Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Monero transactions are extremely difficult to trace.

Bitcoin transactions are traceable and can often lead you to a real person or organization, but if you're the FBI and you're tracing some Russian resident cashing out some extortion payments at a Russian exchange and transferring that money to their Russian bank account, there's nothing you can do about it.

The vast majority of these ransomware gangs are in Russia and/or neighboring states, so that means you can't really do anything about any of them, besides trying to periodically go after some of their infrastructure in a whack-a-mole manner. You can't actually do anything about the criminals themselves.

(I wrote more about this here: https://news.ycombinator.com/item?id=27096715. Not saying about Russia or its people, of course, and I know there's a lot of anti-Russia writing in the West, but this particular issue of ransomware can definitely be largely blamed on the Russian government's stance of not addressing it as long as Russian citizens aren't targeted.)



It's almost like the FBI's activities on this matter are futile and should be replaced with continual public service announcements telling people to not give money to the telephone.


This isn't scamming but rather ransomware extortion. If you're the CEO of a company and a ransomware gang targets you, encrypts the disks of every single server, including backups - leaving you completely inoperable - and messages you with screenshots of all the sensitive documents and PII they'll release if you don't pay, it's hard to just release a PSA telling people to ignore it.

The threat is absolutely real, and the total cost might end up being much more than the ransom payment. This happens on a daily basis. You might as well inform people to not pay when a cartel kidnaps their child and holds them for ransom.

A better PSA would be to keep off-site cold-storage backups, secure hot backups as much as you can, abide by the principle of least privilege, keep sensitive materials in as few and secure of places as possible, general network and application security advice, etc. But no matter how much you try to inform people, there'll still be thousands of companies that won't win against organized crime gangs filled with sophisticated, dedicated attackers who are constantly scouring for potential new victims and who know they have no risk of being hampered by any law enforcement organization in the world.


> If you're the CEO of a company and a ransomware gang targets you, encrypts the disks of every single server, including backups - leaving you completely inoperable - and messages you with screenshots of all the sensitive documents and PII they'll release if you don't pay, it's hard to just release a PSA telling people to ignore it.

If a company is this incompetent once, it will happen again. Paying a ransom is just giving the company the opportunity to cover it up and collect more PII without punishment or oversight.


They should indeed be required to report such incidents. But banning the paying of ransoms is also foolhardy, I think, even though the US has now officially declared that paying ransoms is illegal.

They're hoping to game-theoretically reduce ransomware attacks with this policy, but I'm not sure if it'll work. (It might be working to an extent, though, because in the interview I reference in https://news.ycombinator.com/item?id=27097061, the ransomware operator says he's concerned about this policy.)


I think the prohibition is on facilitating payment of the ransom (eg to a previously sanctioned individual or organization).

So what we could see is a situation where Alice kidnaps Bob and tells Carol to pay a ransom; Carol attempts to do so but when she goes to withdraw money from her bank account Dave, her banker, puts a hold on the transaction or even freezes her account if the fact of Bob's kidnapping is widely known.

Bob doesn't make it but Eve, Frank, and Gary tell Carol that his life is a small price to pay for standing up to Alice's terrorism.


The public article just mentions phone scams, but now having read the Outline link I see the private version goes into much more. Obviously PSAs aren't an approach to ransomware, but talking about the need to take software security seriously isn't as directly actionable.


They get arrested as soon as they land on US-friendly soils. (ie: https://en.wikipedia.org/wiki/Alexander_Vinnik )

But, yeah, otherwise the US can't do much if they are currently in Russia or China.


Indeed; I mentioned that, with Vinnik as an example, in https://news.ycombinator.com/item?id=27097212


They're mostly untraceable, but not completely. That's why Monero devs keep trying to increase the ring size.


> That's why Monero devs keep trying to increase the ring size.

Is there anything stopping them? It is my understanding that larger signature rings are always better. Currently it seems to be fixed at 11 signatures. Why not a larger number?

https://www.getmonero.org/resources/moneropedia/ring-size.ht...


Larger transaction size (and hence chain size growth) and verification times.


Is there any data on the strength of the current ring size of 11? Is it sufficient to prevent tracking?


Thanks, I've clarified my post.


but cross chain tx of millions of dollars of btc to xmr is not exacly trivial, unles there is someitng i am missing


Indeed; it's their country's law enforcement being okay with the crimes that's the core of the problem, here.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: