Bangladesh Bank exposed to hackers by cheap switches, no firewall
reuters.com
reuters.com
Security comes in layers, and L2 networking is one of those layers. But blaming this on switches is like blaming a home invasion on your fence because someone jumped over it and walked into your open door.
We use this kind of signaling a lot: I work in IT, and we regularly perform entry-audits for new SMB customers. We use phrases like in the article to illustrate the competence level of the client: "the desktops are still on XP", "their network is a single /16", "they have Sweex switches", "the main equipment room is shared with the janitor". That doesn't necessarily mean that there's nothing else wrong at the client, and there may even be a good reason for that particular situation -- but between engineers, it still provides a good indication of what the client environment is like.
More on topic, I have to ask: doesn't SWIFT (which is a global organization specifically for interbank communication) have security baselines for connected banks to meet? Don't they perform physical audits before connecting a new bank to their network, and recurring audits thereafter? How on earth can there be "a handful of central banks in developing countries that [are] equally insecure", yet still connected to SWIFT?
They're banks FCOL, operational security should be their core business. It's not like they can't afford it, just one less Bentley for the CEO.
I witnessed the meltdown of a privately held global business that had us redesign and rebuild their corporate network during an expansion.
The week I was on site at their HQ they hired 400 new people, so it's safe to say they were expanding quickly. At the time they had a global network of satellite connections that routed back to corporate for Internet access. Before we arrived, each location had access to one another, to every device at corporate, and to their other u.s. based sites that connected via mpls. The network had a bunch of residential grade Linksys routers hooked up as switches and AP's throughout their building, and oh so much bad wiring that we were pulling hundreds of pounds out a day... We spent over 100 hours just plugging everything in and removing the residential equipment. We put in VLAN's isolated by a firewall and acl's for important devices, enabled a proxy for some of their global Internet access, and a bunch of other things to increase redundancy.
We followed up a few times and aided them in configurations, assuming things were going well. A year after our last chat they called us up in a panic! They had a crypto locker variant crawling along their global network locking up all their data. ALL OF THEIR DATA!
Basically, they told us they couldn't figure out how to manage the network we built and the owners didn't want to pay us to do it. They decided they would rip out all the equipment they bought and paid for plus paid us to configure and they put everything back on one network with residential gear.
They then decided they would share the important files off each hard drive across the network with everyone because it took too much time to configure security and they thought that since they had mcafee they were safe.
No backups. No disaster recovery.
They fired the poor i.t. director that day. They filed for bankruptcy protection that month. Last I checked the owners formed a new entity and somehow retained one of the products they sold out of the proceeding company. They are a much smaller company now.
Anyway. If you see any Linksys routers in production within a business you know what's up. You should expect this.
Even that wouldn't necessarily prevent a compromise but it would have been a helluva lot harder with little (relative) effort.
This may be partially explained by a brain drain effect where everyone who really knows what they're doing on a *nix platform leaves the country to work for $70,000+ USD/year somewhere outside of PK/IN/BD. Those who are left are very far from the best network security, network engineering or sysadmin talents.
Arguably, nobody with a brain would still be living in a failed state that is a sponsor of global terror.
And does anyone have an I.P. address to another Bangladesh bank with $10 routers and stuff on SWIFT network? Just so I can try to SMTP a warning to that address to help them avoid being hit, too.
I was thinking about having multiple layers (security loves onions!) with interchangeably components that you roll over at random. That way any given attack vector at one point might be mitigated by a different interface below it. Literally unplugging and plugging things in to shake things up.
This can be done on the protocol level, or wrapping the protocol with a secure shell like SSL/TLS, or wrapping everything with an encrypted VPN tunnel like IPSec.
WHO has a list of essential medicines for all countries. Maybe we should have a list of essential technologies for all organizations.
http://www.who.int/medicines/publications/essentialmedicines...
Then again, I guess I shouldn't be surprised at the lack of shared responsibility. This is banking, after all.