Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the real world protection rackets are a stable business. You either pay up and are protected or your business gets messed up. No sane criminal would xerox the client list, split from the boss and also try to extort money - it is unhealthy as the turf will be defended.

In the online world there is no concept of local. You can't protect your clients. But then, why should clients pay up - there is an infinite supply of copycats.



So would a valid defence strategy be for a white or gray hat to send out millions of these threats (maybe linked to an invalid payment method so it became impossible to pay up).

Everyone would get so many of them that the "genuine" threats would get lost among the fake ones.

Alternatively somebody uses the same technique to send massive amounts of fake Adsense traffic to multiple businesses without any warning thus forcing Google to improve their customer service or validation algorithms...


> Everyone would get so many of them that the "genuine" threats would get lost among the fake ones.

So the internet will turn into the United States Postal Service then w.r.t. advertisements vs legitimate correspondence?


Surely in many people’s spam folders this is already the case?


I can already see my spam folder being made up of 100% extortions and threats of varying severity. A grizzly thought.


Security companies have a pretty good grasp of how trustworthy an aversary you're dealing with. So if have doubt about whether to pay up for the cryptolocker ransomware that just infected your corporate network you can always give them a call. As happened recently with a Dutch University.

https://www.maastrichtuniversity.nl/um-cyber-attack-symposiu...


> why should clients pay up

Because otherwise their ad income stops.

How does "I might get extorted again by someone else" factor into this?


> How does "I might get extorted again by someone else" factor into this?

The value of the ad income may be more than paying the extortion when it happens once. That doesn't mean it's more when it happens more than once.


And what prevents them from asking again next week. Or forging account ban regardless of ransom.


The whole scheme would collapse. It only works as long as people reasonably believe paying will solve the problem for a long while. This is why many ransomware campaigns pretty much run a callcentre with support for how to easily buy BTC and make the transfer.


If there’s only one group running the scheme it works, but if there are many, it becomes very difficult to coordinate and limit repeated demands. Soft of like how oil producers can only keep the price up if everyone joins the cartel. Each member will make more money if they defect.


This is why organized crime is very aggressive toward upstarts.


So these scammers have a better customer support system than Google?


You still probably get the best outcomes if you're willing to pay sufficiently credible threats a couple times.


We don't typically see that with ransomeware so I don't know why we'd see that with other types of extortion.


With ransomware if you get hacked you usually fix your defenses.


Or a different extortionist comes along next week?


"there is an infinite supply of copycats. "

No there is not, as the number of botnets is big, but limited. And I can imagine something like online turfs to actually happen, with criminal hacker groups setting up areas. And taking other groups down, if they mess with their turf. (afaik some crackers take already good care of their botnets so they do not get under the control of other groups and effectivly remote admin their bot computers and patching)

Now while there is never such a thing as 100% security, right now the average number is frightening low. So the root problem is that the average tech stack is just too vulnerable. There is way too much truth in that:

https://xkcd.com/2166/

And our government agencies don't seem too eager to change that.


The same botnet can back an infinite number of these ransom notices, because when you get one of these ransom notices you have no way of knowing if the ransom notice you got today is the same botnet you paid off last week but with a different name.

Add in the fact that there are botnets available to rent, and you create a near-infinite supply.


Sure thing. But that is allways the thing with ransom. You don't know if paying once is enough. But also the criminals know, there is only a certain amount of money to be extracted from their victims.


IRL, if another gang threatens me, I can go to the first I paid protection for, and usually they try to convince the other gang that, no, they should not do that.

There is no such thing online.


Why not? Wouldn't you be able to forward contact info from one group to another?


A bitcoin address does not give that much information about who wants to get paid.


Ransomware hackers have call centers to teach people how to buy bitcoin. I'd suspect groups involved in this kind of scam would have something similar, isn't it?


I cannot upvote this enough - a deep insight into the problem.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: