Ransomware gang threatens release of Washington D.C. police records
apnews.com
apnews.com
We’ll never have perfect security. Secrets can always leak. Almost everyone’s one hack away from being blackmailable.
We can minimise the opportunity for blackmail in two ways: better security, and a more liberty-focused society — for example, you can’t be blackmailed for doing weed if nobody cares you did weed. (Same applies to many non-drug laws, but all this will vary from jurisdiction to jurisdiction).
Of course, once a lawsuit was underway, many backups were placed under legal hold and no longer pruned old versions.
You won't tell us your mother's maiden name or the street you grew up on any more, so now we're trying new questions. Have no fear, it's all for your security.
Store less data, store it better, and make loss of control of that data less important.
Although we can’t store nothing, and we can’t store anything perfectly, and we can’t make everything legal, we should try to maximise each of these objectives.
Or maybe I've been watching too much Battlestar Galactica
So yes, we have WAY too much shit on the Internet that has zero reason to be there - and we have way to many connections and content flowing between orgs without any kind of assessment as to what the content is, it's authenticity, etc.
The vast majority of ransomware incidents happen via spearfishing over email - pretty nuts that literally one erroneous click by a user can take down an entire network.
Think about that. Talk about inherent fragility!
And its hella hard to hack paper in a locked filing cabinet, in a locked building, filled with police.
In person documents:
requires being at a single location in the world
single copy
in secured storage
in a secured building
filled with people who can shoot you legally
Online documents: Can be done from anywhere in the world
infinite copies can be made easily
1 hack can un-secure the data
threatening to shoot a computer doesn't have the same impact
Its really a computer hacker versus traditional spycraft. Spycraft isn't impossible, but does require assistance and tech from nation-states, and is prone to a set of really bad negative eventualities if caught.Other documents, will need a whole process of retrieving information, copying it, adding info, sending it, checking it, sharing it with other people. Police officers' own personnel records might be an example. If you only store these on paper, informal access procedures might be developed. For example, the civilian secretary is used to certain people requesting copies of 6 or 7 files at a time, so they don't always keep track of what was asked for. Unofficial copies get made and kept in someone's desk drawer so they don't have to spend a morning going over to the main HQ. And so on.
Now you have the worst of both worlds - lax security, but also no hope of the traceability and fine-grained access control of an electronic system.
It's also why SMS text messages do not meet the criteria for 2 factor authentication - it's trivial to social engineer phone companies into moving a phone number to a new phone - presumably one you would not have. Authentication apps are a PITA to move to new devices because having a way to move your keys around without some reliance on meatspace defeats the whole goal of "something you have".
Obligatory "if you're in the US, then yes - elsewhere, it depends". In the UK, obtaining a PAC code is a bit more complicated/non-trivial for the attacker. I'd consider it fairly safe to use SMS 2FA over here.
A threat actor intent on extracting the informant list of the DC police will have a completely different approach to the hack, probably involving advanced surveillance, infiltration, bribery, etc.
[1] https://www.thetrace.org/2016/08/atf-non-searchable-database...
Think how insane it was for the OPM to keep clearance files in one big networked database.
A society would need to be both liberty focused and tolerance focused to reduce the potential for someone to be blackmailed, but this runs counter to the notion that the fallout of blackmailable material being released is a just occurrence.
Blackmail is a side effect of punishment, legal, social, or otherwise, and the only cases where I think the majority will agree to reduce punishment to reduce blackmail is cases where people already believe the punishment isn't deserved.
Since drugs are a black market with lots of money on the line and no legal protections for the business, things get violent rather quickly. Gangs can also use the violence of the police against their rivals, in a deep twist of irony.
There is a long and nuanced discussion to be had that blackmail can actually serve a useful societal function and laws against it make things worse, but I don't want to get into that here.
(No, I'm not sure the word infiltrate can be used that way, but it should be)
Plus, there is probably personal information (payroll). Not that it matters how much anyone makes (that's probably public record already), but ACH banking details and things like that.
Some of these things we can't really reduce, need to be kept online for significant time frames, and can't be made public.
That being said, I agree that we should plan on having less perfect security (and then design for that sort of world).
C and Unix is absolute dark age crap. We know how to prove programs correct. We just don't want to pay for it. There still be social engineering, etc., but that is much harder to pull off.
I also think better programming techniques will eventually make programming more productive, as there is less to mentally worry about, and good libraries with lemmas exist. That means rather than being a expensive defense -- expensive offense escalation, it's a 1-time capital investment for defense vs permanent increased operational costs for offense.
This is a quite unpopular opinion with security people, I'll grant, but people are also not used to thinking about technology as demand-constrained not supply constrained in general, which is exactly what's going on here and in so many other ares.
A better understanding of economics and development not CS I think will be the thing that corrects this.
I think about this exactly the opposite from you, and this is why. Humans are the weakest link in most technical systems. The only secure device is one that's turned off and buried a mile deep, because if someone has to use it, they can always leak/allow someone else to use it by proxy.
Perfect defense does not exist. Especially once we get down to people. Even in your scenario, those "good libraries with lemmas" are now the point of attack. Find a weakness in that and you find a weakness in thousands of systems.
And that does happen all the time. Commonly used libraries are found to have privilege escalation vulnerabilities. They get patched, then something else, somewhere else, is discovered. And sometimes the patches themselves open up other vulnerabilities.
As for social engineering being more difficult to pull off, that's not true at all. We're all looking to streamline the process, we're tired, we're sleepy, we're bored, we just don't care, we hate our boss, we just want to watch the world burn. Those are all ways we fail even the most airtight security measures.
Tell me the provably correct patch for willingly handing over my credentials to a malicious party.
It is? In what sense? I've always understood the wisdom to be that people are one of the most leaky bits of any system.
This is imo the most feasible/pragmatic approach for privacy issue.
Instead fixing it by hiding the information, we should fix the actual issue that cause misery when the information is public.
My point is it doesn't have to. Ask what is it that makes people prefer to keep secret then fix that instead.
Not saying its going to be easy but at least we should spend the effort on fixing that, instead of spending the effort on hiding the information.
>society will still have its own opinions.
So we need to spend the effort on minimizing the misery caused by that
Likely the homosexuality has changed because society's view towards it has changed.
That would be situational. It sounds like the old rule was that just being gay was a show stopper. What you describe has little to do with sexuality and everything to do with extramarital activity which could offer leverage to straight people too.
Part of the problem is that it sounds like there were baked-in "hard-checks" about things that were automatically assumed to be shameful secrets that could be used for leverage.
Watching the number of accounts grow over the years on haveibeenpwned has only reinforced that belief in me.
There's more leaked accounts out there than actual people on the planet, tendency rising fast.
The longer something is out there, the higher the likelihood it will get shared/leaked in some way or another.
This just covers the current crop of behaviors we can imagine (e.g. your weed example). But, as long as you have a society, you'll have/need some laws, behavioral norms and a social contract. Violation of any of these would be blackmailable.
You're arguing we shouldn't put up, "don't feed the bears signs" because some people are going to do it anyway.
first off, privacy and legality and confidence and sharing are all interrelated but different. to merge is to simplify and lose context.
Even if they pay the ransom those people are not 'safe'.
The only valid approach in my eyes is: Have backups, never pay, assume this data to be public now and act accordingly.
You could even argue that we should destroy the viability of the market for these scams by harshly fining anyone who pays ransom. Right now individual interests go against collective ones. (unlikely to happen because it looks like victim blaming if you squint... but something needs to be done at a system level)
They have been provided ample warning that their cover is about to be blown. Leaking the hacked data immediately or privately conducting negotiations would put those at risk in far more danger.
Somewhere, somehow I think there is a data storage approach that encrypts data (lets say a pandas dataframe) and the authorisation is your ownership of relevant key. All data changes start to become eventually consistent, sharded and passed around as single atomic units....
I need to think about that somemore ...
I tend to agree and go a step further. We need to eliminate "anonymity by default" and switch to communications where it is a default to verify the identity of whom you're connected to. No more spam emails, or at least you'd have a verifiable origin. Better still would be verification increase sender costs. Proof of work would be useful, and people on our whitelist could be given less work or no work. Just an idea.
If we have good identity verification, places like reddit or HN could strip that off to maintain anonymity but criminals attacking would have to offer up some identity.
Once strong identity handing is possible your encrypted data access become much simpler too.
I don't think this will happen because too many parties from ISPs to governments don't want it. Strong identity also makes end to end encryption easy.
Lol, why would reddit strip off identity? They might not display it to preserve the illusion, but they would store it forever. The same with every other surveillance-loving company, who right now are constrained to making their best guess and harassing you with CAPTCHAs etc. And the results of such leaks with real world identities would be that much worse.
Strong identity on a cross-jurisdictional network is a fallacy that would only bring increased corporate and government control over our lives. The problem is a lack of software security plus lackadaisical network administration, and adding mandatory identity to the "works as intended" path does nothing to address that.
Wouldn't it make sense for governments to make it crushingly illegal to pay a ransom? I would think that drastically changes the calculations of would-be ransomers.
https://www.rollingstone.com/culture/culture-news/anonymous-...
"Online vigilante Deric Lostutter helped expose the cover-up in the Steubenville rape case. Now he’s facing more jail time than the convicted rapists."
Yep, the rapists got 1 and 2 years for the rape, and the hacker got 2 years for that hack. Clearly shows what the society's priorities are.
That's one way to read it. The other way to read it is "The rapists, being minors, were convicted and sentenced under laws that apply to Juveniles. The vigilante, being an adult, is being tried under laws for adults."
I'm not sure how you would convince society to do away with separate rules for minors. It's very rare for a justice system to decide that a 16 year old should be tried as a 21 year old.
You really want to go down that shaky rabbit hole? What if a hacker deliberately caused the collision of 2 subway trains, killing everyone on both trains? Is he still going to jail for only a year because he didn't actually physically harm someone?
And if you're going to say he didn't physically drive the trains into each other, how far does that rabbit hole go? Can anyone be held responsible for any action performed with a tool at that point? "Your honor, I just caused a collision of his head with this hammer, it was the hammer that killed him, not me." Oh, he swung the hammer, so that counts as "physical harm". What about guns? "I just caused a collision of his head with the bullet, the bullet killed him, not me." Yes, he would have pulled the trigger, but he didn't physically shove the bullet into the guy (by your definition). Or if pulling the trigger makes him liable, then the guy pressing the keys to run the programs blah blah blah that cause the trains to collide means he caused it.
In your case, he engineered the deaths of the people on those trains, he's liable for them. This ain't hard.
With kids we expect to rehabilitate them faster.
The long version: You may no see how it matters, but the reasoning is sound:
If you are going to be lenient on juveniles because they are not fully mature enough mentally to contemplate the full effect of their actions, why make certain actions exempt from contemplation?
> This does quite clearly show what the people in the justice system think is worse: an adult hacker vigilante is worse than a 16 yo rapist.
The criminal justice system does not evaluate the actions of a criminal in isolation, they largely take into account the intention behind the action (Look up Mens Rea).
You are just putting two outcomes next to each other for comparison, while the reality is that the intention and maturity of the mind behind those actions are what decides the judgment.
Should someone with the mental capacity of a 5 year old commit some violent crime, do you still think we should judge them as we do with a normal adult?
The ultimate problem with your argument is that the justice system is not about getting revenge on criminals. It's about making society safer.
When someone commits a crime we remove them from society for the period we think it will take to rehabilitate them[1], and ensure that they aren't able to harm society further during the time they are not rehabilitated.
The reasoning for juveniles to get a lower sentence is because we, collectively, think that it will be faster to rehabilitate a minor than an adult.
> I doubt you would get the same result if civilians were asked.
You'd be surprised: leave gender out of it and ask about "violent crime" and most parents would agree that the court should be more lenient on kids. That's because, as parents (and former kids) we know that kids make incredibly poor decisions.
Phrasing the question as "would you prefer your kids rapist to get off with a slap on the wrist" would get the response you want.
[1] Whether or not this is successful is irrelevant as we cannot know the success at the time of sentencing.
the real situation is opposite - it is pretty exceptional to not charge 16 years olds as adults in a rape case.
Separate rules for minors is a right thing to do up to a reasonable limit - a 16 year old thinking it is ok to joyride somebody's car is one thing, whereis to murder or to rape - it is very different.
However, Deric played no role in exposing the rape itself. The article you cited even points out that Deric learned about the Steubenville rape case reading the NYT article about it. None of the evidence that Deric and the other members of Anon hacked and released were used at the juvenile court proceedings due to evidentiary and due process issues (and for that reason would similarly have been excluded if the defendants had been tried as adults), and (per the linked article) a lot of what they posted wasn't even relevant to the rape or the coverup; it was simply intended to embarrass and harass. At least one of the (adult) hacking victims was not involved with the coverup; they simply had the misfortune to be mentioned in the news articles as being involved with the case, and if it satisfies your moral umbrage, that is why Deric was sentenced to 2 years.
[1] https://corriganlawohio.com/felonies-in-juvenile-court. Generally, for a rape charge, in Ohio the youth defendant must have aggravating circumstances to be tried as an adult, such as a previous violent juvie commitment or the use of a firearm in the commission of the crime, which did not apply to this case. Note that these laws were passed as a response to juvenile defendants being treated as adults, on the premise that juvenile defendants are less in control of their actions and therefore should face less punishment than adults.
And it does make sense of the difference in sentencing. Deric's crime was related to the rape case, but nothing they did affected it. They didn't garner any new indictments or convictions, they just stirred the shit.
We know for a fact that young men's brains aren't developed as fast as young women's brains. Either the passed law wasn't passed because "juvenile are less in control of their actions" or it is a clear case of not looking at the science they cite since 50 % of juveniles are less in control than the other 50%. I'm personally sure this is all about society being angry about juveniles being punished too harshly and the justice system seeing this as a way out instead of actually ruling as they should: on an individual basic. As it is now they cite a scientific basic and don't actually follow it at all.
Also IMO it does also show that the justice system is out of touch. If you asked civilians I'm convinced that close to 100% would say rape should be punished harsher than the hacking and the hackers punishment is the one that is too hard.
but, a rapist hurt (in theory) 1 person.
A "Hacker" can hurt hundreds or thousands or millions of people...
I'm honestly not sure how to equate fair punishment in that space.
Just imagine that you have to choose - either you're going to be raped or you computer is going to be hacked.
I take it that a person just finds a few random strangers' public keys with previous history, and gives them signing power over the coin. Those strangers just have no way of knowing they have signing power because the ring is represented in the unspent coin by its hash. Is that correct? In order to spend a coin, however, the ring needs to be revealed. How is the race condition resolved where those strangers could see there's a pending transaction for a coin they could spend. Can't those strangers just see the transaction and pay a huge mining fee to jump the queue and spend the coin first?
The ring signatures are used when spending an output. For minting an output you essentially just spend to a single public key.
When spending an output, you pick 10 other outputs (at random from an age-based distribution so the age of a ring-member does not say much) and you produce a ring-signature saying "I have the key to one of these 11 outputs". They combine this with Pedersen commitments to ensure that you are not spending more than you are minting, without ever revealing the total amount of the transaction.
In older versions of Monero, you would pick a few (rings were smaller then) outputs of the same amount, and the amounts were hidden.
Zero-knowledge proofs/cryptographic accumulators are used to verify each coin is spent at most once. Any of 11 coins could have been spent, each owned by a different single key.
For some reason, I thought Monero was basically ZCash plus using ring signatures to make traffic analysis much more difficult even if the zk proof system were broken. I was completely mistaken.
Edit 2: Sorry droffel, I wasn't fast enough editing away my old understanding of how it worked and asking what I was missing. Thanks for the explanation.
> The Babuk group said on its website late Monday
I don't think they care about it being untraceable, they can dump it on a non-US exchange, they probably care about it being un-censorable.
That said, the article doesn't mention if they want the payment in crypto (presumably they do).
Bitcoin, for example, doesn't claim to be an anonymous payment system.
In addition there is no 3rd party verification of the wallet owners so in practice there is plenty of ways to whitewash dirty bitcoin into clean currency, especially in economies with an large black/gray sector.
Add to that that any international investigation into cyber crime becomes an instant political hot potato due to the prevalent political rhetoric around state sponsored actors and you have an environment where the treat of actual capture/punishment is extremely low.
I am curious about this. If Uncle Sam serves Coinbase notice that it considers the contents of XYZ wallet to be stolen goods, then haven't they created lower-value coloured coins, and won't other exchanges start creating lists of those pretty quickly?
There are ways around this on BTC that do not require protocol changes. For example, you can use a coin mixing service like whirlpool to essentially `wash` your BTC. However, this solution is incomplete unless everyone agrees to use it and in doing so `taint` their own BTC supply.
> "If we are all using stolen BTC then none of us are."
The proper way to fix this is with a protocol change as mindslight said. This already exists in a half-way form called ZChash. This is a fork of the BTC blockchain that updates to protocol to allow for `shielded` transactions. These protect anonymity and, I believe, transaction amount as well.
However, ZChash only gives the option to perform a `shielded` transaction. Most transactions on the ZCash blockchain do not utilize this function since it is slower than a standard BTC transaction.
The actual proper implementation of `shielded` transactions that I know of is called PirateChain.
If I have an output of 1 BTC, and I want to send you 0.3 BTC, then that 1 BTC gets split up in 0.3 and 0.7BTC the 0.3 goes to your address, the 0.7 goes to a new address belonging to me. If that 1 BTC was "known bad" is the 0.3 BTC now also "known bad"? Also, for the outside it is a guess whether the 0.3BTC or the 0.7BTC transaction was my "change".
You cannot fully trace every transaction. You can just find every other transaction it was linked to. That list grows somewhat big.
"CoinJoin requires multiple parties to jointly sign a digital smart contract to mix their coins in a new Bitcoin transaction, where the output of the transaction leaves the participants with the same number of coins, but the addresses have been mixed to make external tracking difficult."
For example, the service Whirpool [2] cycles users' Bitcoin numerous times; the end result is one which can be interpreted 1,496 different ways.
Wouldn’t the simple solution be tagging coins that exited such a tumbler?
Perhaps. But the legal precedent is for laundered money to be tainted per se. The laundering itself taints the cash independent of any preceding criminality.
And because none of the wallets aren't accurately linked to real persons all tree actors in the above transaction could be the same entity with 3 distinct fictional personas.
Add to that that the former soviet block is littered with regions where nobody really agrees on who the legitimate government is and where the entire economy happens using foreign currency, there is plenty of ways to deliberately block investigations from simply following the money trail.
LEOs pay millions dollars yearly to have firms do this type of white hacking of using key collisions to unmask crypto coin users.
If you use Google you can find the more than 20 firms that offer their services to LEOs to do this.
Key size was based on number of users not number of transactions big mistake!
Permanently kill illegal addresses.
Yes crypto is theoretically decentralized, but in practical terms it is remarkably centralized - very similar to the Internet’s supposed decentralization.
There would be a limited black market but the value of crypto coins would fall to nearly zero. Certainly crypto would be much less attractive as a means of transferring illicit money.
Humans want what they cannot have and the government saying you can't have crypto would be the ultimate sign you need crypto. See India and China "bans" on crypto.
So if the goal is to get paid, releasing the information is actually counter-productive.
Blackmail is a game of chicken.
Second, if these people were trustworthy, they wouldn't be blackmailing you in the first place.
And once they get the money, what's to stop them from asking for more? It's not like they stop having the information once they get paid.
We probably fundamentally agree: in my opinion one should not concede to a blackmail, in order to destroy blackmailing. However the associated cost, for the victim, may be very high, roughly a sacrifice.
Such blackmailing works because there are known cases of ransoms paid, leading to recovery without any known after-shock (in 2020, as far as I understand: Tillamook and also Delaware County, Florence, Utah Univ, CWT...).
Not sticking to this behavior would be a threat to the ransomware "business", and people gaining from it are probably rational to the point of trying to preserve it. Most, even quite dumb, don't kill the goose that lays golden eggs.
Moreover in some cases the victim lost access to at least part of data vital to its operations, and pays in order to survive.
Releasing data stolen to a victim plainly refusing to pay or even simply trying to play for time sends a powerful signal to future victims.
hXXp:// wavbeudogz6byhnardd2lkp2jafims3j7tj6k6qnywchn2csngvtffqd DOT onion/blog/040c040c85339ebb4b2a8f8d865b4d2c5c83121b48c8dfde5436a78b113919fa/
(from Babuk) "The negotiations reached a dead end, the amount we were offered does not suit us, we are posting 20 more personal files on officers, you can download this archive, the password will be released tomorrow. if during tomorrow they do not raise the price, we will release all the data."
The password AND link to a 161MB rar file is present and working.
There's historical precedent for this.
You don't need to do much to Russia. You just need to let some "hackers" empty the foreign bank accounts of some oligarchs a couple of times. Those are probably much easier to wipe out and it would send the appropriate message--clean up or stay home--indefinitely.
Let's turn it around (with a real example): A US diplomats wife ran someone down in the UK while drunk driving and then ran home to the US. The US refuse to let justice run its course. Should everyone else then be just as dirty as the US and let every criminal do whatever they want and just laugh at the US when they want justice?
It's a very steep and slippery slope. One cannot both be angry that Russia doesn't jump when we say jump and then not jump ourselves when it is the other way around.
And the fact that you have to choose an individual case where the US is wrong (and that it is exceptional) and compare it to entities blackmailing dozens to hundreds of people who will wind up with some of them dead and who have done it repeatedly demonstrates that.
Or perhaps we can talk about the beatings at the Erdogan protests?
Back to internet, even with the best security, how many entities could really stand up to a concerted attack? What everybody asking for OpSec that can stand up to this is really asking for is complete loss of sharing and trust in any group entity. I'm not sure people really grasp that solid security implies lack of sharing. Do you really want HR to require an ID with every interaction? Do you really want the line slowdown while every Karen fishes out her Target fob from her purse before she can check out?
At base, you need at least a minimum level of trust between entities to operate. If someone is preventing even that, you will eventually have to do something drastic to them.
If you shoot for the king you better not miss.
And it's not like Russia is opposed to the idea. That's been their schtick for a while now. They've been baiting direct action for years now. The U.S. government has so far avoided responding directly even to actions that could also be seen as acts of war. Because war with Russia does not serve the U.S.'s interest as much as it would serve Russia's.
We can't really enforce penalties against citizens of other countries. We don't have the authority to do so.
I’m all for leaking this data. It would be a heroic act to let the people know how bad our police really are.
Extorting people for money is also bad, and I hope that the extortionists don't get paid, and just release this shit. Police misconduct is the worst sort of misconduct.
We've had multiple recent presidents and vice presidents who have used illegal drugs.
That seems far more "beyond the pale" because the president has more power than anyone to ending the drug war
We also do not know if the officers that did drugs also locked up people for doing drugs. There are police officers that try to be lenient and use discretion.
A risk to everyone you have poor judgment.
Risk to authority as you are vulnerable to manipulation by bad actors.
If anything, that this stuff is on the background check makes me feel more comfortable. It means that whatever happened has been owned up to which makes you somewhat difficult to blackmail.
Part of the leak also contains all confidential informants TO the police. This, in the hands of criminal enterprise, is a hitlist.
And given how the police operate, I think it would be safe to say that not all the informants are willing (think- "we look the other way over your drug garbage for juicy data")
It seems most ransom ware is used for fairly explicit and immediate commercial gain.
We already have a word for "bad thing", "crime". If we start using terrorism for every bad thing it becomes meaningless.
Mind you, irregardless is becoming a word and literally now has two opposing meanings, so it's likely based on current USA usage terrorism will become a catch all phrase as well if it hasn't already. I am curious however what use it then becomes calling something terrorism. Today there's implicit notion it is a higher threat demanding higher response but even that I think is diluted.
Arguably it is violent. The threat in this case, should the ransom not be met, is to release information that will lead to violence.
I don't think we should start calling everything we don't like terrorism. Nestle? Not terrorists. Dirty roommate that doesn't clean up? Most likely not a terrorist.
BUT: Only the government has the force of law to aid in their data collection.
Theoretically: if you wanted to avoid Google/Facebook web tracking, you could never use their services, block all cookies and domains. You might not have the best web experience but you could still browse the web.
If the government made a WebID to help people stop the tracking/prevent certain ads from being served to minors/think of the children/... then you would have a nice juicy target of information on a whole bunch of people.
The same with gun control arguments, if there is a gun registry then it is a target. Now there can be a debate on if the trade off of having that target helps prevent other more serious crimes.
Another example might be library system membership. Libraries membership lists have but they are not all linked, this is inconvenient if you want to take out books from different systems but might help protect the data more.
Also, private companies don't expect you to lay down your life to defend them.