Baltimore Blew Off Ransomware Demand Only to Find Data Had Never Been Backed Up
techdirt.com
techdirt.com
"Given the fact that $6 million has already been pulled from parks and public utilities funds to "harden" city systems, the $76,000 demand now seems like a bargain."
That doesn't seem fair at all. They'd still have to harden everything and it would still likely cost millions. From the looks of it they'd at least have their stuff back, probably, but they'd still need to put all the same time/money/work in, wouldn't they?
Secondly, Later on in the article is the more relevant
>The city figures it will cost $18 million to recover from a rejected $76,000 ransom demand. I guess if you're going to play chicken with extortionists, you might want to make sure your backup plans at least meet min spec.
Either way, it's a terrible article and I'm on the fence about flagging it.
https://www.bleepingcomputer.com/news/security/a-closer-look...
>>The person in charge of the city's systems was Frank Johnson, who went on leave (presumably permanently) after a post-attack audit found the IT director hadn't done much IT directing.
Even knowing that paying the ransom is no _guarantee_ you actually recover, and that you have to then harden your system anyway after that (which you should have been doing all along)... I tend to agree.
I am a Baltimore resident, and I've also had that opinion since the day after the ransomware attack was announced -- just pay the ransom. (In part because from what I experience of Baltimore City government, i was pretty sure the backups and recovery/continuity plans were going to be basically nonexistent).
But on previous HN threads, it was a very unpopular opinion, in the articles right after the attacks were announced, very few in the comments threads seemed to think it was acceptable or a good idea to pay the ransom.
I'm curious if that remains true?
If it was discovered that the backups were faulty (as in this case), or if it were not possible to discover how the infection happened prior to the ransom deadline, I would have advised paying the ransom, since 76k is a relatively small amount to the city of Baltimore. (And then of course continuing to investigate and harden to avoid having to do so again.)
1/ You have to trust the criminals are "good" people and actually took the time to write code to decrypt the data.
2/ Paying the ransom paints you an easy target for the next exploit.
It might paint you as an easy target, but that's why you increase your defenses. Basically, I'd rather roll the dice and see if the paltry sum gets me a fully working environment why I try to plan next steps.
It's complicated, like any scenario where there is individual benefit but social harm (with healthy mixes of fault and incompetence too). It's so obvious sometimes it can get lost, but the people behind the ransomware are criminals. Ransom paid to them is money that is in fact directly going to supporting criminals, the government and in turn taxpayers aiding them. At "best" they're very pure single type cybercriminals and it "merely" supports them in pushing more ransomware. More often criminals are into a diverse set of activities, ranging from other varieties of cybercrime to being part of a real world physical syndicate, in which case some of the ransom is going to an organization that does stuff like murder/assault/human trafficking/drugs/etc. The strong reactions against just paying the ransom, even if it's cheaper and a clear winner from the individual first order perspective of Baltimore City, stem from this and that hasn't changed. Even if it costs $18 million vs $76k, that is still $0 directly going to the criminals themselves. On some real level, if Baltimore just paid the ransom they would be attacking the rest of us for their own benefit following their own fuckup.
Sometimes there might be other mitigating factors in the intensity of people's reactions, but most of them don't apply here. This wasn't an innocent or complex mistake, it was utter, mind blowing incompetence at the most basic level. It wasn't a matter of economics either, or technological sophistication. They'd be immensely better off if they'd merely aimed at any basic network share and cycled a few USB hard drives into a safe deposit box twice a month. That'd still be embarrassingly primitive and ineffective by any remotely modern standard for any significant organizational entity, yet it'd be something. And since it's a democratically elected government entity the complaints about it falling on citizens fall a bit flat too, because citizens have a duty to be checking on their government in a democracy. And this has been a lesson that has helped push things forward elsewhere at long last, so some good came from it that wouldn't have if the ransom had been paid.
So basically yes, it remains true for a lot of us.
The only way not-paying the ransom is beneficial (aside from having proper backup systems in place obviously) is if there was a large public sentiment shift promoting NOT paying ransoms. If society at large came together and decided the majority of entities are NOT going to pay, then ransomware viruses would be less profitable and thus not as favorable projects for hackers/scammers.
But that would take a lot of effort, organization, and favorable circumstances to have everyone do that simultaneously going forward. And there would be casualties at the beginning before the public sentiment cemented itself in the collective conscious.
But yeah, the only way ransomware will stop is if it stops becoming profitable: which means companies either need to have proper OpSec and backups (so they have no need of paying), or collectively agree that no one will pay ransomware attacks.
Seems like a pipe dream that we'd ever get to that point though. So I imagine companies will continue to fork over the ransoms.
Edit: this got me thinking, say for example, the US government outlawed paying the ransom to hackers. And they could somehow enforce this law effectively. Wouldn't that pretty much stop ransomware attacks in the US? or where ever a law like that could be effectively enforced?
Society also seems to have come together and decided we'd rather save money than spend it on effective backups and security.
Honestly lack of back ups is unacceptable. I can accept it if its a young start up handling some basic data and passing payments to an established business. However, any SE, DBA, IT director/admin with some experience should know about backups and push management for them. If management fails to pay for cost of backups, that individual should note it(preferably with a paper trail) and bring it up when shit hits the fan.
I will write SQL statements prone to injection, I will hack things together when I have to due to circumstances but I inform management of risks and they make the decision to proceed in a certain way knowing the risk. If they try to light my ass on fire 2 years from now, I will open the email and say "told you so". I have actually done that multiple times already and never got burned.
Baltimore is basically a 'failed state' of municipal government.
While you can "blame the voters", being one myself I literally don't understand what the fuck is going on or what to do about it, even when we elect people who seem like they might do something different, it remains the same.
So... if individual people working in IT protected their own asses by documenting that someone told them to do the wrong thing... that's great for them, what it does for Baltimore is _nothing_. The IT director lost his job (probably? Maybe? So far just on unpaid leave?), which he thoroughly deserves, but that ALSO does nothing for Baltimore, cause people like this keep getting replaced, and it still doesn't get better.
Anyway, this actually doesn't have much to do with ransomware in general, but yeah.
I’ve only helped recover from ransomware once about 2 years ago. When we ran the decryption program provided after paying it decrypted ~97% of the data. Some files were just permanently corrupted. Windows Server with ECC memory fwiw.
Fun note but the owner wanted to reboot after decryption and I yelled “No!” across the room, wanting to clone the known good data first. Good thing too, a reboot started the encryption all over again… good times.
I heard they were hit again but took my advice and setup Backblaze.
Also, regarding backups... at least 3 physical devices and at least two distinct geographic locations. Have backup systems push to a drop location (temporary), where a pull system can then pull those backups to a separate location. This provides a separation between your internal systems and backup systems. Otherwise, in situations like this, the backups could have been compromised as well.
Aside: this is a perfect example of why government agencies should have policies in place for disclosure of security breaches after 60 days or so. This allows them a window to exploit as needed, while still preventing catastrophe in the case of too many previously unknown exploits going into the wild in a breach. While I'd prefer everything just responsibly disclosed to affected software, I understand that cyber warfare in state actors is a thing.
Would be great if every organization conducted targeted attacks in order to probe the reliability of their assumed safeguards. If your system hasn't been tested by someone who has a real incentive to break it, you have no idea if it is really as secure as you think it is.
Another important thing is fine granular permissions on network shares.
Internal politics are always an issue of course, especially at schools where a handful of luddite teachers / administrators can kill good idea, but that's also an issue of IT leadership too.
I was glad to move away from those products.
Since you seem to know all kinds of facts that discredit the school district, the superintendent, and the IT supervisor, yet "didn't stick around" to absorb info that might look bad for the group of employees, makes you a narrator who is difficult to believe is being objective and non-biased.
Several companies have gone out of business this year due to getting their servers wiped by an attacker. Their backups were on live servers as well.
I only provide that context because I've been as far away from that experience as I can possibly put myself and I can only hope it's gotten a lot better.
Prior to me and during the time that I managed backups, the statement "if you don't have backups at all, you don't have backups" was true for the entire backup set probably about once a week[0]. Those miserable robotic devices would crush tapes, the drives would eat tapes or otherwise fail, the backup servers would be over-whelmed (despite being nearly the largest hosts we had), the software would crash (Backup Exec), the server would just be ... skipped? And the tapes had a lifetime that was 1/10th what was advertised (and 1/2 what we had planned on[1]).
Our process included a monthly restore test of a few critical pieces of infrastructure and a rotating list of other hosts. I think the one time that we passed might have been worthy of opening a bottle of wine. Most of the time we could get enough data back that the restore wouldn't result in more than a rounding-error financial loss, but for the most part our server team spent a lot of time praying.
That system gave me nightmares for years after I left that position.
[0] It was so bad that our initial plan was to backup DC A using DC B and vice versa, but we opted to backup both from both data-centers (one of our requirements was off-site backups).
[1] I think I read the headline to an article a month ago about why "tape is still king" in backups. I couldn't bring myself to click-in. I assume things have gotten better, but if they're still selling this product the way they did back then, I'd want real-world numbers on MTBF and the like.
Systems push to drop location. Backup services pull from drop location(s). Redundant storage, etc. I don't trust "disposable" media at all anymore, and limited trust for hard storage (hdd/ssd/etc).
To me, if it's not on at least 3 devices at at least 2 locations, it's not properly backed up.
OK, so I know how to test — manually — that a few randomly chosen files are correctly backed up in my backup systems.
But what if there are larger classes of systemic error in the process I haven't thought of testing? What if some particular file type or directory tree has vanished from the backups, but since it isn't in my manual testing process, I never catch it? Are there best practices for validating that whole directory trees are correctly backed up across the board? Or any form of automated testing for backups (but, presumably, separate from the software that does the backup process)?
Plus, you'll have solid data integrity instead of relying on buggy firmware in your RAID controller.
Also, redundancy and snapshots are not a backup.
This helped us with several problems:
Backup system didn't record the permissions.
Backup didn't get 'resource forks' or 'alternate data streams'
Backup wasn't complete enough to satisfy copy protection for software that was no longer supported.
Backup process didn't see deep into the folder because there was a hardlink/symlink loop that caused it to stop
Backup didn't get a coherent copy of a bunch of files that was acting like a database
Drive had a CRC error that let it keep running but stopped the backup system from reading the file
Windows program stored vale in the case of the file name while the Unix backup command assumed it could squish the Windows files to lowercase.
They had a backup script on their server that was written some time in the 90's by the looks of it. Used ye old `cpio` command to write to a tape drive; someone's job was to manually go and eject the tape every morning and replace it.
For verification, the script simply checked the exit status of the cpio command, and if it returned 0, it wrote "BACKUP STATUS: SUCCESSFUL"-- or 'BACKUP STATUS: BAD" if non-zero--to a log and sent an email.
At some point we had to try to restore something, and spent several hours trying to figure out why their backup tape was empty. Some quick digging into the script discovered that the command would indeed write some kind of tarball to the backup tape, it was just zero bytes.
IIRC, I eventually traced it to some problem with the cpio command erroring out if it tried to copy a file larger than 4GB. Suffice to say, the client was a little shaken that they had gone god-knows-how-many-months without an actual backup.
I'd argue that isn't true. Ransomware is a form of terror in the form of "losing everything". And that threat of impending loss combined with 'backups are hard wahhhh' and the fact that no Corp I know backs up user machines...
As a numbers game, it pays. Well. And even if it didn't, some still hack for the "lulz".
Most of the orgs I've worked at (for at least the last decade) map the local profile to a network share, which is definitely backed up. The only things not backed up would be saved outside that folder structure, but the organizations have always been clear about that.
Even if you criminalize paying you'll still have a tiny portion that do.
https://www.fbi.gov/news/stories/ransomware-abettor-sentence...
I've seen many PC-raid hardware solutions that simply didn't work. A drive fails, and the machine becomes unusable, fail to recover when a good drive is inserted, or crashes/hangs and the data is lost.
Yet people keep buying raid solutions for PCs. I recommend: pull a drive from your raid hardware and see what happens. If you're afraid to do that, then you need a different solution.
If you don't have the same confidence in your systems you need to fix that.
The next morning he got a fedex from netapp... a replacement drive.
I once took over management of a startup that was just acquired (this was back in 1999). The people there never did backups. Ever. They told me with a straight face: "We have a RAID. It doesn't need to be backed up."
it's somewhat attractive price wise simply because it's a very affordable urban east coast city. there's a vibrant/edgy art scene (to include drama, etc.) that's attractive to younger artists, sort of like what detroit is going through (as i understand it)
https://statescoop.com/4th-cio-leaves-baltimore-within-five-...
It is a corrupt town the facts/history clearly show this. It's where I was grew up/live/work; all within in surrounding counties, which is solid living! Though Baltimore isn't the only corrupt US city!
CIO for an acutely underfunded department in large but very poor city is not an easy job.
Try as I might, I would never be able to come up with something like this, even if you held a gun to my head. There surely must be a small industry of HR consultants who specialize in writing this kind of drivel
Taking a career-ending bullet like this is Part of what these c-level people sign up for, an occupational hazard, especially In Baltimore
It could have been some trigger-happy accountant just tallying up stuff left and right.
Some organizations need a disaster to provoke change. Hopefully, they'll do the right thing now and transition to something that works.
love this writing man :) :)
Dont know why would a city's chief digital officer go backup free?!!! even at worst , backblaze would have helped :|
Most end users looking for "ransomware protection" probably just want to drag and drop some files, like Dropbox, which is why a simple SFTP (filezilla) solution is nice, but of course you could point any old thing[2] if you were more sophisticated ...
[1] https://www.rsync.net/products/ransomware.html
[2] borg, restic, rclone, git-annex ... rsync ...
Whatever works for you.
The second call back is always more expensive for them, but sometimes someone needs to touch the stove themselves to see it’s hot.
If you genuinely can’t afford it, I’ll help for free, but there’s only so much time in the day and I won’t eat the cost of stupid or politics.
Also aren't their some pretty tough mandates like x% of companies must be minority owned etc. I imagine it allows those companies to charge extortionist rates because they hit the relevant quotas and nobody else does.
Is there any chance that something like this might be done for IT? Or is it all too young to be done sensibly?
We did wait for a fire to create building codes, it just was a long time before either of us were born: https://en.m.wikipedia.org/wiki/Triangle_Shirtwaist_Factory_...
There was certainly plenty of fires before that but this one was terrible enough to cause a public outcry.
An individual city council is not free to learn the lessons again the hard way, no matter how tight the budget and how close the elections. Either it meets the code, or it gets closed down.
> Also aren't their some pretty tough mandates like x% of companies must be minority owned etc. I imagine it allows those companies to charge extortionist rates because they hit the relevant quotas and nobody else does.
One thing I saw was that the big players will have employees who fit the desired characteristics, and they just spin those employees off into their own corporation as needed.
According to an ancient Chinese parable, a lord once asked his physician – whose two brothers were also healers – which of the three was the most skilled. This doctor was renowned for his expertise and ability in healing throughout China, and he replied, “My eldest brother sees the spirit of sickness and removes it before it takes shape, so his name does not get out of the house. My elder brother cures sickness when it is still extremely minute, so his name does not get out of the neighborhood. As for me, I puncture veins, prescribe potions and massage skin, so my name gets out and is heard among the lords.
Knowing exactly how to fix a problem, having the skills to do so, and being absolutely forbidden from actually doing it.
This sounds like one of those "opportunities".
All that said, laments about "how do we fix government X" will never be solved if we deem the cost of entry too high to even attempt to fix it ourselves. Obviously this is all in addition to and outside of any democratic process that would lead to reform of how these positions were managed, performed, etc.
It's actually not something that would be my first choice, but I do personally know people who have been harmed by incompetent/apathetic IT leadership in local governments. It angers me enough that I would consider a career change.
I got the impression they were a group of people that broadly understood their problems and were finding it very difficult to steer the city towards good solutions.
Although Mr. Johnson was the City's Director of IT, realistically he had very nominal oversight over many of the city's actual IT departments - which were spread across a series of departments with their own employees, budgets, and resources. This was something he had been actively trying to improve but with limited progress.
I don't know what the best solution is - their hiring process is flawed and it's difficult to remove or replace problem employees. The budget is about 60% of what it probably needs to be and there's no path towards improving it.
The hardest thing for me to do was convince anyone to get me money. They STILL have servers running that were purchased in 2007-2008. (I moved all critical services off, and made damn sure backups worked). It took two years before I was able to convince the board to give me $5000 for server hardware alone. That went towards the most needed hardware too, not my wish list.
This was before I was able to get things set up so I was able to buy something under $500 without board approval, just needed IT Committee approval. The board required everyone in the county to go through the IT Committee for any purchase related to IT. Printer ink, a $10 wireless mouse, etc. That was the first thing I got rid of while I was there. They only reason they did that was because it gave them power over people. I've seen them turn down people over $15 purchases...
The other person who replied is pretty correct about politics. The board there HATED tech for no reason other than if you weren't in the "old boys club" you were garbage to them and they treated you like that.
So overall, it really gave me a great view on why so many counties are so dysfunctional and why government works so slow (for most things at least). I don't regret my time there, but I wish it didn't take such a toll on me.
/Edit Also, there's no reason that they couldn't have tested backups. I was the only IT person for a county of 350+ PCs and a hospital, and I still managed to test backups every month. Shadow Copies saved me so much time too. I also used linux /pfSense when applicable.
Municipal government doesn't have a sustainable funding model for things like IT unless they are really small or really big. In my city (~100k people), they have 3 guys and a couple of freelancers that work <100 hours a year. The staff make like $40-55k/year.
Really? I'll never forget the description given to me by a close friend who had left a "Government IT" job for the private sector: (1) You have standards and practices like everywhere, but forget one and you're explaining yourself to a judge instead of a boss and (2) there's never enough money for doing all of the things required to meet regulations let alone make things better which is why you'll see silly things you haven't seen on banking websites in a decade still prominent as "security features" on state treasury websites.
I found the story about "important data on a desktop drive", and the shock it caused, surprising. Maybe my past life (a decade ago in infrastructure) was unique, but I specifically recall an incident where I was called down to make an old IBM NetVista (mind you, Lenovo had owned that line for a while at this point) boot up[0]. I noticed some numbers on a printed label and a boot error about the CMOS battery, realized it was drive telemetry, realized that nobody who was looking at the problem had ever heard of plugging in those values (or probably had touched an IDE controller -- server guys -- and it was ancient technology).
The rest of the story I might not have completely correct as parts of it are assembled third-hand, but this desktop was located in our data center, hooked up to a modem (2400bps) and it handled submitting charges to another carrier to the tune of "a few layoffs" for every week it wasn't functional.
How does this happen? Well, the company went bankrupt and emerged, then was purchased by another company. During that time, a large part of our operations was moved from one state to another, hardware and all (but mostly not the people). This predates all of that, of course. At some point, a NetVista was put in place to test setting up an automated process for billing this carrier -- something carrier imposed (must have been one of the big guys). The developer who set up the test system was successful ... on his final week of work before being laid off. A few months later, the carrier continued working the migration plan and switched things over, and after a short delay, accounting rang the alarm bells. A busy developer stepped in, found the offending system was connected to test and re-configured it to point to prod. Everyone went on their day. And hey, when desktop migrated everyone to Windows XP, they put UPSes at every desk so it literally ran in a cubicle until the Data Center migration (where it failed the first time and the label was printed). Rather than figuring out what, on earth, it would take to fix it, they put it on a shelf and plugged it into the UPS in the rack until I was called several years later.
[0] I was one of two people who were called when everything else was tried. This sort of incident happened to me in very similar ways at least 4 times (once with an old Thinkpad Laptop).
The same kind of people that would say no to a pocket change ransom, are the same kind of people that would use taxpayer money to not just do a poor job, but to not do it at all!
The kind of people whose shit don't stink.
There is one exception: if the ransom is paid in such a way that the FBI (or equivalent) can track where the money goes and thus arrest the criminals.
Also $76,000 is oddly low... like low enough to be the price of a well established firm to do a pen test on your network...
Had the city engaged in the pentest, would there have been an appetite to spend 10-20x that amount on remediation?