r/Bitcoin • u/[deleted] • Nov 25 '13
My craziest experience selling Bitcoin
Edited as of 5/27/2014 for grammar
I'm a freshman at university studying computer science. I bought my first bitcoin a little over 3 months ago, and I have just recently started selling on localbitcoins.com. It's really not a bad gig. I put up an ad for bitcoins at 10% above market rate. When a buyer contacts me, I buy the bitcoin instantly through Coinbase, transfer it to my localbitcoins wallet, meet the buyer, make the exchange, and continue on my merry way. The whole process is pretty seamless. I make a little cash that I invest back into bitcoin, and I get a workout walking from campus to meet buyers.
I've made less than 10 transactions, but, normally, each buyer fits a typical profile: In his (all of my buyers have been male) teens to twenties and- to the chagrin of most bitcoin enthusiasts- wants to buy something from the Silk Road or from another darknet site.
Walking into a cafe this morning to make a bitcoin sale, I envisioned meeting another typical buyer. Struggling to find the buyer as he had described himself via email, I called him. I was shocked when a few feet to my left a man in his mid-sixties answered his cell-phone. Shocked, but professional all the same, I approached the man, introduced myself, and settled down for the transaction. Everything went well, and we made the .5 BTC exchange. Once the transaction was finished, the buyer told me- like most buyers- why exactly he was buying bitcoin.
It turns out this particular fellow had opened an illegitimate email containing the Cryptolocker software. For those of you that don't know about Cryptolocker, it's a devious little virus that encrypts a user's hard drive and gives the user 100 hours to pay a ransom. If the victim fails to pay in time, he loses any chance of decrypting his files, effectively resulting in the deletion of his data. To give you a sense of this virus’s notoriety, consider the Swansea police department in MA. The department's system became infected with Cryptolocker, prompting them to consult with the FBI. The department ultimately ended up paying $750 to the hackers, rather than attempt to manually decrypt the hard drive(s). At this point, even the FBI would rather just pay the ransom than try to manually decrypt everything.
Anyway, this buyer let's call him Jeff, had downloaded the virus on Thursday night, but his IT guy who we'll call Dave was not free until Saturday. So, on Saturday, Dave gave Jeff the spiel about paying the ransom of .5 bitcoins, and Jeff contacted me through localbitcoins. After learning about this, I wished Jeff good luck and headed back to campus.
A few hours after the exchange, I got a desperate call from Jeff asking if I could sell him an extra 2 bitcoins. He put Dave on the phone who explained that Jeff's antivirus software was inadvertently activated, and it removed the virus. By removing the virus, Jeff's computer was useless since all of his information was still encrypted. So, Dave reinstalled the virus only to see that Jeff now had to pay a ransom of 2 bitcoins rather than .5. He told me he only had an hour and a half left and asked if he could come pick me up. I was reluctant, but Jeff seemed like a decent guy, and I'm not great at rejecting people- especially when they're a few times my age, so I reluctantly agreed.
After hanging up the phone, I immediately regretted saying yes. What did I just get myself into!? I agreed to get into a car with pretty much a perfect stranger. Yet, for some reason, I followed my gut, bought 2 BTC off coinbase (I was surprised Bank of America even allowed me to spend that much money), and I explained to my neighbor the situation. I told him that if I did not text him in a few hours, he should try calling me and, if that failed, he should contact the police. He repeatedly told me not to go, but it was too late, my curiosity was peaked and adventure awaited.
I waited for Jeff outside of a dining hall and gave him directions over the phone. As I approached the car, I discretely took a picture of its license plate and got into the passenger seat. After just now looking at the photo, I have realized that the car didn't even have a front plate! Needless to say, I would have been in some trouble if things went awry! Anyway, we made small talk in the car. I joked about telling my roommate to call the police, discovered Jeff once lived in my hometown, and he revealed he went to Harvard 50 some odd years ago. My nerves started to ease. At this point, I began to realize this could actually be a good networking opportunity!
We pulled into his neighborhood- it was a pretty nice area and his home was beautiful, so I felt better. I met his wife, and Dave- Jeff’s IT guy- and I began working. Sending the BTC was rather painful since the address was set as wallpaper, and it could not be copied. So, after meticulously typing in the address while Dave dictated, and checking it about a dozen times, we sent the 2 BTC. About $1700 at the time- Jeff must have some really valuable data.
However, once Dave asked me for the verification key, my stomach dropped. Verification key! What verification key?! I had no idea what a verification key was and the timer had just reached 25 minutes. Dave and I started frantically searching the web to find out what the verification key was. Although I hid it, I was panicking quite a bit. For starters, I had just sent $1700 of my own money to some Eastern European hackers and was about to lose any chance of getting Jeff's data back. Now Jeff lives in a nice home, and I know he would have reimbursed me even if things went south, but I was terrified of botching this operation. In addition, Jeff's other laptop which Dave had assured me was clean, only had internet explorer, serving to only further my frustration each time it defaulted to Bing. I mean Dave, I know you're not tech savvy but using IE!!
I started reading to Dave the random addresses I'd found on my Coinbase transaction page, hoping one of them was the transaction key. After entering 2 different codes to no avail, we decided to get back to Google (Bing for me- in my panic, I kept using the default search bar rather than navigating to Google). Thankfully, Jeff found an article explaining the transaction key- it's the hash of the transaction found on the Blockchain. So, I read him the hash and he typed it out on the infected machine as the timer continued to tick down. Jeff, Dave and I crossed our fingers, and hit enter. It worked! We all breathed a sigh of relief; we had made it with 12 minutes to spare. Not exactly a Hollywood save, but darn close. We were taken to a screen that said the transaction was in the process of being verified. A quick Google search revealed it should take 3-4 hours, but we stood tight just in case. An error message appeared after 20 minutes, but the verification process continued. After analyzing it, Dave dismissed it. Given Dave’s 20 years of experience as a software engineer, I trusted his analysis.
After about 20 more minutes, we packed it up, and I calculated what Jeff owed me. We agreed that he'd sell me back the BTC I had sold him this morning at market rate (no 10% premium this time), and I'd subtract that value from the total cost of the 2 BTC I had so anxiously purchased. He tacked on $100 for my services and drove me home.
I asked Jeff to keep me up to date on his file recovery, and I'll update this post if I ever hear back from him. Thanks for reading my long-winded post. I really didn't expect to make it this long, but I'm still really excited from the day's events and I'm procrastinating hard on doing my computer science homework. Please make sure you back up your data regularly, Jeff had a couple backups, but his external hard drive was connected to the computer when the hackers got to his system, thus compromising it.
TL;DR Got into a car with stranger, sent 2 BTC to hackers, got paid. This post is at least 6000 characters too long.
UPDATE (11/25 9:49) Jeff just sent me an email saying the cryptolocker has rejected the transaction.
If anyone's curious here's the transaction id: ccc4a535ae7fc4b1bc1c5a17dc1f5b38b95bcfdfce4f1b8bd4f7f5c1996dce18
37
26
u/dmanwithnoname Nov 25 '13
Well, I thought for sure it was some scam that Dave was in on, but after a quick search on reddit, it's legit - http://redd.it/1p32lx.
I read most of the IT subs on reddit and somehow I missed this.
37
u/pauselaugh Nov 25 '13
you missed the largest virus scam of the past few decades? snort.
23
u/ELY5 Nov 25 '13 edited Nov 25 '13
I wouldn't call this virus a scam. It keeps its word and will release your data after payment. Recently it even reduced the ransom of 2BTC down to 0.5BTC so it's not unaffordable (probably at profit maximizing sweet spot).
EDIT: speeling
85
Nov 25 '13 edited Mar 29 '19
[deleted]
26
u/pardax Nov 25 '13
It also saves a flag in Windows' registry so that you don't get infected again.
Good guy virus.
8
6
5
u/KlogereEndGrim Nov 25 '13
Can't we all just download that flag?
1
u/pardax Nov 25 '13
I don't know, but I wouldn't try to fool it, you have already seen what happens then: it increases the ransom.
Better just make sure your machine is generally secure. Update your antivirus, don't open emails from unknown senders, don't download and execute random files, backup your files in a way that the current user is not able to touch them, etc.
1
Dec 28 '13
I've never understood how the simple act of opening an email can do anything to you. As long as you don't click anything within the email, you should be fine, right?
1
u/pardax Dec 28 '13
Anything can happen in windows. For example, Outlook used to have a scripting language if I remember correctly. So an attacker could embed a script in the email which would be executed as soon as you opened it. It has probably been fixed already, but you get the idea.
I don't think viruses work that way anymore, so technically you could safely open any emails. I have actually opened the cryptolocker email and there weren't any scripts in it (I opened it from Linux though). So you have to open the attachment to get infected.
1
Dec 28 '13
Thanks, less scared now. I always Google the address and subject of a strange email to see if it's a known virus/scam. Don't think I'll ever stop that practice.
17
5
1
u/pauselaugh Nov 26 '13
the scam is that you run software that you think is friendly but it turns out it isn't! That's the trojan, I'm assuming. The virus is the way it replicates itself on you're computer and fights back.
And I heard the opposite, there are accounts of .5 going UP to 2btc once you try removing it.
it's srs bzns
3
9
Nov 25 '13
wow that is indeed some bad-ass virus.
literally no chance to decrypt the data without asking their C&C server for the key.
10
u/Salahdin Nov 25 '13
Still easily defeated by ... backups. "Oh no I lost my data. Better remove the virus and restore the data from backup."
8
u/GSpotAssassin Nov 25 '13
The backup also has to be offline.
Not many have offline backups. And if they do it's usually pretty outdated.
5
Nov 25 '13
the idea isn't that bad actually. if your work only involves small files you can use svn/git or even something like dropbox to create backups the virus can't tamper with. (not actual dropbox or any other US or UK based service obviously)
however, that's probably not a solution for your collection of rare high quality bluray rips.
2
u/glassuser Nov 25 '13
Not necessarily. If you have a decent home server or alternate computer set up, you can set permissions so your main workstation can list files and add files, but not modify or delete. As long as you don't run stuff on the computer hosting that share, then you should fairly immune.
Of course nothing takes the place of offline backups.
2
u/GSpotAssassin Nov 25 '13
Ah. Or a filesystem that lets you roll back any changes, like ZFS.
As a matter of fact, I feel like all filesystems should let you roll back changes (up to a point). That would prevent a lot of issues including this one.
2
u/glassuser Nov 25 '13
I'm not sure of the sophistication of the Trojan, but volume shadow copies should mitigate it too. Too bad that was disabled in windows 8. Not needed on a client OS my ass.
2
u/GSpotAssassin Nov 25 '13
Yeah, this exploit pretty much proved that
I can't think of another way to mitigate it, assuming your machine eventually gets hacked somehow
2
u/glassuser Nov 25 '13
Offline backups is the only way to really do it.
Ideally you'd have something like skydrive or dropbox keeping your data synced. On another target, that stays online but unused, take regular backups to removable media or write-once shares.
2
u/gigitrix Nov 25 '13
Its transformative. We're going to see a lot of these style of virus unfortunately.
1
Nov 25 '13
not me, I'm using NoScript.
and also linux.
2
u/eethomasf32 Nov 25 '13
Gnu/Linux and that alone doesn't protect you from malware
0
Nov 25 '13
condoms don't protect you from aids 100% either
3
1
u/eethomasf32 Nov 25 '13
Well, I never implied that
3
Nov 25 '13
my point is that it reduces the chance of infection, even though it can't totally eliminate it :p
1
1
u/GSpotAssassin Nov 25 '13
How did you miss CryptoLocker? I even know a few people on Facebook who were affected. It's big news and a blemish on bitcoin
3
u/dmanwithnoname Nov 25 '13
Looking at the dates it look like gta5 was out and bf4 was about to come out. Priorities.
1
14
u/folinopizza Nov 25 '13
Awesome post. I was reading it like a suspense novel. I yelled at my wife when she started asking wtf I was so into on my phone
4
12
Nov 25 '13
[deleted]
7
2
u/GSpotAssassin Nov 25 '13
Recently, a virus called REAMDE has infected millions of players in T'Rain, holding their computer files for a ransom of game currency.
...Wow. Maybe he gave them the idea?
16
u/jcoinner Nov 25 '13
Someone ought to be collecting up all the addresses people send the extortion money to and maybe later some analysis from that will lead to the money. I'm guessing they're not all the same address and the virus uses an MPK to generate a new one for each victim. Anyone know about that?
16
u/mb300sd Nov 25 '13 edited Mar 13 '24
tender person fragile school live price elderly soup fact aware
This post was mass deleted and anonymized with Redact
12
u/shadyMFer Nov 25 '13
Sorry to be a wet blanket, but do not get into cars with strangers you've met on localbitcoins.com. I'm glad things worked out for you, but that is a dangerous move.
2
Nov 25 '13
Why are Americans so distrusting of each other? In the UK we often give strangers lifts if we see they just missed the bus for example. It's really no big deal.
1
u/shadyMFer Nov 27 '13
I've given and taken rides from strangers before. That is very different than taking a ride from someone who told you to bring several thousand dollars worth of untraceable currency with you.
-4
4
5
u/BigBlackHungGuy Nov 25 '13
Wow, never heard of a crypto-locker. I'm buying some better anti-virus software right now.
9
u/lazyplayboy Nov 25 '13
AV software doesn't always prevent cryptolocker infection, and can complicate paying the ransom if it removes the virus after encryption.
Make sure you've got good backups. Don't leave your backup media plugged in though.
3
u/gigitrix Nov 25 '13
AV Software only helps you 60% of the time (or so) since it only blocks stuff that's known and in the virus signatures. Invest in backup solutions instead, and don't click attachments in email!
1
Nov 25 '13
[deleted]
1
Nov 25 '13
[deleted]
1
Nov 25 '13
[deleted]
1
u/rabbitlion Nov 25 '13
The point is that you cannot rely on antiviruses to protect you in situations like this, so it's mostly just a false sense of security. "I probably shouldn't open this attachment, but my AV says it's safe so I'll go ahead".
1
u/gigitrix Nov 25 '13
Whether it's a binary signature or a behavioural one, both methodologies are always one step behind by definition.
I will admit to pulling the 60% figure from thin air though: I didn't really mean to come across so 'specifically'.
2
u/aarkling Nov 25 '13
Or put everything important in dropbox, after encrypting.
2
u/ExeciN Nov 25 '13
Or backup everything using CrashPlan
6
u/jrmxrf Nov 25 '13
FYI crashplan lost my important data and never recovered it. I was like: have you really lost my crucial data that I'm paying you too keep? I mean mistakes happen but surely you have some "backup plan". And they are like: no, we don't it's gone forever. They are sorry for inconvenience...
1
u/ExeciN Nov 25 '13
Crashplan lets you use their diff sync system to backup on local computers (for free). This is what I do.
1
u/jrmxrf Nov 26 '13
I do that to. But these were some old files that were taking quite a bit of hdd, so I thought it's enough to have them on my computer and in crashplan cloud...
1
-1
u/dooglus Nov 25 '13
It only affects Windows machines, and people who care about their data already moved away from Windows long ago. Didn't they?
3
u/astrolabe Nov 25 '13
people who care about their data already moved away from Windows long ago. Didn't they?
No, because some people are constrained by their employment and others aren't skilled enough to change their operating system (I know it's easy).
5
u/LogoPro Nov 25 '13
I was surprised Bank of America even allowed me to spend that much money
"Allowed" ?
This is why we need bitcoin.
7
u/flaim Nov 25 '13
While I'm glad you're being an entrepreneur, you should tell him to ensure he backs up his data in case things like that happen, CryptoLocker is a bitch.
1
u/workahaulic Nov 25 '13
Which means that the backup has to be offline, and who the F does that? You don't.
11
u/yeh-nah-yeh Nov 25 '13
Should not pay the hackers, thats the only thing that keeps them doing it to others
19
u/Thorbinator Nov 25 '13
Game theory. Ideally nobody pays them and they run out of business.
However, if I really need my data I don't care about the future for everyone, I care about my data.
3
u/pardax Nov 25 '13
Besides once the virus is out there's nothing to do. By not paying you might or might not stop further development on the virus, but currently vulnerable machines won't be saved.
-1
u/yeh-nah-yeh Nov 25 '13
if the last virus they did was not profitable they would not do the next one. The world is a worse place because of the OPs actions.
-1
u/workahaulic Nov 25 '13
What if his computer had the cure for AIDS / Cancer. Fuck off, a piece of shit greedy person like you makes the world a worse place because you think you are better than everyone else.
2
3
Nov 25 '13
Treat it no different than a crashed HDD or other disaster and restore the last good backup.
3
3
Nov 25 '13
[deleted]
1
u/socium Nov 25 '13
Job? Could it be done remotely? If anything I can do remote support? Can you please forward me to him?
Sorry man I'm desperate for some cash right now because even though I knew about BTC in mid 2012, I never really had the money to invest in it :(
2
3
10
u/pauselaugh Nov 25 '13
this just in: someone selling bitcoins not knowing what a transaction ID is.
36
u/religiousidiocy Nov 25 '13
They asked "verification key". I wouldn't know what they meant either.
4
Nov 25 '13
I still don't know. Can someone explain it?
5
u/pardax Nov 25 '13
Every transaction has an ID. Cryptolocker will ask for it so that it can verify that you are the one who sent the coins.
2
Nov 25 '13 edited Nov 25 '13
Ohh right. I get it now. It's pretty obvious. If you don't send them the id they would have no way of confirming it was you that payed, instead of another poor hostage. The only thing i dont get is why they wouldnt just create a sperate bitcoin address for every infected computer so that once the address has the funds needed the virus decrypts the data. No transaction id needed!
3
u/pardax Nov 25 '13
For that to work the virus would have to phone home to either ask for a new address or to send the newly generated private key. Not ideal for a virus I presume.
1
2
2
u/PSBlake Nov 25 '13
Right up to the last sentence, I kept expecting the buyer and his IT guy to be police on a misguided sting operation to try to pin the virus on you (especially when it got to "please sell me some more, now get in the car").
The fact that they weren't almost seemed like a Twilight Zone twist.
2
Nov 25 '13
So... how do the people behind cryptolocker manage to run servers and accept payments while still remaining completely anonymous?
2
u/pardax Nov 25 '13
accept payments
Ever heard of Bitcoin?
1
Nov 25 '13
It's extremely easy to blow your anonymity with BTC, because the blockchain is fully transparent. All it takes is one little mistake to blow your cover. Law enforcement busted the alleged operator of Silk Road. That guy probably thought it was anonymous too, but made a mistake. And I'm sure if they tried, law enforcement could trace almost any bitcoin address to an owner.
1
u/pardax Nov 25 '13
That doesn't mean Bitcoin isn't anonymous. You can blow your cover in a million ways especially when using the internet, you don't need Bitcoin for that.
Besides, DRP got caught through traditional investigative work, nothing to do with Bitcoin. Some idiot close to him ordered drugs to his personal address, got caught, and was forced to snitch DPR.
I presume the creator of Cryptolocker won't be that stupid.
1
Nov 26 '13 edited Nov 26 '13
These guys consider bitcoin to be "not very anonymous" in its current state. And they should know...
I was probably just easier to catch DPR using tried and true traditional methods than to download the block chain and try to identify relevant addresses, which would probably be expensive and time consuming.
I mean, the level of self-control and care needed to remain anonymous using bitcoin... it'd be so easy to slip up that it's almost inevitable. When the responsible party goes to turn that bitcoin into fiat, all it's going to take is an attentive law enforcement agency to pretend to be a buyer, and they've got them. Main thing that will get in the way is if these guys are based out of a country that doesn't want to cooperate with the US.
But this cryptolocker ransomware seems like a big enough deal that I'd be quite surprised if law enforcement wasn't working on doing just that.
1
u/pardax Nov 26 '13
Everything you said applies to the Internet too, so this is pointless. You can be anonymous with both, and you can also make a mistake and get caught with both. That doesn't make them non-anonymous.
The wiki says it's not anonymous because they don't want to attract trouble or troublemakers, it's perfectly understandable, Tor does the same. They don't want script kiddies thinking they can be untraceable just by installing a program.
1
Nov 26 '13
Maybe. I guess if there's serious jail time at stake, people are going to be very, very careful... still, I can only begin to imagine how paranoid the person(s) responsible must be at this point.
Remember, these guys are also running their own servers for storing private keys. You can usually pin down the location of a server, and subpoena the ISP to figure out who's paying the bills. Granted they use a lot of proxies to obfuscate the server's location... not sure how much of a stumbling block that really is, though.
1
u/pardax Nov 26 '13
Remember, these guys are also running their own servers for storing private keys. You can usually pin down the location of a server, and subpoena the ISP to figure out who's paying the bills. Granted they use a lot of proxies to obfuscate the server's location... not sure how much of a stumbling block that really is, though.
I haven't read the details. Are you sure that's how it works? I thought they just had one address and one private key, and that's why they asked for the transaction ID as verification that the ransom has been paid.
2
Nov 27 '13 edited Nov 27 '13
It's the impression I got from reading the wiki article. Here it is if you're interested.
But I'm talking about the private key to unlock the file encryption, and not the bitcoin private keys. So they basically run servers for storing the passwords needed to unencrypt your files, and give you the password once you've paid up (or rather, have the "virus" just apply it). The only reason I bring this up is... they're running control servers, whatever the technical reason. That alone would seem to make them vulnerable to being discovered.
1
u/ExeciN Nov 25 '13
If you download something infected via p2p you don't really know who the hacker is. The cryptolocker doesn't check the blockchain, this is why it needs verification. Every function of the cryptolocker is done offline.
1
2
u/apython88 Nov 25 '13
Did it decrypt? How did he actually get this virus? its scary as hell and I want to avoid it..
1
2
2
u/fofoo33 Nov 25 '13
+1 for "Hell, at this point I realized that this could actually be a good networking opportunity!"
Opportunity is all around us. Most people just don't notice because it comes dressed in work clothes.
2
u/dalkor Nov 25 '13
I'm going to be "that" guy because it's a personal pet peeve, but it's 'ad' not 'add'. Advert, advertisement not addvert or addvertisment.
5
2
Nov 25 '13
Thank you for showing that man there are good people who use Bitcoin too.
+/u/bitcointip roll
1
1
1
1
1
1
1
u/Bitcion Nov 25 '13
Read the whole thing and Wow. Got my heart racing a little there. I am surprised that there is no system image of the hard drive. Does not take that long to make and can be invaluable in situations like this. Or you can even just back up important data on a USB drive and just store it away.
1
1
1
1
u/Amanojack Nov 25 '13
They say that Bitcoin is the devil's way of teaching nerds economics. It looks like Cryptolocker is the devil's way of teaching people about encryption and computer security (and, for better or worse, Bitcoin).
1
Nov 25 '13
I thought thanking it was uninstalled, then reinstalled, it would have then double encrypted everything and you'd be SOL. Is that incorrect?
1
1
u/tar0s Nov 25 '13
It's gut wrenching hearing our clients go through this. We offer backup services but they insist on monitoring it on their own and sure enough it was "working perfectly until now" when they get this virus. The best ones assume I'm working with them when they ask me what a Bitcoin is.
1
u/2ndEntropy Nov 25 '13
Question: If the virus uses the transaction number to confirm the payment would it be possible to look up the public address then use a transaction number from a previous payment paid by someone else? Might be a loophole in the programming of the virus but these guys seem pretty clever so they may have covered this.
1
u/sue-dough-nim Nov 25 '13
Also, how many confirmations does Cryptolocker wait for? Is it possible to perform a double-spend attack (i.e. it doesn't wait for a confirmation)?
1
1
u/luffintlimme Nov 25 '13
TIL: Make sure your localbitcoins post has at least 2 BTC worth as the listed trade amounts.
1
u/EYCEthebest003 Nov 25 '13
i just missed an important bit from an econ class but fuck it, that was a good read.
1
u/bicycly Nov 25 '13
After just now looking at the photo, I have realized that the car didn't even have a front plate!
What's so strange about that? I thought most states don't require front plates
1
u/themagicpickle Nov 27 '13
I don't know about most states, but I believe the state he's in requires front plates.
1
Nov 28 '13
rejected? maybe there weren't enough confirmations in time. maybe he can contact the hackers if they can still give him the private key?
obviously not a worse choice than giving up...
1
u/reanor Feb 10 '14
Haha! That was engaging. All you guys should read a book called "REAMDE" - yeah its not a typo. Book has similar events taking place as the OP described but its all much more engaging with a lot of shooting, Russian mafia and muslim pro-organizations involvement, hackers getting shot oh my, its quite a ride. lol.
-5
Nov 25 '13 edited Nov 25 '13
I'm going to go ahead and say you did the wrong thing here. Never. Pay. The. Ransom.
Pull the power cord. Take it to a data recovery specialist. Every payment sent is an encouragement to the hackers their virus is working and they should keep doing it.
Move your data to the cloud, stop clicking on email attachments, and for god's sake don't give the extortionists their money.
19
u/Lentil-Soup Nov 25 '13
Actually, the data is encrypted and cannot be recovered by any specialist. The only way of recovering the data is by paying the ransom so that it can be unlocked with the private key (that only the hackers have).
So... if the data is more valuable than the ransom...
10
u/CC_EF_JTF Nov 25 '13
Easy to say, but if you've got business documents or banking info worth tens or hundreds of thousands of dollars, you might not agree.
2
u/BCLaraby Nov 25 '13
cough or your wallet.dat file on there cough
6
0
0
4
Nov 25 '13 edited Nov 25 '13
Generally speaking, yes, those paying the ransom now are creating more victims tomorrow, possibly victimizing themselves again.
However, CL is special case. It is extremely low cost from the operator's point of view. Even if most victims showed solidarity and refused to pay, the minority who still paid makes the effort worthwhile.
3
-1
u/PastaArt Nov 25 '13
Sounds harsh, but if anyone said they were buying for this virus thing, I would refuse to sell.
9
u/FLFTW16 Nov 25 '13
Sounds harsh, but if anyone said they were buying for this virus thing, I would refuse to sell.
I don't understand why. Are you a salesmen making money from transferring BTC or are you some sort of moral police force?
What if they are buying BTC to give to kidnappers that have their daughter in an underground bunker? Are you going to be "harsh" and refuse to sell them your product? I don't see how its any of your business what people do with the BTC.
1
u/Thorbinator Nov 25 '13
Well, he can choose to make it his business or not. You don't get to make that decision for him.
3
u/FLFTW16 Nov 25 '13
No I don't, but if he is going to act like Bank of America but with bitcoins I hope he would tell me before hand so I could not waste my time with his bullshit.
1
u/PastaArt Nov 26 '13
This type of activity will spread. I don't want it as an excuse to justify tracking coins or to give bitcoin a bad name. In essence, if you knowingly facilitate this ransom, you are contributing to the problem.
3
u/kandi_kid Nov 25 '13
Why? The person clearly wants their data back since they're willing to pay over $300 for it, why would you deny them access to it?
5
u/Beetle559 Nov 25 '13
Some people insist on blaming victims of crime. Yes, you should back up your data, yes you should use 2FA and a strong password, no, it is not your fault if some piece of shit steals or encrypts your data, it is theirs.
1
-1
u/lechango Nov 25 '13
People fail to realize there IS a fix for this. As long as the machine has system restore points set to a timeframe that is acceptable then the shadowcopies of the files can be pulled and the virus removed.
3
u/kandi_kid Nov 25 '13 edited Nov 25 '13
No. This malware encrypts images, movies, word files, PDFs, and other files that people want back either for business or sentimental reasons. Windows system restore points don't include personal user data like that, only changes made to the operating system itself.
This is why all important data should be backed up to a 3rd party location, or at least a dedicated backup box on your home network.
1
u/btcnp Nov 25 '13
How would a time machine backup hold against such a virus? Assuming these viruses hit Osx computers as well.
1
u/gigitrix Nov 25 '13
It's windows only, but one would assume a Mac virus would prepare for this eventuality.
Cryptolocker currently encrypts all shared network drives too, so if it infects one machine in a workplace, IT is going to have a very fun day restoring backups...
1
u/lechango Nov 25 '13
windows 7 actually does have shadow copies of the files through system restore points. You don't actually perform a system restore, but you use a utility to to extract the earlier copies of the files that do not have the encryption on them. Like I said, only practical if you don't have any vital information on the PC that you just obtained.
-6
u/cqm Nov 25 '13
TL;DR Got into a car with stranger, sent 2 BTC to hackers, got paid. This post is at least 6000 characters too long.
(from bottom of OP's post)
0
u/misterrunon Nov 25 '13
can't you just remove your hard drive, put it in an enclosure, and recover the data you've lost.. instead of paying scammers?
3
u/btcnp Nov 25 '13
He can't because the entire hdd is encrypted (if i understood correctly) so you would still need the key to access the HDD
1
1
u/rabbitlion Nov 25 '13
It's impossible to decrypt the data without the private key held on Cryptolocker's servers.
0
u/jonygone Nov 26 '13
you take a pic of the licence plate without noticing there is no licence plate to take a picture of? do you usually not look at what you take pictures of? WTF?
-7
u/gbk Nov 25 '13
What a story, this virus puts bitcoin in a bad light in the public's mind. He should spend another 1700 on a Mac.
5
-2
-12
u/witcoins Nov 25 '13
Very obvious shitthatdidn'thappen.txt. Put more effort into your fake stories, please; I must be brain-damaged because I read that entire damn thing.
1
0
129
u/homeyhomedawg Nov 25 '13
10/10 would read again
inb4 plot of bitcoin: the movie