Ransomware gang threatens to expose police informants if ransom is not paid
therecord.media
therecord.media
Basically "thanks for the report, should be fixed now". Such a normal workflow
An average person with a mundane office job that happens to be for e.g. a certain government agency (to stay with the example), indirectly causing all kinds of mayhem elsewhere that is largely beyond their comprehension, simply because it's all neatly abstracted away from them.
https://en.wikipedia.org/wiki/Banality_of_evil#The_Banality_...
"A million bureaucrats are diligently plotting death and some of them even know it."
(please don't try to read that wretched book on the strength of this single quote)
I think if person ends up in amoral/illegal group, eventually he will end up doing amoral/illegal/unethical things, there is no guard except to avoid such groups proactively.
Writing these articles she made €5000 per month. It was a life changing amount of money.
Now she owns a 4-plex downtown and another 2 airbnb units. She has lifted her family into the middle-class thanks to this. Her employer profited millions; and they did no worse than the usa does to many other countries on a daily basis.
That tens of millions were had more to do with the fact that we'd been doing it to ourselves for decades than with your friend's additions to it. Oh, certainly she made everything a tiny bit worse, but I don't have any anger to spare on top of the deep enmity I feel for the people who teed up the situation in which she worked.
I have a sneaking suspicion that if your friend (and her coworkers) did something less despicable for a living it would not have made much difference. People right here carefully cultivated that environment of hatred and gullibility that your friend helped exploit. They're the real problems -- and they're still doing it.
From afar I loved the Donald! Wrecking the wreckers!!
For the rest of the world he was a much better choice than HC. She would have been dropping bombs, and using murderous robots just as Obama did. Much rather the USA is rulled by a selfish clown than some one who cares to use the horrendous weapons the USA has so many of.
Well done your friend!!
Organized crime gets to levels where it is essentially a competing government with an equally competitive consent of the governed.
That's why they have to be paranoid about gangs: they're embryonic states
I've listened to interviews with phone scammers before and basically their worldview is that they're ripping off some first-world asshole who would be just as happy to destroy the scammers own country if it could make the cost of consumer goods slightly lower.
I suspect working for a ransomware company would at least mean you don't have to pretend the awful things you are doing are for the greater good, and I suspect also contains a bit of the phone scammer view that the people you are attacking are ultimately your enemy as well.
It's far more surreal when I've had to check into work, plan all day how to rip-off or exploit users without losing them, and then be cheerful about what a great customer focused team we are.
That hits home.
I remember an interview with a ransomware-as-a-service business owner. He was pretty upfront with having grown up in severe poverty and being empathically impaired. Somehow when a greedy person is honest about it it makes it better for me. I feel like I know what to expect of him. It's the self-labeled good people who think that means justify the ends that make my alarm bells ring.
My friend a few grand on pretty useless talk meetings, but got his referral.
Gets his coveted time slot with the doctor. The doctor tells him today's fee is $450.00. Then $200 per month if I write a script.
The guy knew he was short on funds. My friend paid, and walked away. I didn't give him advice other than thing will get better.
(I look back on the biggest scammers, and most wore ties, and made their money legally.
Old phrase: The road to hell is paved with good intentions.
I suspect this hits home for a ton of people and applies to many people who don't (or are unwilling?) to realize.
I used to work for a company where their whole deal to make money was convince old people to enter their credit card and make them forget they ever entered it. Of course, I did not know this when I joined. I stayed for about 6 months I think.
Exactly the kind of excusing I would expect from the Harkonnens.
― C. S. Lewis
For example, to the extent that the various Communist regimes fall under this descriptor, C.S. Lewis may have a point.
Are you dismissing this out of some logical-positivist impulse, because you reject the idea that well-intentioned groups can behave tyrannically, or because you don't think anybody acts with good intentions?
Take the oil and gas industry for example. They have known for 40+ years that they cause global climate change while disavowing it publicly and funding fake scientists and interest groups to spread FUD about it. I think the effects of global climate change will be at least an order of magnitude worse than well intentioned busy bodies. Climate change doesn't sleep.
(You could easily say the same about the tobacco industry, advertising monopolies, social networking websites, etc.)
"they have known about climate change" and those who know about it also have said we'll be dead in 1980... 1990... the seas will rise a dozen feet in 2000 and the snowcaps will be gone in 2010. If the "tyrannical" companies are wrong...
https://nypost.com/2020/01/09/glacier-national-park-removes-...
https://cei.org/blog/wrong-again-50-years-of-failed-eco-poca...
If you want to go that route that Oil Companies are Robber Barons... that would make the GCC doomsayers the "good" guys who are as bad on the other end - and have no problem being as bad with their lies and happy about it because it matches their conscience.
what does that say about the doomsayers? Exxon knew? When did the doomsayers know that their predictions were bunk? They are the "omnipotent moral busybodies" who have no care that all of their predictions are wrong and the damage - past, present and future - of their lies? Who cares because they are "Saving the Planet"...
The point is that "actual" tyrannical robbers are bad - and there's no denying that... but so are those who are worse in the name of "good".
And how exactly is the "sjw religion" worse in the name of good? I get it. You don't like people calling you out if you do shitty things. But that doesn't make it worse than robber barons. Or even in the same ballpark.
Or do you agree that peoples lives should be destroyed if they do something you disagree with? Mobs of people calling the friends, family, work places, etc of someone who dares do something you disagree with?
I personally know someone who works in a rescue... someone got a bug in their butt that she did something "wrong". She's been hounded for weeks by The Righteous who have the Holy Word that she did "wrong" - no matter the nuances about what happened.
You can ignore the violence, the mobs, the hounding and the overall shitty attitudes of the SJW Religous... but they are literally the modern day Crusaders who have The Holy Decree to destroy the Heathens.
You want to know how SJWs are worse in the name of good? Open your eyes and look at all the "worse" done on a daily basis. I could list dozens or hundreds of publicly available examples but if you can't ALREADY see them without me pointing them out?
I happened to watch "The Battle of Algiers" last night and the scammers' sentiments reflect what the FLN commander Ben M'Hidi (insurgent/freedom-fighter depending on who you ask) had to say in response to questions about the civilian death toll:
Journalist: M. Ben M'Hidi, don't you think it's a bit cowardly to use women's baskets and handbags to carry explosive devices that kill so many innocent people?
Ben M'Hidi: And doesn't it seem to you even more cowardly to drop napalm bombs on defenseless villages, so that there are a thousand times more innocent victims? Of course, if we had your airplanes it would be a lot easier for us. Give us your bombers, and you can have our baskets.
I must mention here that I am not taking any ideological sides, and firmly believe that killing of innocent civilians, by any party whatsoever is plain wrong.
I suppose in any battle, ideological or otherwise, the actors involved come to justify their tactics as being in service of a greater, grander goal which also, at least in their minds, allows them to subvert responsibility and accountability.
villain - antagonist; evildoer
villein - peasant ranking above a serf
Works either way, though. :-)
Even Hitler and Stalin thought they were the good guys.
That doesn't mean one can't make moral judgments about which side is more or less evil, just that it's hard to be impartial., and in the end of the day, like in politics, it depends on what your values are.
one would think it would be easy - just compare counts of innocents killed by each side. Unfortunately that would frequently make a "good"(winning) side look like a bad side and so they force other and more complicated criteria like this:
> it depends on what your values are.
It would also be a very flawed measurement unless you count the innocents the "evildoers" wanted to kill. The difference between what Hitler achieved (and that's already horrible) and what he wanted to achieve is rather big.
I mean, on one hand, I fully understand that many startups begin by offering a free or very low cost service and then have to figure out how to monetize, but I don't really see that as "screwing over the user", I see that as ensuring the business is a going concern. Even as a user, when I see that a business is transitioning from "everything is free and great" stage to "now we need to make money stage", I either leave or decide it's worth it, but I'm not really mad about that.
Furthermore, there are lots of startup services that I use, love and pay for, and I don't feel like I'm getting screwed over.
Just an example, in 2017 I bought a fairly expensive, brand-new GM truck. It was manufactured in Mexico. I've bought GM stuff before but they were made in Texas. I'm sure it was a cost saving measure. I recently sold it after 4 years and 14k miles. Dead battery needed to be replaced, the transmission was hosed, and I took a bath on it. It's known as the "Chevy shake." There's a big class action suit that I believe was dismissed. We bailed them out in 2008 and they started making absolute dog shit. I'll never buy a GM truck again.
Most home appliances are also garbage and will only last you 5 years or so, if that. My elderly mother is paying for 2 ovens. The first one stopped working before it was even paid off. Her current one won't heat consistently and she constantly complains about it.
The LG OLED TV I bought a few years ago has YouTube burned into the screen. I won't reward them with another purchase. My "commercial grade" grill's wheel rusted off after a couple of years because it wasn't treated and had cheap metal. I have the broken, detached wheel on the ground under it, sideways so the thing won't constantly rock back and forth.
Planned obsolescence that almost killed many US industries 40 years ago is back in full force and will have predictable results.
Examples please.
For a moment, I thought you were talking about the police informants themselves.
Not that I'm fond of cybercriminals but it's somewhat ironic to see one sort of infiltration of an enterprise (say, informants at a drug dealing operation) threatened by another sort of infiltration of an enterprise (criminals spear fishing the police). Not all police informant program are problematic but plenty are imo and moreover, the need for police informants more or less comes from things like the drug war, which allow permanent criminal enterprises which need to be put permanently under siege.
It was only halfway through the episode you realise that Hank Scorpio is the stereotypical james bond villian and everyone working for him (including homer) was helping him in his diabolical schemes! But you wouldn't know it if Homer didn't re-sign from his job while Hank was battling Bond. :)
Monero, on the other hand...
- Ban anonymous cryptocurrencies.
- In pseudonymous cryptos, mark any address that has been the destination of a ransomware payment or demand as tainted. Any net positive transaction from a tainted source wallet marks the destination wallet as tainted. (I.e. you are obligated to return tainted monies to tainted wallets if they send money to you.)
- Exchanges are forbidden to deal with tainted wallets, or with any exchange that deals with tainted wallets.
While you're at it, I guess you could mark any wallet funded at an exchange that doesn't KYC as tainted as well, to limit the use of crypto for money laundering.
I'm guessing we're going to figure a lot of this stuff out in the next 10-20 years, if the crypto craze doesn't die off naturally during that timeframe.
The real fault lies with institutions rushing to half-assedly digitize so now they're wide open to script kiddies, and with enterprise IT providers doing a piss-poor job at doing correct software engineering. And now you're suggesting more savagery like it's some sort of solution to anything at all?
The war on drugs is bad because it doesn't work, and because drugs cause less harm than fighting them does. It's not an apt comparison to the situation we're talking about.
Which of the following causes more harm in total: (a) a ransomware gang attacking the computers of a hospital, thus endangering the lives of its patients; or (b) law-abiding citizens adhering to a historically contingent economic system which leaves millions of people without access to healthcare?
B) Use your laundered dirty money in other addresses to pump the token on uniswap (or any AMM)
C) Sell the token from address in A) back into the Uniswap liquidity pool at a massive profit, enjoy the profits and reintegrated money. You look like any trader.
D) Bag hold the token in the address from B) and never think about it again and never worry about trying to cash that out. In addition that address can add to the liquidity pool and provide a service to all other traders indefinitely.
E) Laugh at people that are still imagining how difficult it is to launder money on public ledgers. Blockchain detectives on their wild goose chase looking at the wrong addresses.
Do this all over time, and not immediately pumping a token with the laundered money.
Sure, I’ll probably get more scrutiny after writing this but you won’t. I really hate chilled speech and people having dumb ideas because the should-be-obvious reality is never talked about. The point is that the trader behavior is indistinguishable from others, and there are no financial intermediaries on permissionless AMMs to flag anything.
(This style of intentionally introducing a pricing error and arbitraging it yourself happens for real and is not always particularly profitable. You can read about the foreign exchange fixing antitrust shenanigans. Some traders thought they were being very clever, and, according to Matt Levine, made relatively small amounts of money and ended up getting seriously smacked down. The feds and the courts may be slow, but they’re not dumb.)
This all seems very abstract, but, when you try to spend what you think were carefully laundered ransomware gains on a nice beach in France or Florida and Interpol or the FBI arrests you, the resulting trial and prison time will be considerably less abstract. :)
Sounds like a great benefit for the government
All other stories on that podcast list are very interesting.
I think the IRS scammers still usually ask for something like that instead of cryptocurrency, because cryptocurrency is a bit too hard for their marks to figure out.
No, money will always be used for crime as long as money and crime exists. People invent new crimes, People invent new money. Crime is the problem, not the money.
I would argue that money that can be used in this context is extremely valuable, as it is beyond the state. This is a very awful situation, and I feel for the victims, but the existence of cryptocurrency is not the problem, any more than cryptography is the problem wrt ransomware.
Tech can be used in many forms. Use it properly. Find and bring those to justice that do not. Don't blame the tools.
So, at least where I live, you can "buy stuff" with BC.
However, there are a number of benefits; for one, average ticket size is about 20% higher for credit transactions vs cash (if I recall correctly) and merchants do not have to hold onto and manage piles of cash. This is a material cost savings.
Further, of that 3%, about 0.1% goes to Visa, the rest goes to the issuing bank and covers the cost of rewards programs and loan origination. Generally speaking between 1 and 2% of that will be rebated to the buyer.
For the remaining 0.9-1.9%, customers get benefits like insurance and the ability to issue chargebacks.
In Europe, debit interchange is capped at 0.2% and credit at 0.3%, and they just don't have insurance or rewards.
As it stands today if you wanted to transact in crypto, not only will you pay the $30 fee, you'll also be paying the mark-up for credit acceptance.
Only bitcoin and ethereum have fees in this range. Other cryptocurrencies do not.
https://bitinfocharts.com/comparison/transactionfees-btc-eth...
Of course the "average" might be more bytes than buying a pack of gum but the argument still holds that the transaction costs are prohibitive for general commerce.
When your economy revolves around an entity armed to the teeth you don't need consensus.
The USD is an inflationary currency and Bitcoin is a deflationary currency. Right now Bitcoin is extremely deflationary and so there is extreme savings, but that is not sustainable indefinitely. Whether it becomes more popular to spend Bitcoin after the value levels out remains to be seen, but deflationary Bitcoin will always tend to encourage savings more than inflationary competitors like the USD.
Technology comes with negative externalities.
The cryptocurrency world needs to accept that it does have negative externalities, and show that the benefits outweigh them, rather than pretending that they don't exist.
I'm personally not convinced that the upsides of cryptocurrencies outweigh the downsides.
In the case of general purpose computing, the upsides are obvious and massive. Whereas it's much, much less clear that the upsides of cryptocurrencies outweigh their downsides.
If I say cash and banks get used by the vast majority of organized crime I'd be factually correct, but I'd also be accused of whataboutism. In a world without crypto I'd be seriously hampered by an unfair economic system, so to me personally the pros outweigh the cons, but it'd be anecdotal evidence. Hope you see what I'm trying to get at.
Whether or not a technology's pros outweigh its cons is some appropriately weighted average across all the people that it affects. The person who gets hit by crypto-enabled ransomware likely feels differently from you.
I also think there is some moral weight to particular benefits. Dealing with unfair economic systems is definitely a "better" benefit (for some definition of good) than those people whose benefits are currency speculation or ransomware.
Governments and banks can't touch your money or see what you're doing unless they get your keys. What other reasons do you need?
We don't need anyone's permission or blessing either. We want our freedom back and society's gonna have to accept this. If that means more crime, energy consumption or whatever -- so be it.
The answer is to get rid of poverty and unequal opportunities.
I’m not saying it’s easy. But if you’re dissecting a problem, at least present all the pieces.
Just because they figured out a technologically advanced way to do it doesn't mean it becomes ok.
This seems to fly in the face of the facts. Namely, that ransomware was virtually impossible to conduct before digital currency, due to the traceability of electronic money, and all current ransomware uses cryptocurrency rather than any other form of payment.
It's the exploitation that's bad whether it takes the form of scams or profits
If someone is killed in a crime of passion, where's the monetary exploitation?
Seriously, I can't think of a single positive use case of crypto currency. So while it can be used for some things, it seems to me that the only concrete use case that is already happening, is crime.
And there is literally no one to fine because no one owns the “ledger”. That’s the joy of a decentralized blockchain
You could increase taxes on cryptocurrency capital gains. Big exchanges would absolutely report those gains to the IRS and you could be on the hook for a bigger bill.
It's not impossible to regulate this stuff. Yes, some folks will figure out ways around the regulations, but you'd catch most tech-unsavvy people just fine.
You need some intergovernmental agreements, but it's possible
For example, the author of the wannacry failed at layering and exchanging his Bitcoins into fiat.
Source: https://www.fatf-gafi.org/publications/virtualassets/documen...
There will always be a way to get illegal cash, ransomware just became much simpler with cryptocurrency. Now that the trend is here to lock your systems for ransom I don't think they will go away with cryptocurrency.
therecord.media get's a lot of attention now on HN presumably because it's new and Catalin joined them.
It's not a big deal, but I think it needs to be pointed out (especially to the audience outside the US) that they are CIA funded. They should be more transparent about this.
the tragedy of all cyber reporting is that there can be no neutral party. the moment you need to call out your own camp you'll lose support/protection and legitimacy to exist (e.g. imagine Bellingcat being vocal of anything that happens within FVEY. Unthinkable!)
Bellingcat (despite the great work they do IMHO) certainly does not get Russian passport details simply by hacking or by asking some "corrupt" Russians working for the state for help. So you can probably trust most of what they say but not how they get their info or that they are simply a "hacktivist / citizen jorno" outfit (they'd be dead since long time if that would be all)
At least until I've seen them uncover something as big as Skripal or the MH17 (within the FVEY) I wouldn't believe their claims of being "independent". Which will never happen because you don't bite the hand that feeds. Anyone playing in that league will not survive very long (quite literally) unless they get security benefits needed (which requires affiliation).
There doesn't have to be a conspiracy. That protection comes at a cost of bias (it's not required when everyone around you and most importantly yourself believes you're part of the good guys).
https://www.bellingcat.com/news/africa/2017/02/20/tracking-n...
Yes, imagine if they covered things in the US:
https://www.bellingcat.com/tag/usa/
Ex: "US Law Enforcement Are Deliberately Targeting Journalists During George Floyd Protests"
https://www.bellingcat.com/news/americas/2020/05/31/us-law-e...
Give me something of the same magnitude that got exposed by Manning, Snowden or Assange and I will be happy to believe that they are "neutral". But oh wait - they'd be in exile or dead. So my point stands.
One of the strongest messages the US sends abroad is that the 1st amendment is sacrosanct. Highlighting law enforcement violently suppressing that is extremely damaging to America's reputation.
Nobody is moving any goalposts. Your assertion that they are independent but also are unable to highlight crimes committed by the US then they are simply not independent.
FWIW I'm not highlighting any side being bad or good but that the claim of independence needs to be viewed in relation to their alliances.
They still are a citizen journalist type of outfit, they don't take direct funding from government orgs. But they have to suspect some of their anonymous analysis contributors are working with a state agenda and resources.
As a result, Bellingcat unlikely to go after Israelis in Gaza, but more likely to go after ISIS terrorists, Syria, Russia. WikiLeaks more likely to focus on US politics and NATO, than to look at Putin's finances or Russian banks.
But then all of advanced journalism becomes murkey, as you can be independant, while only looking at what your anonymous sources give you. Is NYT or WP independant when it runs an article on national security by the CIA or DoD for censorship, and securing those future juicy leads?
Part of one of their rounds of funding included investment in 2010 by In-Q-Tel, the CIA's investment arm. They are one of numerous investors, which includes Google. They are not receiving ongoing funding.
A private equity firm bought them two years ago for $780 million.
Seems very misleading to claim they are CIA funded at this point.
So getting funding from the CIA really is different from other thing - possibly. But the situation of all this not being known and being officially concealed produces a lot of paradoxes.
>> The deal essentially buys out earlier investors, which included GV (Google’s venture arm), In-Q-Tel (the CIA’s venture arm), IA Ventures, Balderton Capital, Mass Mutual Ventures and others — and gives them a healthy return in the process.
Who is Catalin?
This is easily the most vicious threat that I’ve seen.
It has indeed been amazing to watch how little discussion there has been about this as it keeps getting worse. Some people are writing warnings, especially those who are the ones who are supposed to be doing something about it. That seems to be a common tactic these days, if you are responsible for solving a problem print a warning, then when the problem manifests say "I warned you". Many problems have been ignored for decades this way.
The CIA seems to exist primarily to conduct attacks on foreign targets.
There's so much waste in Washington D.C. for them to have no ability to do anything about this stuff makes me think there's way too much corruption in our government. Until that's rooted out and qualified people put into the important decision-making roles, may we simply hope things don't get too bad before they start getting better.
Can thse be taking in payments (even bitcoin) that with enormous legal effort can't be tracked down? Even if they are in Russia or some place that won't prosecute them, they can make life hard by putting out international warrants for their arrest. So big companies just don't care enough to try to get them prosecuted?
Also it should be considered an illegal payment, extortion at least. This feels like an actual real job for international crime fighting.
The group demanding the ransom can freely set their price. Surely if they know an insurance company is on the hook for it then they’ll add a few zeroes accordingly, making it impossible to underwrite.
Nothing is perfect, but when there is no money in the crime there is much less crime. (Don't confuse less with zero!)
In theory, this helps with lower prices, negotiated support policies with the ransomware criminals to ensure the decryption process goes well, and they keep cryptocurrency available so the policy holding company doesn't have to scramble to get millions of dollars in crypto in a day or two.
Similar to kidnapping negotiators, ransomware negotiators often have the experience to produce a better outcome
I would expect the net result of this would be that groups raise their demands to match what (they think) the policy limit is.
And I know the DC police force doesn't have global jurisdiction to root out cyber attackers, but the 3 letter agencies that do have this jurisdiction may view ransomware in a different light after this attack.
People who live in other countries aren't just mindless drones that march in lock-step with their ministry of foreign affairs.
That's why the reply a few comments up the chain said "These type of ransom seems to be state backed or at least tolerated."
"At least tolerated" part means that the hackers are doing it for their own purposes or for money, but not under command or employment from foreign federal agencies. Foreign federal agencies simply tolerate those hackers by looking the other way, since no skin off their backs for some ransom payments taken from some US entities.
> Hackers from Russia or China are higher up on the hierarchy of needs and attack targets for geopolitical advantage.
That is a completely different claim from what you are talking about. The throwaway account claims that foreign hackers are all political agents. (Which is an incredibly broad generalization to make about an entire country, that strips its residents of their agency, and would require extraordinary amounts of evidence to support.) Your statement does not support that interpretation - it argues that they are economic agents that are tolerated/encouraged/whatever by the political apparatus.
Your claim is compatible with mine. The throwaway account's, on the other hand, isn't.
Their ability to evade or the lack of ability of Western countries to deal effectively with them?
Then you read how the ransomware groups "avoid" CIS countries, well I wonder why...
https://en.wikipedia.org/wiki/Commonwealth_of_Independent_St...
My company was attacked relatively recently and our local servers were all encrypted. All we had to do was contact our insurance provider and they handled the investigation and negotiations with the group. A day or two later and our files were back.
A lot of companies either can no longer afford the insurance, or else it has become expensive enough that it doesn't make any sense to purchase.
"Hate Crimes" 525 KB
Though exposing police informants could lead to their death and obviously shouldn't happen, I'm fairly curious why they're tracking the "MOST VIOLENT PERSON MVP."
Undercover agents should be extracted or wrap up things where they are under the assumption of being exposed.
Informants should be notified, and possibly given witness protection (by a more competent agency) if they are at risk.
Training and re-training for everyone involved on proper digital hygiene. Also get qualified staff and create a process that avoids compressible elements where possible. E.G. Text files are so much nicer for security, automation, and long term archive.
.docx cannot contain macros
But when it's extortion, what is to stop from them instantly asking for another ransom?
It's a tragedy of the Commons thing I think?
I think instead “taking security seriously” will just be an eternal arms race.
One that we are already engaged in. And each person that gets extorted is rudely reminded that they are losing.
Private corps when faced with a data breach under GDPR laws are made to pay for their slip ups. LE under the same circumstances have a special pass under the guise of national security. And the cost is your life in the worst case scenario
Now here's yet another instance, and we're seeing them at this high level almost every day. Tragically, this leak could have very serious consequences in that people are likely to be killed as the consequence:
It's time we citizens demanded that such critical records be stored on paper files and in locked cabinets in secured buildings as they once were. Simply, we've no other option.
Smart governments such as Russia have gone back to keeping critical documents on paper as they once did. In essence, no matter how hard one tries to secure digital data it's still dead easy for a determined adversary to access it—but it's much, much harder - in fact almost impossible - for the same adversary to break into a building and then into locked repositories and steal the same files in their paper form.
Let's do some very basic sums to prove my point:
1. The amount of data stolen in this case is 250GB. (This is an absolutely huge amount of data.)
2. If we commit text to paper we get about 2K bytes per page (a long accepted round figure)
3. Therefore, a standard ream of paper, 500 pages, stores 1,000,000 bytes (1MB) of data.
4. 250GB is actually 250,000 megabytes
5. Now, a ream of paper weighs conservatively 2Kg (it's likely more). Thus, each 1MB in paper storage will weigh ≈2 kg
6. Extrapolating this out, we therefore need ≈500,000 kg ==> ≈500 tons of paper.
7. Thus, I'd strongly assert that whilst thieves (smart hackers) have amply demonstrated that they can easily steal 250GB of data from right under the noses of highly secured sites such as the NSA, Police etc, that it would be nigh on impossible for them to do so if the records were STILL stored in paper form, as they:
(a) would have to breach the physical security of a guarded building and break in;
(b) once inside, they'd then have to breach records security by breaking into secure records rooms thence secured filing cabinets; and,
(c) then remove 500 tons of paper records, this would require a huge logistical operation involving much manpower and many, many trucks—and they'd have to do all this without being caught!
The only way this could ever happen in practice would be for a country to be invaded by another (like the Nazis did in WWII).
In short, digital security has long proved that it's nowhere near being ready for prime-time. QED!
In unrelated news, we congratulate Sergeant Yang of the Benevolent Retirees Association Metro Police for winning the "face up, face down!" raffle. Also of merit is the National Penalty Battalion, who successful accomplished the release of a genetic bio-weapon targeting the financial profiteers of international narcotics trafficking. We ask for no money. Please simply change your ways. In response to your hardship and efforts, 100 billion dollars has been deposited to your accounts by the federal central bank at 0.0001% interest.