? At least with cars, perhaps we’ll begin to see some pushback.
Yes, I think this is a reasonable conclusion from your priors.
My car isn't from Kia, but this is not unique to Kia. I eventually personally found the microcontroller and shorted the modem myself, after doing extensive work to figure out how to do it without breaking anything else.
https://www.cbc.ca/news/canada/montreal/quebec-man-fights-ba...
I would think that breaking the antenna would be easier.
Or are they not that large anymore since car bodies have so much plastic in them these days and not so much metal to interfere with the signal?
(perhaps silly?) question - why not just disable the antenna or put it in an appropriate faraday cage?
The antenna on the body of the car is for XM/FM/AM radio and is only a receiver. It's not connected to the cellular modem in any way at all as far as I can tell (apart from being attached to the same car).
It'll vary for each manufacturer, but in my case shorting the modem was trivial once you knew which pins to connect.
Why do you think that? It provides valuable functionality that I use, such as journey logging, fuel status, access from an app, and so on. You need an intermediate server run by the vendor. I can't give it my phone's IP address, can I!
Zero management need by the customer.
In this environment the vendors doesn’t get to watch and inspect the content of what’s transmitted, their devices don’t phone home, and the service is trivial to restore because they’re pretty much stateless.
Try setting up a generic wlan-compatible printer and a macOS laptop on a local network. I have such setup, and it is just fails every once in a while for no reason.
I would not recommend this to anyone over well-run centralized server.
1. Why couldn't you give it your phone's IP?
2. You could just as easily use USB, Bluetooth, or local wifi, none of which require anything other than your phone and your car.
Because my phone frequently changes IP as I connect to different networks. It's dynamic, not static.
> You could just as easily use USB, Bluetooth, or local wifi, none of which require anything other than your phone and your car.
USB is wired.
Bluetooth requires me to by physical standing by my car.
My car and phone may not be on the same WiFi.
If you want to remotely start your car to warm it up from a mile away, then by definition you're not going to be sitting in your car connected with a physical wire, are you?
And whatever your IP was the last time you plugged in may have changed by now. Do phone networks even let you accept incoming connections from non-approved services?
Does not compute.
> The vast majority of people would be fine with a setup that syncs their phone and car when they're in the car, though
I think demand for wireless car functionality in practice in the market (it's often an optional extra - people pay real money for it) shows you you're wrong.
Oh, yes, in that case we're totally talking past each other and you have a completely valid point. I was originally responding to:
> journey logging, fuel status, access from an app
which should be perfectly doable locally, but agreed that [very] remote start is likely to need some sort of intermediary.
> I think demand for wireless car functionality in practice in the market (it's often an optional extra - people pay real money for it) shows you you're wrong.
Possible; it certainly wouldn't be the first time that I had very different preferences from 99% of the population without noticing...
I'm not sure that's clear. Almost nobody custom orders options on cars anymore. They take what's in stock or readily available at the dealer, and those are mostly the fully-loaded models.
Yes, they are buying it and paying for it, but do they really have a choice?
I think this is a uniquely American thing. In Europe, Asia, etc, most people custom order a configuration on a website that’s then built at the factory and delivered to the dealer where they pick it up.
My SO absolutely loves being able to enter a heated (winter) or cooled (summer) car for the drive home from a cafe, restaurant or similar.
Parking for these activities is seldom within direct phone range (BT/WiFi), so would have to be something else.
You could say: "but I want to configure my car to upload data to a different pod" -- but this is possible today. If there were an interest, the car could ask for WebDAV / sftp / webhook address + credentials, and put telemetry there. But manufactures don't do that because there is not enough interest for this feature to justify development + support costs.
Or alternatively that you live in an apartment complex where your vehicle does not reach your personal router.
My house thermostat is failing. Many segments on the display don't work, the programmable bits no longer work, I woke up to a frigid house last week.
I went on amazon.com and looked at thermostats. Internet connectivity galore, fancy phone apps, full color LCD displays, dashboards and logging, the works.
I bought an $18 model that has a weekend/weekday programmable schedule. I know I can't trust these vendors. They care entirely too little about my security.
Some day I may sit down and build myself arduino-based thermostat, but that day is not today.
>After the publishing of this story, numerous Hyundai and dealership employees contacted BleepingComputer to state that Hyundai was also affected by unexplained outages.
>In emails sent by Hyundai Motors America to Kia dealerships on Saturday and seen by BleepingComputer, Hyundai stated that multiple systems were down including their internal dealer site, hyundaidealer.com.
[1] https://www.bleepingcomputer.com/news/security/kia-motors-am...
Monero markets itself to criminals. Bitcoin to speculators and ancaps. You can hide your BTC gains by saying you made some leveraged trades in Malta. You can’t hide your Monero gains. Ironically it’s what makes it better at its job that makes it less useful.
You really want to toe the line.
For more than half a decade many bitcoin invoices have actually been paid with Monero and we don't have a way to quantify that except to participate in forums where people talk about what they do. The merchants wouldn't even know if thats what happened.
For every XMR.to that shuts down, another has already risen and is just waiting for marketshare.
There are also trusted bridges between blockchains.
And people are still working on trustless bridges compatible with Monero, which will really unlock its value and make exchanges completely ignorable.
Ultimately the state will never accomplish its goal of strongarming the intermediary.
Wow it’s like reading 1984. The uh, first part of course, not the end. If you haven’t read it I don’t want to ruin the surprise.
Monero is compliant with all FATF goals. The state has gotten used to surveillance of digital transactions over the past 50 years by deputizing financial institutions, this was a temporary convenience for them and now digital transactions don't require financial institutions, which is simply a reversion to a mean with a millenium of precedent. For now they can strongarm the intermediary as they havent even noticed that they’ve just been taking a convenience for granted, but the reality is pretty clear: the state will have to deter whichever activities they dont like by actually investigating and stopping that person as regulating/strongarming the intermediary wont be a tool they have anymore.
This isn’t a new game lol, it’s been played to death and one side has a lot more experience than the other.
I’d suggest you’re in the wrong century, I’m thinking when Isaac Newton lost all his money in the south seas bubble. 1700s?
I had never heard of this!
https://royalsocietypublishing.org/doi/10.1098/rsnr.2018.001...
yeah we've been over this before, when a client outside the US wants to pay find me another way to convert an international wire transfer (high degree of delay including increased scrutiny) to a domestic wire transfer (low degree of delay, no scrutiny) that doesn't use a cryptocurrency network.
the transaction fees alone of that one use case makes the native cryptocurrency scarce, even if that native cryptocurrency is not what was used to settle the transaction.
and I've done inter-Europe transfers too, the SEPA system is not what its cracked up to be. It is even more fragmented, transactions between some combination of SEPA nations can take 2-5 business days just like the US ACH system.
from what I know about this discussion is that each use case is its own conversation, so I randomly chose this one out of a hat.
The people buying goods online are not usually very tech savvy, so you lose a lot of potential customers by requiring a difficult-to-acquire cryptocurrency. Those selling the goods usually know what's up though, so they're still going to be doing the BTC->XMR->BTC->exchange swap in order to hide their identity.
edit: You would be surprised how dumb some people are online though. Nowadays folks are a bit wiser, but the original silk road got taken down because they used hotmail, lol.
Wouldn't this just shift the risk to the exchanges who are now holding tracable proceeds of crime?
To my knowledge, there is at least some amount of identity verification on the major exchanges, so presumably that they're fronting with stolen identity documents and the exchange is the one "holding the bag" so to speak?
Also, it's pretty much impossible to fraud Coinbase/Gemini/etc. since you need to hook it up to your bank account, right. Ergo, no one is sending BTC (even if it's "clean") to an exchange hooked up to their bank account. If someone is thorough it's highly unlikely that clean BTC will get them imprisoned, but the IRS might take a hefty cut that vendors of course would prefer to circumvent.
Many vendors also don't cash out until they're completely clean, if they can afford to.
Existing transactions cover other usecases just fine
When you transfer to a bank account, it cannot move out of the country's jurisdiction without triggering multiple regulatory touchpoints. It's not easy to cash the money out overseas.
But when you transfer bitcoin, it's done once to a virtual ID. The person receiving doesn't need any online account. You can't trace anything here. It's just "sending from wallet id X to wallet id Y". wallet id Y is just a cryptographic key known to the sender and receiver. Yeah so this "virtual ID" is replicated across the network, but who cares. It doesn't point to anyone yet.
After this single step, there is no jurisdiction. The hacker can travel and cash it anywhere in the world outside jurisdiction of the host country's law enforcement.
So how do the coins evade that since any transfer is traceable on the blockchain?
Not being able to do business with any business that does business in the United States is a pretty big deal. Not to mention your executives not being able to travel anywhere with an extradition treaty.
“All outputs in the Bitcoin transaction with hash <...> are illegal to redeem.”
This, however, means that criminals (who don’t care about the law) can still use these segregated Bitcoin to transact between themselves — as long as miners aren’t punished by including the illegal transactions in new blocks.
You make trade-offs, which is fine until you pretend like your set of trade-offs is the best set, and everyone else is wrong.
New tech being abandoned down the road doesn't help any of the poor saps who bought that new tech.
It's not quite to this extreme, but IIHS did a test (https://www.youtube.com/watch?v=xtxd27jlZ_g) a while back that showed the difference in safety standards between a 1959 Bel Air and a 2009 Malibu. The Bel Air is about 5% heavier.
Probably less of a worry in a 3/4-ton truck though.
https://www.bleepingcomputer.com/news/security/kia-motors-am...
Btw, not to mention that New Cars are becoming too expensive compared to say 15-20 years ago due to all this "tech" while the engines are becoming crappy with plastic (shout out to famous youtuber Scotty Kilmer if anyone knows him :))
The next sucker down the line though is in for some severe finacial pain.
watching transactions on a blockchain is a wild goose chase that relies on amateurs making stupid mistakes.
Money laundering IRL is hard - and compared to cold cash, bitcoin is accepted in very few places so it cannot be easily off ramped
So I am going to guess bitcoin in crime is mostly like stolen artworks. Someone steals the painting and a newspaper says "20 million dollar painting stolen" and they can use it as a deposit on a drug deal (maybe at 200k worth).
At a guess bitcoins are passed around from phone to phone, part-cash part-BTC (like part cash part shares buyouts). Just the ten minutes wait for the transaction to clear probably involves people nervously fingering guns.
Of course, signal analysis helps here too. If I am right then there is a ring of transactions all of which are dirty, and if you break one through poor ops sec (same phone used for drug deal and for day trading) then you get a ton of good info. If someone used a burner phone for that one transaction then it's hard - but how many ur ed phones were turned on just once in a given city at a specific ten minute window. And now how many phones were on that same cell tower when that came online .
Yeah these things are traceable.
You dont know if a transaction was an exchange for something on a different blockchain
And even when you do know that, that just increases the ways for them to obfuscate and unlink. If they got ethereum or an erc20 token, it goes into an AMM, a layer-2 system or straight into Tornado.cash and its gone. Even if you did compromise Tornado Cash somehow in the future, you wouldnt know of the note was sold offline to someone else or again about the original depositor selling their ledger/private key.
If the funds were used to pump a different token, you wouldnt know if the criminal had different funds under their real identity that was just a benefactor of the price appreciation in the pumped token, indistinguishable from any speculator that got lucky. Tokens rallying in price 5,000% is not uncommon, someone with $100,000 in clean funds that already own the to-be-pumped token can sell a 50-bagger for $5,000,000 with no suspicion.
If that sounds too contrived, it doesnt even account for cloud mining at a loss and earning slightly less new bitcoin over time.
Or buying a bunch of actual mining machines and really mining new coins because the chinese vendor doesnt care about tainted US/EU coins. Can we even say that when one of those states seizes and auctions the coins off, that they are magically clean... everywhere? If the Myanmar disputed government did an bitcoin auction, would chainanalyis systems even factor that in, are those clean? Would you even know or would you still be following transactions around like “aha! I see you!”
Your assumption is that the original funds needs to be invisible and never tied to anyone’s identity, when thats not the vector at all.
Following a transaction around tells you nothing, and reintegration of tainted coins is exceptionally easy in unlimited-enough amounts.
Even major exchanges that require KYC still often have 2 BTC/daily thresholds before they require identification to increase that. Thats currently $120,000 per account per day. And thats the worst and one of the slowest ways of getting liquid given the possibilities of them freezing funds and requiring the user to be more careful and also quick.
If you receive Bitcoin which was originally received as a ransom, could you be held legally liable even if you weren't the thief? I suspect that such ransomed crypto would be forever tainted, as would anything ledgers that touched it. The US has a number of laws to criminalize comingling of money gained from criminal enterprise, doesn't it? This makes owning any crypto potentially dangerous imo.
Or is the reality that criminal and non-criminals funds are already being obfuscated regularly because bitcoin is 12 years old and people already thought of this problem a decade ago
when you trade your bitcoin out for Monero, someone else has received your bitcoin and its their problem.
did you just frame that person, or are the other people following the bitcoin transactions between addresses just wasting their time. do those people even know that one of the series of transactions they've been following for years was a trade for Monero? no, they don't.
this reality is indistinguishable between legal and illegal transactions.
for anyone passing by: the scenarios so far are based on starting with bitcoin, briefly swapping to monero, and ending with clean bitcoin. many people start with Monero, and only get the amount of clean bitcoin they need when necessary to pay for things, which completely alters the problems and solutions.
We can solve money laundering but it needs political will - write your congressman!
Is this one of those things that's completely trivial as long as you're willing to completely throw privacy out the window and make life more difficult for completely legitimate transactions, or is it really "just" political will?
There’s been plenty of examples of politicians deliberately hampering corruption and fraud investigations because they might embarrass the current government. Semi-recent good example is Theresa May hampering the serious fraud office in the U.K. [1].
Lots of this work can be don’t in a privacy sensitive manner, and without impacting legitimate transactions, but that would require the political will to do more than just pay lip service to the problem.
[1] https://www.independent.co.uk/voices/serious-fraud-office-na...
Too many big corps have been victimized to think that it can't happen to anyone. You must assume it will happen, and when it does you must have a plan to recover.
Somehow I hope that when, say, Toyota sees this someone somewhere pushes for better recovery plan / offline backups, etc.
If your data is important, you should replicate your backups to an append-only storage with a long retention period.
I've been using S3 in "Compliance" retention mode, which coupled with Glacier is cheap, and more importantly lets me sleep at night.
An LTO backup tape on a shelf might as well be stored in Fort Knox as far as a hacker is concerned.
I'm sure a few "out of control" cars causing mayhem would attract sufficient attention. The question then is whether it'd make the manufacturers reconsider their "always connected" stance, or just cause them to lock down things in a user-hostile fashion even harder.
Now you know one of the answers to the question of why am I scared of self-driving cars...
Also, I can pay my bill at kmfusa.com right now, so what does the article mean about not being able to pay on the loan?
I will say the standard two e-mails they send aren't being sent. They sent the "Kia Motors Finance Payment Authorization" from speedpay.com, but have not sent the "Thank You - Your Payment Has Been Processed" email from KMFUSA@servicing.kmfusa.com.cname.campaign.adobe.com yet. Odd. Money was taken out of my checking account.
Of course, if the intruders have the means to disable my car remotely, that is a much more serious issue.
There are always promises, wishful-thinking, hypothetical demand for a use case but it never materializes. Here are some:
BTC: Trade (edit: for goods and services)? No use since price is too volatile. Store of value? Tell me again after this bull run. Besides, what's different than LTC, or even Doge that defines a different value proposition?
DEFI: The infrastructure is there but people just use it to speculate. Never heard a real business borrowing in DEFI to finance, for example, shop renovation. The only use case I can come up with is miners borrowing to buy miner hardware, since returns will be in crypto and will be implicitly hedged against crypto price inflation. Other than that, trading SUSHI or UNI or whatsnext is the only way.
NFT: What happened to CryptoKitties between last bull run and this one? NFT actually guarantees the uniqueness of the outer shell, not what's inside. Rare gaming items might be a use case, but why a game maker would use something it can't control, or fully extract value is beyond me.
But I think the ransomware attack is more on the Kia internal servers rather than on the cars themselves. The inability for people to unlock their cars remotely seems to be a side effect rather than a main target of the hacker group.
The bitcoindollar, negotiated by nation states with hacking syndicates to price all their contracts in bitcoin, forcing nation states to continually purchase bitcoin and is a key demand driver of bitcoin, and vital to diplomacy and hegemonic peace.
replace bitcoin with petro. same thing
If crypto become the payment system for criminals I wonder what will happen with crypto.
IF Kia pays the ransom, then they are arguably playing a willing part of the economy of Bitcoin.