Logo
    Search

    147: Tornado

    en-usJuly 02, 2024

    Podcast Summary

    • Digital Assets OwnershipThe value of digital assets is not determined by production cost or ease of replication, but by demand and convenience. Ownership and control can be complex and uncertain.

      Despite the intangible nature of digital assets, they hold significant value in our lives and in the economy. However, ownership and control over these assets can be complex and often uncertain. The discussion highlighted various examples, from stolen art to digital files and online accounts, revealing the blurred lines between what we perceive as ours and what is truly under someone else's control. The value of digital assets is not determined by their cost of production or the ease of replication, but rather by demand and the convenience they offer. As our lives become increasingly digital, it's crucial to understand the nuances of ownership and control in this domain.

    • Digital Ownership in GamingPlayers can buy, sell, and truly own virtual assets in decentralized blockchain games like Axie Infinity, providing an alternative source of income during the pandemic

      On the dark web, you can create and truly own your own domain using cryptography, and in the world of cryptocurrencies like Ethereum, you can digitally own and control your assets through decentralized blockchains. The game Axie Infinity, built on the Ethereum blockchain, exemplifies this concept by allowing players to buy, sell, and own virtual creatures called Axies using cryptocurrency. This fusion of digital ownership and gaming has attracted a large following, and during the COVID-19 pandemic, many players in Southeast Asia saw it as an alternative source of income. The value of Axie Infinity's in-game currency skyrocketed, reaching astonishing heights, and the decentralized marketplace allowed for direct transactions between players. This innovative approach to gaming and ownership is a testament to the potential of blockchain technology and the digital world.

    • Crypto in GamingCrypto use in popular games like Counter-Strike 2 has led to the creation of decentralized marketplaces and side chains, but also attracts scammers and security concerns

      Despite Steam banning crypto-based games due to regulatory uncertainties and potential risks to the in-game economy, players have found ways to use cryptocurrency for buying and selling in-game items in popular games like Counter-Strike 2. This has led to the creation of decentralized marketplaces and side chains like Ronin Network to facilitate faster and cheaper transactions. However, the popularity and significant value of these games have also attracted scammers and thieves, leading to security concerns and potential losses for players. The use of cryptocurrency in video games presents both opportunities and challenges, highlighting the need for robust security measures and clear regulatory frameworks.

    • Social engineering attacks on video game companiesSocial engineering tactics can trick employees into downloading malware, granting hackers deep-level access to systems and leading to significant financial losses.

      Video game companies and their employees are prime targets for hackers looking to steal valuable assets and sensitive information. In this instance, hackers targeted an engineer at Sky Mavis, a company behind the popular game Axie Infinity, using social engineering tactics to gain access to their systems. The hackers offered the engineer a fake job, which resulted in the downloading of malware onto their work device, granting the hackers deep-level access to Sky Mavis' computer systems. The hackers then focused on the Ronin Bridge, a conduit for money flowing in and out of Axie Infinity, and gained control of five out of nine validator computers to take over the bridge and control the flow of money. The result was a theft of over $600 million in cryptocurrency. This incident highlights the importance of security awareness and the need for companies to maintain control of all aspects of their systems to prevent such attacks.

    • North Korean money launderingNorth Korea is a leading suspect in the Axie Infinity hack, but due to the massive volume of stolen funds, traditional money laundering methods are impractical. Thieves must find a way to move the funds to places with high liquidity and convert it into hard currency, making it a complex and ongoing process.

      The Axie Infinity hack, where $625 million in cryptocurrency was stolen, presents a significant challenge for the thieves looking to cash out. North Korea is a leading suspect due to its history of state-sponsored cybercrimes, but the sheer volume of stolen funds requires a flexible and mobile money laundering scheme. Traditional methods like setting up an exchange in North Korea are impractical due to the lack of goods or services to purchase with the stolen funds within the country. Instead, the thieves must find a way to move the money to places with high liquidity and convert it into hard currency, making it a complex and ongoing process.

    • Cryptocurrency LaunderingDespite offering anonymity, cryptocurrencies can be traced and laundered funds face challenges due to international sanctions and flagged wallets. Non-custodial, decentralized privacy tools like Tornado.Cash offer a solution, but their use raises ethical concerns.

      While cryptocurrencies offer a level of anonymity, they are not completely untraceable. North Korea, having stolen cryptocurrency from Axie Infinity, faced challenges in laundering the funds due to international sanctions and flagged wallets. They turned to Tornado.Cash, a privacy tool designed to obfuscate the origin of transactions. However, unlike traditional money laundering methods or custodial mixers, Tornado.Cash operates as a non-custodial, decentralized service. It does not hold users' funds, making it legally distinct. The developers ensured they could never access users' money by coding it into a smart contract. Despite potential misuse, the developers emphasized its privacy-preserving benefits and made it publicly accessible. This case underscores the importance of understanding the nuances of cryptocurrency transactions and the role of privacy tools in the digital economy.

    • Cryptocurrency privacy tools regulationThe decentralized and autonomous nature of cryptocurrency privacy tools like Tornado Cash poses unique challenges for law enforcement in preventing illegal activities, as seen in the ongoing debate between privacy preservation and regulation.

      The decentralized and autonomous nature of Tornado Cash, a cryptocurrency privacy tool, posed unique challenges for law enforcement when it was allegedly used in connection with large-scale money laundering. The organization behind Tornado Cash claimed it was created to preserve privacy, but the US government argued that the creators were still responsible for ensuring their service did not facilitate illegal activities. The decentralized and open-source nature of Tornado Cash made it difficult for authorities to shut it down or seize funds associated with it. The debate highlights the complexities and gray areas surrounding financial privacy, cryptocurrency regulation, and the responsibilities of creators in the digital age.

    • Financial SurveillanceFinancial surveillance, such as China's social credit system, can infringe on individual privacy and freedom, potentially leading to oppressive consequences. Privacy tools like Tornado Cash are essential for maintaining anonymity and supporting causes without fear of retaliation.

      The surveillance of financial systems can lead to significant issues in a free society. An example of this is China's social credit system, which restricts individuals based on their purchases and monitors their activities. The need for privacy in financial transactions is crucial, especially for those living in oppressive regimes where speaking out against the government could result in imprisonment. The use of privacy tools like Tornado Cash is essential for maintaining anonymity and supporting causes without fear of retaliation. The ongoing debate surrounding the responsibility of creating and sanctioning code, as well as the implications for freedom of speech, adds complexity to this issue. The increasing prevalence of digital money and autonomous businesses presents new challenges for governments in regulating financial transactions, leading to unprecedented actions like sanctioning code. This situation raises concerns about privacy, freedom, and the potential chilling effect on innovation.

    • Crypto mixing services regulationIntense scrutiny on privacy-focused crypto mixing services due to money laundering concerns, but regulatory challenges remain due to technology neutrality and user responsibility

      The use of privacy-focused cryptocurrency mixing services like Tornado.cash is under intense scrutiny from law enforcement agencies. Companies track the volume and amounts going in and out of these services, but cashing out large sums anonymously remains a challenge due to the need for significant liquidity. The developers of such services, who argue for privacy preservation, are being accused of complicity in money laundering and other illegal activities. However, the neutrality of the technology itself and the responsibility of users for their actions are important considerations. The ongoing legal battles surrounding Tornado.cash and its developers highlight the complexities and uncharted waters of regulating decentralized technologies. Despite sanctions, Tornado.cash remains operational, and there is ongoing debate about the effectiveness and necessity of such regulations.

    • Crypto privacy tools sanctionsThe use of privacy tools in cryptocurrencies like Tornado.cash for evading sanctions has led to government actions and raised questions about financial regulation and privacy in the digital age. The crypto space's complexity introduces new challenges for identifying transactions that have passed through privacy tools.

      The use of privacy tools like Tornado.cash, a cryptocurrency mixer, has become a contentious issue due to its potential use in evading sanctions. The US government's sanctions on Tornado.cash have raised questions about the boundaries of financial regulation in the digital age. The case of Tornado.cash is not an isolated incident, as other privacy services have also faced similar actions from authorities. The debate around privacy and encryption has historical precedents, such as the case of Phil Zimmerman and PGP encryption. However, the crypto space's complexity introduces new challenges, as it is unclear if exchanges will be able to identify transactions that have passed through privacy tools like Tornado.cash. The implications of these developments for privacy, financial regulation, and the future of cryptocurrencies are significant and ongoing.

    • Cryptocurrency money launderingCryptocurrency money laundering is a complex issue with criminals using advanced techniques to hide their transactions and create new wallets, making it difficult for authorities to trace. The FBI has issued a warning against using anonymous cryptocurrency services, raising concerns about privacy and potential infringement on individual rights.

      While cryptocurrency tracing is advanced, there are still ways for criminals to launder money through complex transactions and new wallets, making it difficult for authorities to trace. Jeff White, the author of the book "Rinsed," discussed these methods during a recent interview. The book delves deeper into modern money laundering techniques and their implications for our future. The FBI has issued a warning against using cryptocurrency services that don't require personal information, which raises concerns about privacy and potential infringement on individual rights. The FBI's warning represents a push towards a future where privacy may no longer exist. The book "Rinsed" offers valuable insights into these issues and is worth exploring further. The interview and this episode were brought to you by Jackary Sider (the firewall fidgeter) and Tristan Ledger (the router rigger), with mixing by Prexsemani Sound and intro music by the mysterious breakmaster cylinder. Privacy and security are essential, and we must be aware of the potential threats and implications of giving up these fundamental rights.

    Recent Episodes from Darknet Diaries

    147: Tornado

    147: Tornado

    In this episode, Geoff White (https://x.com/geoffwhite247) tells us what happened to Axie Infinity and Tornado cash. It’s a digital heist of epic proportions that changes everything.

    This story comes from part of Geoff’s book “Rinsed” which goes into the world of money laundering. Get yours here https://amzn.to/3VJs7pb.

    Darknet Diaries
    en-usJuly 02, 2024

    146: ANOM

    146: ANOM

    In this episode, Joseph Cox (https://x.com/josephfcox) tells us the story of anom. A secure phone made by criminals, for criminals.

    This story comes from part of Joseph’s book “Dark Wire” which you should definitely read. Get yours here https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691.

    Darknet Diaries
    en-usJune 04, 2024

    145: Shannen

    145: Shannen
    Shannen Rossmiller wanted to fight terrorism. So she went online and did. Read more about her from her book “The Unexpected Patriot: How an Ordinary American Mother Is Bringing Terrorists to Justice”. An affiliate link to the book on Amazon is here: https://amzn.to/3yaf5sI. Thanks to Spycast for allowing usage of the audio interview with Shannen. Sponsors Support for this show comes from Varonis. Do you wonder what your company’s ransomware blast radius is? Varonis does a free cyber resilience assessment that tells you how many important files a compromised user could steal, whether anything would beep if they did, and a whole lot more. They actually do all the work – show you where your data is too open, if anyone is using it, and what you can lock down before attackers get inside. They also can detect behavior that looks like ransomware and stop it automatically. To learn more visit www.varonis.com/darknet. Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free. Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    144: Rachel

    144: Rachel
    Rachel Tobac is a social engineer. In this episode we hear how she got started doing this and a few stories of how she hacked people and places using her voice and charm. Learn more about Rachel by following her on Twitter https://twitter.com/RachelTobac or by visiting https://www.socialproofsecurity.com/ Daniel Miessler also chimes in to talk about AI. Find out more about him at https://danielmiessler.com/. Sponsors Support for this show comes from Varonis. Do you wonder what your company’s ransomware blast radius is? Varonis does a free cyber resilience assessment that tells you how many important files a compromised user could steal, whether anything would beep if they did, and a whole lot more. They actually do all the work – show you where your data is too open, if anyone is using it, and what you can lock down before attackers get inside. They also can detect behavior that looks like ransomware and stop it automatically. To learn more visit www.varonis.com/darknet. Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free. Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    143: Jim Hates Scams

    143: Jim Hates Scams
    Jim Browning has dedicated himself to combatting scammers, taking a proactive stance by infiltrating their computer systems. Through his efforts, he not only disrupts these fraudulent operations but also shares his findings publicly on YouTube, shedding light on the intricacies of scam networks. His work uncovers a myriad of intriguing insights into the digital underworld, which he articulately discusses, offering viewers a behind-the-scenes look at his methods for fighting back against scammers. Jim’s YouTube channel: https://www.youtube.com/c/JimBrowning Sponsors Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more. This episode is sponsored by Intruder. Growing attack surfaces, dynamic cloud environments, and the constant stream of new vulnerabilities stressing you out? Intruder is here to help you cut through the chaos of vulnerability management with ease. Join the thousands of companies who are using Intruder to find and fix what matters most. Sign up to Intruder today and get 20% off your first 3 months. Visit intruder.io/darknet. This show is sponsored by Shopify. Shopify is the best place to go to start or grow your online retail business. And running a growing business means getting the insights you need wherever you are. With Shopify’s single dashboard, you can manage orders, shipping, and payments from anywhere. Sign up for a one-dollar-per-month trial period at https://shopify.com/darknet. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    142: Axact

    142: Axact
    Axact sells fake diplomas and degrees. What could go wrong with this business plan? Sponsors Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more. Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com. This show is sponsored by Shopify. Shopify is the best place to go to start or grow your online retail business. And running a growing business means getting the insights you need wherever you are. With Shopify’s single dashboard, you can manage orders, shipping, and payments from anywhere. Sign up for a one-dollar-per-month trial period at https://shopify.com/darknet. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    141: The Pig Butcher

    141: The Pig Butcher
    The #1 crime which results in the biggest financial loss is BEC fraud. The #2 crime is pig butchering. Ronnie Tokazowski https://twitter.com/iHeartMalware walks us through this wild world. Sponsors Support for this episode comes from NetSuite. NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more. Support for this show comes from Drata. Drata streamlines your SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR & many other compliance frameworks, and provides 24-hour continuous control monitoring so you focus on scaling securely. Listeners of Darknet Diaries can get 10% off Drata and waived implementation fees at drata.com/darknetdiaries. This show is sponsored by Shopify. Shopify is the best place to go to start or grow your online retail business. And running a growing business means getting the insights you need wherever you are. With Shopify’s single dashboard, you can manage orders, shipping, and payments from anywhere. Sign up for a one-dollar-per-month trial period at https://shopify.com/darknet. Learn more about your ad choices. Visit podcastchoices.com/adchoices

    139: D3f4ult

    139: D3f4ult
    This is the story of D3f4ult (twitter.com/_d3f4ult) from CWA. He was a hacktivist, upset with the state of the way things were, and wanted to make some changes. Changes were made. Sponsors Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free. Support for this show comes from Thinkst Canary. Their canaries attract malicious actors in your network and then send you an alert if someone tries to access them. Great early warning system for knowing when someone is snooping around where they shouldn’t be. Check them out at https://canary.tools. Support for this show comes from Quorum Cyber. Their mantra is: “We help good people win.” If you’re looking for a partner to help you reduce risk and defend against the threats that are targeting your business — and especially if you are interested in Microsoft Security — reach out to Quorum Cyber at www.quorumcyber.com/darknet-diaries. Sources https://www.vice.com/en/article/z3ekk5/kane-gamble-cracka-back-online-after-a-two-year-internet-ban https://www.wired.com/2015/10/hacker-who-broke-into-cia-director-john-brennan-email-tells-how-he-did-it/ https://www.hackread.com/fbi-server-hacked-miami-police-data-leaked/ https://archive.ph/Si79V#selection-66795.5-66795.6 https://wikileaks.org/cia-emails/John-Brennan-Draft-SF86/page-7.html Learn more about your ad choices. Visit podcastchoices.com/adchoices

    138: The Mimics of Punjab

    138: The Mimics of Punjab
    This episode is about scammers in the Punjab region. Tarun (twitter.com/taruns21) comes on the show to tell us a story of what happened to him. Naomi Brockwell (twitter.com/naomibrockwell) makes an appearance to speak about digital privacy. To learn more about protecting your digital privacy, watch Naomi’s YouTube channel https://www.youtube.com/@NaomiBrockwellTV. And check out the books Extreme Privacy (https://amzn.to/3L3ffp9) and Beginner’s Introduction to Privacy (https://amzn.to/3EjuSoY). Sponsors Support for this show comes from Axonius. The Axonius solution correlates asset data from your existing IT and security solutions to provide an always up-to-date inventory of all devices, users, cloud instances, and SaaS apps, so you can easily identify coverage gaps and automate response actions. Axonius gives IT and security teams the confidence to control complexity by mitigating threats, navigating risk, decreasing incidents, and informing business-level strategy — all while eliminating manual, repetitive tasks. Visit axonius.com/darknet to learn more and try it free. Support for this show comes from SpyCloud. It’s good practice to see what data is getting passed around out there regarding you, your employees, your customers, and your business. The dark web is a place where this data is traded and shared. SpyCloud will help you find what out there about you and give you a report so you can be aware. Then they’ll continuously monitor the dark web for any new exposures you should be aware of. To learn more visit spycloud.com/darknetdiaries. Support for this show comes from ThreatLocker. ThreatLocker has built-in endpoint security solutions that strengthen your infrastructure from the ground up with a zero trust posture. ThreatLocker’s Allowlisting gives you a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker provides zero trust control at the kernel level. Learn more at www.threatlocker.com. Learn more about your ad choices. Visit podcastchoices.com/adchoices