The Increasing Trend of Online Extortion
troyhunt.com
troyhunt.com
It left behind lots of text files giving you instructions and an address you can access via Tor. When you went to that address, there was a web app to allow you to upload an encrypted file to confirm if it was Cryptolocker. If you pay the ransom, they would send their "decrypter tool" that had the encryption key embedded in it.
The real criminal breakthrough, in my opinion, is that all of these utilities worked. When people are able to do some research and find out that if they pay up, they really will get their stuff back, often times they will pay up. It's certainly very disturbing.
Everything old is new again. Back in the late 17th/early 18th century, with no police, ransoming stolen possessions back was a fairly common and accepted practice.
See e.g. http://en.wikipedia.org/wiki/Jonathan_Wild for one of history's more colourful characters.
Oleg and Boris mean business: they have a hammer, clippers, a soldering iron and an AK-47 in the trunk. Their target: your Bitcoins.
They wait patiently for your to exit your apartment or they follow you around or they just come knocking at your door. They are ready to patiently torture you until you transfer all your bitcoins to their address. They will enjoy the process, you .. not so much.
After you finally give in and transfer them your bitcoins, they leave and disappear. Now you've got absolutely nothing to show to the police: You cannot prove that those were your bitcoins and you cannot prove that the address you've transferred your balance to isn't yours. And you have no idea that it was the pizza place that tipped the bad guys.
For Oleg and Boris, it's the perfect crime: They just made $30k in 20 minutes and they didn't even have to kill anyone, a finger here, a finger there and they are rich!
This, in my opinion, is a great risk for cryptocurrency owners, because it offers potentially great returns for the bad guys and the risk is pretty small, plus it's very hard to prove that the theft/extorsion did happen.
It shouldn't be very hard to design the UI to make it hard to fall into this trap, either. Easy way: when doing a small payment from an address with a large balance, the client can automatically add intermediate transfers to avoid the direct link.
I've lived in the ex Soviet Union in the 90's and extorsion through torture was a common thing back then. But now we might see the 21st century version of those guys, probably a bit more gentle - no need to shoot or kill people, just force them to press Enter and you're done.
Because a robber can't demand you transfer money from your bank account and expect not to be traced, that's why.
The recipient has no sure way of knowing that the original address was mine - I might just have withdrawn from a service like Coinbase.
Also, shouldn't there be ways to indicate ownership with the private key?
Well, it's possible to prove control of the address (simply transfer something to an address of the choosing of the person who you're trying to convince). "Ownership" is more difficult to prove.
Besides, I think most "mainstream Bitcoin users" have their wallets on sites such as Bitstamp, Coinbase and so on. So they can prove the Bitcoin was theirs.
BTW, instead of signing a message, you could also move around some money through that account. This may be easier to achieve for non-tech people, as it can be done with any Bitcoin client.
The pseudoanonymity is perfect for phishing and ponzi schemes though...
1. Satoshi is likely carrying $300M in his head, today. Imagine what it will be in 10 years. You can't carry $1,000,000,000 in cash in your head for example.
2. Allowing criminals to steal BTC from you by force or extortion sets up horrible incentives. First, the criminals must voluntarily relinquish control of the BTC if you are to get it back, so there's little the State can do to help you even if they wanted to. Are you willing to use equal or greater force to compel hardened criminals to get your money back? The police probably aren't, and your government is almost assuredly corrupt regardless of where you live.
Ponzi schemes are the least of your worries in a world where Bitcoin is truly ubiquitous.
As the Silk Road proceedings showed - getting someone for wet work even with a lot of money is hard.
Firstly, this problem exists in current society too. I don't think anyone has any problem picking out rich people, and anyone in a city will be able to tell you where the rich neighborhood is. Bitcoin doesn't make this any easier. In fact, best (and common) practice is to never reuse addresses, and use bitcoin inputs from various addresses. (e.g. to pay $5 for a pizza, you could theoretically, if you wanted, use inputs from millions of addresses each having only tiny fractions of a penny). Despite the public ledger, bitcoin offers a lot of financial privacy. As such the first premise of your story I think is flawed: that it's easier to find out who is bitcoin-rich.
Second, extortion, kidnapping, stealing, these are all things that on paper are pretty easy to do now, but to say it leaves no trace or that it's in any way easy (regardless of what token you steal, whether it's platinum bars or World of Warcraft gold) is clearly not true. Regardless of what is being extorted, this is really hard. For example, ideas can be extorted, too, passwords, keys to nuclear launch facilities etc. But it doesn't really happen too often, even though the tools to 'trace' a stolen idea or a stolen digital file are (and can be) limited.
But let's imagine it does happen? Let's compare it to a debit card. They kidnap you, take you to an ATM and force you to use it or give them the code. It happens every now and then, but the amount stolen is usually very limited, a few hundred bucks as that's the limit for most ATMs per day.
Bitcoin has similar options. You can have more than 1 key, and you can give such a key to say a friend, a bank, a server. Technically it's easy to set up a system where you have $1m, and to send $1m requires you and multiple other keys to sign, the key at the bank (stored behind armed guards), your notary or your friends. You can keep it simple or super complicated depending on your risk profile and the amount of money. In a small village as an unknown rich entrepreneur, keep it simple. As a known billionaire in guadalajara? Probably require lots of keys for any amount over $10k or something. Just making something up. Point is, technically you can set it up any way you'd want.
So they'd extort you and you'd say 'just like my ATM, I only possess a key that allows $500 to be transferred per day. For more I need more keys which I don't possess, I own them but I don't have them with me. I'd need to go to a bank' or whatever.
Now there are a lot of caveats to this. The whole notion of keeping all your money in your brain carries physical risks, and keeping keys with a third party (as opposed to 100% autonomy over your money) is sort of contrary to the spirit of bitcoin. But you can keep keys at multiple parties, neither of which individually have enough keys to control your money, while providing security benefits. In short, there are lots of possible solutions to the horror story you wrote (of an easy & perfect crime) that should be arriving in fully consumer-friendly ways over the next few years for sure.
You may keep paying afterwards... or you may not. But even if they do not follow on their threats, $1K each for a weekend of "light work" is still pretty good money.
And interestingly this virtually never happens that I know of outside of some countries in South America (where there's actually a term for it, express kidnapping)
In any case, it's no different to someone being abducted for his ATM card, it applies exactly the same.
We can have a broader discussion about physical security, I'm not saying we're all perfectly secure, but acting like it's a unique problem to bitcoin money is disingenuous.
We can have a broader discussion about physical security, but it's clear this isn't a problem that's unique to bitcoin at all. In fact, bitcoin allows anyone to configure their security according to their own risk profile, and retain full financial privacy in their ordinary lives.
I'm not saying it's a perfect world with bitcoin and that you're fully secure against overwhelming physical intimidation and force, but as I mentioned in another comment, acting like this is a unique problem to bitcoin just isn't true.
For digital extortion it is true, bitcoin is unique, for physical extortion it isn't. The reason being that it's very hard to send money without a trace digitally without using cryptocurrency, so bitcoin is unique here. If you run an extortion over Paypal, you're in jail by the end of the week usually. But physical extortion is possible because cash (or say jewelry) from ATMs is difficult to trace, bitcoin doesn't make this any easier. On the contrary, I'd rather steal from my ATM card than from my bitcoin wallet, as I only have $150 or so in a non-multi signature wallet, but my ATM has a $1250 a day limit, because I can configure my risk profile with bitcoin myself.
The curse of intelligent criminals is all powerful. Intelligent criminals have to get lucky every single day for the rest of their lives. The police only need to get lucky once!! :)
That was a fun thought exercise and I hope your deserved upvotes rain in.
In fact, it would be easier to make the case that this was you money, thanks to the transparency of the block chain (and the fact that you have the keys).
1000 BTC on the other hand have no physical form so it's much more convenient.
It's just a crime, but the rewards can be well worth the risks. You expect returns comparable to robbing a bank, but the criminal method is much safer for the robbers, they can even avoid violence altogether.
In the real world, badass shellshocked war veterans who've done time in a russian prison would meet very little resistance from a bitcoin-rich geek.
They don't need AK-47s to extort most of us, they just have to say something really scary, like 'All your bitcoins are belong to us. Now!' and pretty much all the geeks I know would shit their pants and hand over their private keys or make the transfer.
It's also certainly possible to prove that you did own the funds. That is, if the police is not in on it. And when we're talking big money, impossible things become possible, especially in corrupt countries.
Bitcoin is used all over the world. Maybe it's hard to imagine such crimes in US or Europe, but I wouldn't vouch for the rest of the world. Much much shittier things are happening every day.
Multi-sigs and address shuffling makes sense to us, but some random investor who's storing part of his wealth in cryptocurrency may have no idea.
If you had a reliable identity - well implemented private key crypto or signatures, or perhaps just a fixed IP address - Communications protocols could be created that don't allow anonymous communication. You don't provide identity and they won't accept messages. The thing is, this would also allow private communications which neither corporations or governments want to happen.
So the internet will remain insecure so long as companies want to read your stuff for "ad targeting" and governments want to read your stuff to "stop crime". Got that last part?
I don't know why people don't seem to understand this. Or perhaps the lack of understanding is why it's not here.
1. "I am Bob."
2. "I am not anybody besides Bob."
The default natural state of human societies is that people have multiple, contextual, even ad-hoc identities.
It's the "Nigerian Prince wants to give you $100M" email scam scaled up another notch.
Where that was a pure numbers game, the criminal knows if they send out 1M emails, 1% will engage, and of that 1% they will get 1% to send money, that "scam" could easily be thwarted with a simple click of the delete button in you inbox or the increase of spam filtering to help the unsuspecting or unknowing not start the process at all.
This online extortion is certainly more aggressive and has an immediate effect on your life. Criminals are always looking for the next way to get ahead, I wonder where the "spam filter" to thwart this effort will come from and what they will move on to next.
I just searched and they actually have a page showing how to recover from such an attack: http://support.code42.com/CrashPlan/Latest/Troubleshooting/R...
I'm not sure there's an easy way to restore everything from before certain date, either, though I'm sure it'd be possible to knock something up to do it.
First, the powerful extort constantly. When VCs use their social connections to other VCs (the culture of co-funding) to pull the "we'll turn off the whole Valley" card, also known as "the reputation threat", and get people to sign bad term sheets, that's extortion. Most bad reference and negative reputation issues that exist in the Valley come from people who refused to be extorted. But when people in power do it, they don't call it "extortion". They call it "power".
Likewise, most people who acquire power did so by extortion. Not in the hold-up sense, but by happening into important information on powerful people and being able to leverage it into the investment of said powerful people in their careers. All that said, it takes a certain social skill to pull off. You can't just send an email saying, "I know <X> and will release it unless you provide <Y>, <Z>, and <W>." You'll piss that person off, and it's a felony, and even though you'll probably never do jail time (because the extortion target still doesn't want "X" to see daylight) that person now holds the cards. You have to be really subtle and it's best if the extortion threat is unsaid. One of the reasons why fraternity affiliations are so powerful is the implied mutual extortion that comes from living together for 3-4 years at a time of life in which people tend to be impulsive and do incredibly stupid things that their adult selves will regret.
If you're in the same frat, you're bound to have dirt on that person, and if that person becomes powerful, you'll cash in. If you say, "I'll reveal <X> unless you <Y>" you won't get anything, and you could end up in jail... but if it's a tacit agreement, that person will support your career in perpetuity. Perversely, the network effect of this tacit, mutual extortion is positive for the group of people it covers because it spreads good fortune around.
Extortion seems to be a by-product of stagnation, because it's the ultimate zero-sum activity. It's what people start doing to each other when they give up on new contribution. Oddly, the frat culture (for all its ugliness) seems to be an adaptation to this because, while it creates a low-level tacit extortion field, it also prepares people to handle external extortions (from "the proles" who "have no right") and to exercise power (cough extort others).
What's strange about this rash of online extortions is that it seems to be coming at a time when, objectively, there shouldn't be a sense of economic stagnation. There are, arguably, more opportunities for positive-sum contribution than there ever were. But the social distance between capital and effort/talent has never been greater, especially on a global scale, so that might explain the problem.
That gives VCs lasting power over founders' reputations and their companies. They're no longer passive investors, but actively able to turn off interest in other firms that ought to be competitors. Which means that VCs are no longer competing for deals, but colluding as a group and competing against founders.
Obviously, the extortion is rarely explicitly spelled out, but it's implied in the ability to "pick up a phone" and blackball a founder.
Just to be clear here - are you are saying that Tom calling Bob is morally wrong? Or that Tom believing Bob over you is morally wrong?
The former makes sense to me as it is collusion rather than competition.
The latter not so much
It's not like Tom can "unhear" Bob once the call is made.
There's a wide spectrum of "fraternity". Just look at initiations. There are some where initiation is being driven 5 miles off-campus and having to find your way back, and others where it involves bodily fluids, physical abuse, and dangerous levels of alcohol.
When people complain about "frat boys" or "bros" infesting the Valley, we're not talking about guys who like to drink occasionally or streaked a football game, because none of that's a big deal. No one has a problem with an occasional game of beer pong. We're talking about entitled, well-connected people (e.g. the Spiegels and Duplans of the world) who've lived for decades in a world where there are absolutely no consequences for their actions.
I think you're confused because you're trying way too hard to fit this into a preconceived political template. I find it perfectly adequate to explain the current spate of cyber-extortion simply by observing that it has gotten much easier, which is to say, cheaper, and therefore in the cold cost/benefit calculation that even criminals do, it has become more appealing. No massive global economic climate analysis or weird extensions of the word "extortion" necessary. There is no 19th-century equivalent to just mailbombing extortion threats to everybody the way you can mailbomb an extortion virus like that, from half a world away in a legal system that has no interest in pursuing or extraditing you, and similarly, hacking even large corporations is frankly disturbingly easy which tips the balance in favor of the extortion.
It's the same reason Nigerian scams have exploded. They weren't created by email, my parents received (and discarded, of course) physical Nigerian scams in the mail once in a blue moon before any of my family were ever on email, but over email I couldn't even count how many tens of thousands of them I've received (since I've averaged well over one per day for years and years now, I'm sure). I don't need complicated geopolitical economic analysis to figure out why... it's cheaper over the Internet and therefore more appealing.