University pays $20,000 to ransomware hackers
bbc.co.uk
bbc.co.uk
Here's some major disadvantages that I can think of:
1. Announces to world that you have poor security/backup practices which encourages more attacks against you
2. Announces to world that making and distributing ransomware is good business which encourages more attacks against everyone
I understand that public institutions needs financial transparency in order to be accountable to the public. But the nature of this isn't any different from, for example, a basement flooded due to poor design and required $20,000 to fix. Someone screwed up, and it cost the university $20,000. Let's just pay the money, fix the problem, and take steps to make sure it doesn't happen again. No need to call up the local paper about it and make it a story.
It's also good that this is coming at a time before the rise of self-driving cars. Because the vast majority of car makers seem to know nothing about security, yet are eagerly jumping head first into always-connected, self-updating and digital-first self-driving cars. I'm guessing people are going to raise hell when ransomware arrives for their cars. And I think the car makers will be "shocked" (shocked, I tell you), that this will be happening, and will say something dumb like "Nobody could have ever predicted this! - it's why we never implemented good security in the first place."
However, because the OS/hardware vendors are only going to be dragged kicking and screaming into implementing stricter security measures, it's going to be a while before stricter security arrives.
In the meantime, beyond alerting criminals that ransomware is big business, it will probably also be used as an excuse to pass more CISA-like surveillance laws (which will do absolutely nothing to stop the rise of ransomware).
It could also be used as yet another excuse to end strong crypto (because obviously ransomware uses crypo). But of course, it's not like the Russian or Chinese criminals doing this are going to care that the US has a ban on strong crypto. So yet again a solution that does nothing to stop the rise of ransomware, but would still make it much worse for all of us, and it could even be a step back in the fight against ransomware.
See, I actually don't think that this will change the level of deployment for ransomware. Ransomware has proven its effectiveness from the very first time it hit the web; it's a low cost high return form of malware due to the nature of its operations. Whereas other forms like scareware and annoying malware can often be dealt with, albeit at the cost of time and sometimes money, ransomware has a very clear and tangible cost to the user: their data. For home users, it's somewhat easier to suggest that while the loss of an entire photo directory is tragic, it's not worth the $400. But when you start getting to actual important data, for example, student records, accounting records, large business projects, asking users to take a stand on principle becomes a lot more difficult, especially since in some cases they have a legal obligation to try to remedy the situation.
Ransomware is a low risk venture for ne'er-do-wells because it's shooting fish in a barrel. Point your spambot at any major institution and you're bound to get a hit on something that has essential data to that institution. Combine this with the fact that even after decades of home computer hard drive failure and nearly a decade of cloud storage being common place, people are still really bad at backing up their important things.
Our reliance on data and our poor (often inability) to mitigate the damage done by dataloss is what will keep ransomware firing, regardless of how many institutions are able to take a public stand against the extortion. The barrier of entry is so low that a failure to collect from victims is virtually meaningless. The attackers are out virtually nothing, and can attack ad-nauseum because they know sooner or later they'll get a hit where the cost of the dataloss far exceeds the cost of the decryption key; and as long as the attackers occasionally make good on the sale of the decryption key, there's always going to be the hope from users that "maybe if we pay we can fix this".
A principled stand isn't what is going to be necessary to fix ransonware; major changes in how the public handles its data and in how OSes work with/detect ransomware is going to have to happen first. Until then, anyone who refuses is pretty much just getting a pyrrhic victory; the attackers might not get their payout, but the cost to the victim is far greater.
An effective thing they could have done is to announce that they paid the ransom, but that the decryption did not work (even though it did).
That has the advantage of discouraging other people from paying up, and therefore reduces the incentive to create more ransomware attacks.
Hell, the government could step in and recruit people and companies to falsely claim that they were ransomware victims who paid up, but never got decryption keys and were screwed over. That could put a damper on ransomware psychology.
Thinking about it further however, this will probably lead to better "customer service" by the ransomware makers. They'll adapt their software to selectively decrypt part of your data for free, so they can offer you proof that that they can and will give your working keys once you pay up.
This actually did happen to me. Paid the money, got the key, couldn't unlock my files. Damn shame.
- how your system got compromised?
- did you have backups? (and did the backups get encrypted?)
- how much did you pay and by what method?
- why do you think the key didn't work?
EDIT: It now occurs to me that you're following my suggestion about falsely claiming to be a ransomware victim to discourage ransom payments. Whoosh!
effective, isn't it!
As for why the U of C admitted it paid the ransom, as well as releasing the cost, Dalgetty said it’s an effort to be transparent. “We’re a public sector organization and we pride ourselves on our openness,” she said. Source: http://calgaryherald.com/news/local-news/university-of-calga...
Personally, I am glad they disclosed it. For example this incident raises the awareness that having a solid backup policy is important. Maybe this very story will help IT staff from other universities convince upper management to invest funds into developing a more solid backup policy.
So the initial point, while it may be true to some extent, is not really the common method of attack; the truth is that for the most part there is no need to really "craft" an attack against most users within a large enough organization. Just compromising one or two accounts or using one of many means to impersonate an official sounding account is often enough to get access to a few in-domain accounts. Once you have that, you can easily get past the majority of people's mistrust and get them to run just about anything you send them. When I did support for a small private university in the US, our GAFE accounts were constantly plagued by phishing and spam emails, and despite our best efforts to educate our user base, people just kept on clicking and giving out information. The entire process was basically automated from the attacker's side, as when we compared notes with other universities suffering the same issue, the emails sent out were verbatim copies, save that the university names were swapped out and a different logo.jpg was added to the emails for authenticity. Attacking a major organization really doesn't require a careful eye and dedication, just changing a few entries in some program and starting the process.
As for why to disclose? There's probably some degree of a necessary public accountability - I actually doubt that the university itself called up a paper and said "man have we got a story for you" so much as someone at the publication got wind of the information and plugged the university for a brief interview. Honestly, reading through the article, it's incredibly terse as far as actual details from the University as to what happened. Since it's a Canadian University, I'm not sure on their responsible disclosure requirements, but if it was in the US, I believe they have a timeframe in which they have to admit that student data has potentially been leaked.
Really, these sorts of impersonal attacks do need a lot more attention, since as recently as just a year ago, I found myself talking with somewhat major institutions around the US who had no real good idea how to deal with ransomware, (spear) phishing emails, and so on within their organization. Creating effective user awareness is really tough, since rather frustratingly, getting "phished" seems to be one of those lessons everyone wants to learn the hard way, or arrogantly thinks will never happen to them. We used a Twitter account in combination with a threat blog to try to notify our users, as well as warnings on our log-in page, but even after doing that for 4ish years we still had people giving out their information, and we had an okay-ish following on both.
I'm not saying that it was "good" of them to release that they decided to pay, but I also do question, given how easy ransomware is to deploy, whether or not more discretion would actually have a larger impact. Schools in particular are kind of over a barrel if/when they get hit by ransomware, and a lot of it has to do with poor data retention practices by both the University IT and by offices across the organization. Often times it's not just a mild inconvenience if someone's computer gets locked up by ransomware, you can potentially be irreparably damaging hundreds or more students' academic careers. Should this data be in a position that it can happen like this? Absolutely not, but that doesn't change the fact that it often is.
By default all applications should be sandboxed. Why should a random application be able to read/write to every user directory? We enforce process separation in memory, we should do the same on disk.
For average joe and jane security is a nuisance.
That is how many of these exploits work, regardless of the OS.
not a bad plan, but also, all data should be backed up. In this 'cloud age' of computing, there's no reason, and no excuse. I certainly don't want to blame the victims of ransomware, but if that data was so important that they paid ransom to get it back, why didn't they back it up ?
Backups have to be coupled with some kind of way of noticing that something is wrong. If the ransomware encrypted your data slowly over the course of months and you didn't notice you might be out of luck regardless of your backup system.
Just for my Windows PC I have three backups. One on the machine, one on an external hard drive and one more in the cloud.
How much did it cost me? $80 for the 2TB hard drive and $8 a month for unlimited cloud storage and backup. A small amount to pay to make sure you're covered in nearly any disaster scenario, including ransomware.
Information security is even listed as one of their main research areas.
http://www.cpsc.ucalgary.ca/cpsc_research
they even have some labs that does infosec
http://icis.cpsc.ucalgary.ca/ http://ispia.cpsc.ucalgary.ca/
I bet the people at the CS dept must be pissed.
BTW, are you implying that a strong CS university can break asymmetric encryption? Why is everybody assuming that hackers are stupid all the time, and only they are smart...
https://github.com/leo-stone/hack-petya
(the hn thread https://news.ycombinator.com/item?id=11474613 )
Wouldn't it be more transparent to just allow their files to be published?
Surely there are damages that could be caused, but as a public institution, I feel like this is the way they should operate by default.
It's immoral to pay criminals.
"Ransomware and crypto malware are rising at an alarming rate and show no signs of stopping," said Raj Samani, European technology head for Intel Security.
That statement instills a confidence in me that makes me so glad Intel bought McAfee six years ago.
FTFY.
The University that this story is about is Canadian.
You must not know much about software development...
Microsoft could do without the overhead, or the headache, and so despite the PR upside it's probably not worth their effort.
Might be an opportunity for an ISV to make a utility though?
That's really something that bothers me with the whole ransomware thing: People seem to be completely ignorant to the fact that by paying they're not only getting back their data - they're paying the bills for the people who will launch more attacks against other people. And thus they're themselve guilty of supporting the same crime that just hit them.
That's why it's termed 'ransom'. Because people who don't pay, have things taken from them. You don't really get to condemn ransom payers on ethical grounds without being an asshole.
Paying a ransom encourages the criminal behaviour; it therefore negatively affects all potential victims by making them more likely to become actual victims.
Also, in some jurisdictions paying a ransom is actually a criminal offence so one could end up causing further negative consequences for your family, friend, colleagues, or the institution you work for.
Knowing that the ransomware folk are just going to keep on spamming their software against institution after institution, is it really worth the potential cost of the lost data? If it's student data, is it worth ruining students' academic careers over a principled stand? Is it worth losing a novel you've been working on for 8+ years? Is it worth losing business documents that could cripple your business?
It's not as clear cut with ransomware as it is with other forms of ransom and extortion just because of how stinking' easy it is to do ransomware.