TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Interview with a ransomware group

120 pointsby stereoradoncalmost 4 years ago

13 comments

imglorpalmost 4 years ago
As for repercussions, notice they indicated &quot;fear of the United States and its planning of offensive cyber operations&quot;. We don&#x27;t hear a lot about US offensive operations. Maybe they&#x27;re ongoing but they don&#x27;t get a lot of press. If that&#x27;s the case maybe the need more for deterrence purposes. Does anyone have any visibility?<p>Also, notice they did not mention any concern the FSB would invite them for tea, pay respects to their families, or any other ... imperial entanglements. This says a world about their standing in Russia, whether tolerated, encouraged or some other arrangement.
评论 #28048709 未加载
评论 #28048508 未加载
评论 #28052863 未加载
dcowalmost 4 years ago
This is an interesting topic because BM claims to have a moral compass and is only interested in targeting wealth not impacting humans. Let me ask the question: “if companies paid for in-house security professionals competitive with what one might imagine BM pays, would people still choose the grey work?”. I presume in a dichotomy between clearly unethical and ethical, it’s easy for many to choose ethical. But when you add a grey option, it certainly changes things since I imagine most people are ethically grey. Let’s assume what BM is doing is effectively legal in the country where they operate.
评论 #28052912 未加载
评论 #28053042 未加载
评论 #28055724 未加载
评论 #28053017 未加载
thrwyoilarticlealmost 4 years ago
&gt;Moreover, LockBit encrypts the first 256 kb of the file (which is pretty bad from the point of view of cryptographic strength). We, on the other hand, encrypt 1 MB. Essentially, that’s the secret to their speed.<p>So I can just pad all my valuable data by 1MB?
评论 #28053001 未加载
评论 #28053335 未加载
blankfacealmost 4 years ago
reminds me of the Bin Laden interview(s) before 9&#x2F;11, specifically the one with Robert Fisk where Bin Laden was saying he was going to start attacking America<p><a href="https:&#x2F;&#x2F;www.bbc.co.uk&#x2F;programmes&#x2F;w3csvtth" rel="nofollow">https:&#x2F;&#x2F;www.bbc.co.uk&#x2F;programmes&#x2F;w3csvtth</a><p><a href="https:&#x2F;&#x2F;www.cbsnews.com&#x2F;pictures&#x2F;osama-bin-laden-tora-bora&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.cbsnews.com&#x2F;pictures&#x2F;osama-bin-laden-tora-bora&#x2F;</a>
评论 #28049466 未加载
devnull3almost 4 years ago
&gt; it was seeking to recruit partners and claiming that it combined the features of notorious groups like REvil and DarkSide<p>I wonder if they have leetcode style interviews :)
btbuildemalmost 4 years ago
I wonder why they refuse to rip off oil companies? Too well connected &amp; therefore too risky?
评论 #28052561 未加载
评论 #28054840 未加载
评论 #28049603 未加载
danpalmeralmost 4 years ago
I feel like giving criminals a platform like this is wrong.<p>I&#x27;m all for reformed criminals giving interviews in the context of what they did being wrong, but this is an interview about how they&#x27;re getting better at their crimes.<p>Regardless of how easy it might be given security practices, these are crimes, and they are crimes for a reason: they cause damage. Their impact is felt beyond the ransom money paid, it&#x27;s felt by employees who may be put in terrible positions as their work is held ransom and who might pay up personally to avoid problems at work, it&#x27;s felt by customers of these companies who end up with higher prices, it&#x27;s felt by countries as their output is hit. The fact that this &quot;industry&quot; is getting more &quot;professional&quot; does not change the fact that it&#x27;s harmful. They don&#x27;t deserve the publicity and attention that this sort of platforming provides them.
评论 #28050015 未加载
评论 #28048782 未加载
评论 #28048560 未加载
评论 #28049195 未加载
评论 #28049049 未加载
评论 #28048382 未加载
mimixcoalmost 4 years ago
There&#x27;s an elephant in this room and its name is <i>ethics.</i><p>When I was a mainframe programmer at IBM, one of they first things they taught us was how to stop the processor of a System&#x2F;370 machine. If you can do that, ladies and gentlemen, you can bring down Bank of America, the US Army, the Social Security Administration, etc. So everyone there knew how to be a &quot;black hat&quot; hacker if we wanted to.<p>Was there money to be made in that? Surely. More money than IBM ever paid anyone! But the reason neither I nor any of my colleagues would ever dream of using our skills to hurt people is that last part of the sentence: <i>it hurts people</i>.<p>Yes, IBM did some awful stuff from helping Nazis to keeping apartheid alive in South Africa (over employee objections while I was there), but overall, the &quot;corporation&quot; provided valuable goods and services to real people who had to slog on in real jobs every day to get the world&#x27;s real work done.<p>Oil companies are in the same boat. The world runs on oil and some ransomware attacks aren&#x27;t going to change that. The idea that terrorism (and black hat hacking is absolutely a form of terrorism) is a useful way to change corporate behavior is so ill-informed that it&#x27;s pathetic.<p>When asked about taking a &quot;white hat&quot; approach and selling legal pen testing (or even PTaaS), these developers declined saying they probably couldn&#x27;t monetize their skills at the same level that way.<p>Well, I say, too <i>effin&#x27;</i> bad. If everyone optimizes solely for himself, there will be no one left. It&#x27;s appalling to me that criminal organizations now recruit, have price lists, and get PR placement. These people and their products (and their communication channels) need to be turned off ASAP for everyone else&#x27;s sanity and self-preservation.
评论 #28054126 未加载
评论 #28054160 未加载
评论 #28054095 未加载
cutleralmost 4 years ago
Totally naive but what would it take to protect a disk from unintentional encryption or maybe make encryption impossible?
评论 #28055240 未加载
评论 #28055875 未加载
unixheroalmost 4 years ago
So basically he interviewed a Romulan.
评论 #28053111 未加载
sys_64738almost 4 years ago
These people are terrorists so why are they being interviewed?
评论 #28052871 未加载
评论 #28052874 未加载
评论 #28053088 未加载
fleroviumalmost 4 years ago
This is free advertising for criminals.<p>Correction: this is free advertising for criminals _actively looking to recruit associates to assist them in committing crimes_, and helps them commit crime.<p>Don&#x27;t upvote &quot;Weapons Smuggling, Inc. (YC21) is hiring a coordination specialist for EMEA operations&quot;
4gotunameagainalmost 4 years ago
I find myself puzzled by organizations like these. Let&#x27;s say they do not attack infrastructure or other critical services, and only leech off huge companies.<p>I cannot argue against it?
评论 #28048610 未加载
评论 #28052021 未加载
评论 #28053045 未加载
评论 #28048688 未加载
评论 #28052992 未加载