Hacker News new | ask | show | jobs
by lbwtaylor 1315 days ago
> $5 wrench attack, here's my real password: take the 50 millions. Oops. Decoy.

I don't understand how this defeats the wrench attack.

Presumably you aren't released until the actual tokens are in hand, so decoys just make the attacker angrier.

1 comments

"You can beat me all day, but it's impossible for me to fulfill your demands, you'd also need to beat these other four people, and they're located all over the globe."

Someone might be quite happy to engage squads in lots of countries to kidnap and beat everyone if the payout is billions of dollars, but it's a very different problem and e.g. the Bahamas government or some local thug won't be able to do it. I have no idea how large a cartel would need to be to have reliable operatives on the ground in lots of countries, and I'd assume if you're part of a group holding the keys to those amounts of cash, you're going into lockdown when two of your associates suddenly vanish.

Sounds like an operational Challenge but with billions on the line people will consider it.

Perhaps one or two if the multisig holders are already on board and will "reassure" the others that everything is fine.

Or one government (like the US) coordinates with others to get it done.

Sure, but that's a tall order. The US cooperating with e.g. China, Russia and the EU to get everyone? Or the US running covert ops in China, Russia and the EU to take the money themselves? Both are a very different situation than the US simply sending a cop to some address and asking the person living there to please come with them to the station.

For criminals, it'll also be a huge operation, and it'll come with insane publicity which criminals typically don't like. Who's powerful enough and willing to potentially burn their existence in entire countries for such a payout, when they make billions a year?

There might be a sweet spot where the payoff is large but the notority is low (think about one criminal organization going after the other).

Unless there are street fights, people will not care that much.

Or perhaps political opponents in unstable countries.

On the government side the USs reach is far and criminals are not always willing (or able) to go beyond it. Maybe coordinating with China won't happen, but let's say Japan, mexico and 2 EU countries is not out of the ordinary.

There are busts happening almost every year on that scale