How to survive a ransomware attack without paying the ransom
bloomberg.com
bloomberg.com
Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service.
I can understand that some parts like "social" stuff might depend on some central service but, hey, something simple like syncing ones excercise achievements between phone and watch? Really? Who has designed that?
I am completely with you conceptually, but from experience I can tell you that even if there is a commercial incentive to allow for local communication it takes a few days to get it working with the cloud and months to do it locally only. And you really need to know what you are doing to make it safe and reliable in all eventualities.
[1]: https://hackaday.com/2017/12/29/34c3-fitbit-sniffing-and-fir...
And we'll, there seem to be ready to use libraries, you can use without signing the NDA: https://github.com/search?q=fit+garmin&type=
I just wanted to point out that since cloud based communication is so easy nowadays, doing sync without cloud support is a significantly larger effort. Not unachievable though.
It was 100% about user expectations, the data was never mined for anything.
People use multiple phones, replace their phone, delete apps to free up space, and still expect their data to be there.
Running a cloud infrastructure for PII isn't exactly low cost, and bundling a life time subscription with a one time device purchase is horrible economics. It isn't done for no reason.
Oh I wasn't implying what's generally seen as "data mining". But for such a company to offer many of the features in the paid services they need that data. They don't have to sell it to others, they only have to sell it back to the users as added services even included in the price of the hardware itself. Those added services can be as simple as sync between multiple phones or sharing on social media, or premium features like advanced analytics.
On the other hand this kind of data can be also sold entirely anonymized. Strava does this and many cities' urban planners buy the data to understand better how the city infrastructure is used by the people (running, cycling, etc.) and how to develop it.
I'm not saying there's no value in it, just that without it the value of the product decreases significantly. So it's in the manufacturer's best interest to have it as part of the basis of their offering.
Another reason is that if you still want to sync with the cloud, you need two synchronisation systems that have to be kept in sync too.
No it isn't. We were doing it for years before "the cloud" or even the modern Internet even existed using Bluetooth, RF, IR, and cables. Have you ever looked at a .fit file on a Garmin watch? It's a binary format, but is straightforward to convert to CSV, and doesn't contain much beyond timestamp, latitude, longitude, altitude, heart rate, cadence, and a few other fields. Calculating distance, duration, training effect, calories burned, etc. is simple summarization and arithmetic, plotting course on a map just requires an offline map and a plotting library. It already does all of this ON THE WATCH itself without needing any connection to anything else, so there's nothing stopping an app from doing the same thing locally on a much more powerful iPhone or Android phone. The Garmin cloud is only inserted in the process here so they can monetize your data.
Using a third party transfer app. and then viewing it with another third party app, directly on my phone. no battery complaints, but those ANT transfers were pretty flakey.
I dont think you can browse files on the watch through bluetooth, but an OTG cable would do the trick.
> make it safe and reliable in all eventualities
You mean precisely like it isn't now?
I'd much rather have something fail locally based on conditions that I can affect, than fail remotely and be completely out of my control.
Even if that were true (and it's not), it's not how Garmin sync works. The website isn't cloud based middleware, and the watch and phone sync over bluetooth. It really is as dumb and frustrating as the OP describes.
Before syncing with the watch, over bluetooth, the app connects to the Garmin website. If the web connection fails then the transfer fails.
Leslie Lamport
You really wonder that? I'm sorry, how stupid are you? It's obviously to harvest data and control users. We've been warning and educating people about this for decades. When are you guys starting to wake up and voting with your wallet? Open services! Open software! Open formats! Own your data! Own your devices! Your life will be full of such disruptions if you keep using products that let corporations dominate you.
Unfortunately, a much stronger tone is often needed in order to to get people to pay attention.
No one likes to admit that they screwed up, though -- and we all know that the truth can hurt sometimes.
---
Unfortunately, you were (likely) downvoted mostly because your blunt, honest statement comes across as condescending and rude: "Maybe you're right, but you didn't have to be such an asshole about it."
What those people are either not realizing or conveniently choosing to forget is that, just as you said, we've all been warned about this exact thing* for decades! Apparently, though, the message isn't geting through. When that happens, this type of "tone" becomes necessary in order to get people to pay attention.
Unfortunately, most will still choose not to heed the warnings. Evntually, when it (inevitably) happens to them, they'll say something like "Meanwhile ... users (like me) are wondering how it is that [this could happen]" and, of course, they'll avoid admitting any responsibility for their choices. They would much rather play the part of "completely innocent victim who could never have imagined something like this might happen".
---
It reminds me a lot of a small child that is told, repeatedly, "don't do 'X' because 'Y' will happen" and, later, is absolutely SHOCKED when they "learn" -- the hard way, typically -- that, when they do 'X', 'Y' happens.
If a child learns the hard way that X -> Y I don't berate them and call them stupid for not listening. It doesn't make them more likely to listen the next time. Same with adults, really.
For a different industry, is there an open source e-reader I can support instead of Amazon/kobo/nook?
Maybe I'm stupid as you say, but I genuinely don't know if these things are out there and a quick Google search didn't turn up anything I'd call usable.
Hardware cycling computers, like the Garmin 830 or Wahoo Elemnt Roam, are physical hardware designed for the use case of being strapped to handlebars and being used in a wide range of environments. The battery life and performance is tuned towards always on GPS and Bluetooth for connecting to sensors. They utilize a wider range of GNSS constellations. They have physical buttons as touchscreens don't work well when wet. The screens are designed to be visible in sunlight.
Like the GP, I'm not aware of any open hardware cycling computers.
https://www.goldencheetah.org/
Among others reads .fit data directly from Garmin.
Some solution where I can track my runs, swims, cyclings, treks just like Strava (et al) does does but I can choose to keep the data wherever I wish - local, or sync to an app on computer or to a self hosted server.
Maybe not Garmin but I would love to use such an iOS Strava alternative with similar accuracy and detail.
[1] https://runalyze.com/ [2] https://github.com/Runalyze/Runalyze/
Just imagine how much more $$ one can elicit in an acquisition if potential buyers may add tolls to an already established and well-traveled gate.
Fortunately the watch appears as a usb device when connecting with a charging cable. So it is possible to get data out without relying on accounts and social features.
To puff and look important and to say: –
"Though we know we should defeat you,
we have not the time to meet you.
We will therefore pay you cash to go away."
And that is called paying the Dane-geld;
But we've proved it again and again,
That if once you have paid him the Dane-geld
You never get rid of the Dane.
http://www.kiplingsociety.co.uk/poems_danegeld.htm
parenthetically, this is equally true of toddler-geld.
There doesn't seem to be conventional wisdom about how to build systems that are easy to restore. How do you optimize for recovery after an attack? How do you ensure that you've eliminated all the backdoors?
My guess is a combination of "continuous restoration", version controlled code, and a complete separation of code from data.
I want to read books about this but they don't seem to exist.
- Toni Morrison
If you can take all your hosts down and bring them all back up quickly, that gives you at least one tool for disrupting the attackers.
Decentralization is the key. Microservices, or segregated services, stateless (as much as possible), and perhaps even partitioning groups of users into totally separated instances. One group gets attacked and service only goes out for the 1000 users in the group. Of course, infrastructure costs would go up but maybe not that much (since you need less resources for 1000 users than 100,000). This is relatively easy to build from scratch these days thanks to various IaaS providers and DevOps tools (obviously hard for established companies with legacy tech).
Then, keep employee computers totally separate from production servers. Let employees back them up themselves, especially since so much can just be stored in the cloud (I'll get there next). Forget about VPNs where everyone can talk to everyone else. Don't try to save money by hosting your own Jira and Bitbucket instances. Pay extra for Atlassian to host for you, then let them deal with security (actually it's cheaper from what I remember). Companies already pay for Office 365 and don't self-host that. Don't host your own email servers. Just focus on the core of what the company needs to do and that's it.
This way you spread your attack surface across a whole bunch of services that are better than you at security, and you get the benefit of not having to deal with other issues. If Atlassian or Cloudflare goes down, no big deal; they'll fix it. And all your other stuff still works.
My point is that it's not the only consideration.
The malware needs to execute itself on each computer. But I would think this would be thwarted by hardware firewalls as well as apps like Windows Firewall.
If my PC at work gets infected, somehow it can magically infect the guy down the hall's PC too? I thought that was made impossible years ago.
Extreme example: you can think of an air gap as a "firewall" with all deny rules. Air gaps are pretty secure. (Yes, there are still way's in but finding them will be many orders of magnitude harder than finding a 0day in a "next-gen" firewall).
Another example: I put all printers in a dedicated VLAN and block all traffic in and out except specific print ports from the print server IP only. In practice, way more secure than any "next-gen" firewall will ever be.
Endpoints like PCs and servers check in with domain controllers at recurring intervals, so even if all endpoints are behind firewalls and can’t talk to one another, they still reach out to domain controllers periodically to pull down configuration updates and so forth.
Firewalls do absolutely nothing once someone got your weakest link to click something and go to town.
From my last penn test it goes, phish, get a click and execute or credentials, use a hack like getting legacy NetBIOS exploit to give up hashes for all your users, crack the hashes and hope someone used a short 12 char password or something dictionary-easy like “Wr3st1ing1!”, then leverage that access again and again until you have a printer that someone gave domain admin access to because it was easier than setting correct policies, an admin actual, a service not account that has good AD privileges, etc. Then start pushing software as admin.
Most of the time it’s not even this complicated.
The only thing that “saves” you from paying the ransom is good backups. But if a group is fairly competent, they’ll encrypt your backups too. So it needs to be offline.
I don’t have much love for Barracuda Backup, but for very little money you get nightly offsite backups that might just save your cyber insurance or company itself from having to pay.
Well, fw would be effective if organizations used network segmentation effectively, but of course close to no one does that in practice (e.g. usually IT/support have access to everything).
This is the part I’ve never understood. Surely you should be backing up in an append only fashion initiated from the backup server?
My best guess is that this gets managed from AD as well, so they find it and take over?
Related - see how many examples of S3 policies split access into read and write rather than read, append, write. It doesn't even matter where the logic lives - only whether the storage service allows you to delete anything.
The trick is to get another S3 account (or any large storage really), to download everything from that bucket periodically. The "replication" needs read-only access to the first bucket. The second account doesn't need to be accessed by anything or anybody so it is relatively safe.
The key idea is assuming everything is compromised. Whether you use append or whatever, is not helpful if the functionality to change that configuration exists, because that gets changed, backup server is gone, backup storage is gone, etc.
You have to design a system where even a rogue IT admin with full access to everything can’t screw you. Usually that involves third parties where there is no mechanism for a rogue IT person or other attacker to delete your offline backups. So some people have Iron Mountain pick up disks in a lock box daily, or use an online backup service that specifically has features for this, where they keep extra copies of your backups completely offline and provide no mechanism for the customer to delete them.
OK, brilliant — this is a nice articulation of a fundamental principle.
Do you know of any books that describe how to design such systems?
Guaranteeing that offline backups exist is a great start, but if the backups contain backdoors, restoring could be extremely laborious and yet unsuccessful.
I do wonder if some of my misunderstanding is because my experience is mostly SaaS companies, so paying external providers is more “natural” vs a company that makes its money selling units.
Disaster recovery can be quick if you can restore hundreds of virtual servers (and you're going to have hundreds), whole key machines, and all the user and network config from backup. If all you have is data files and bare hardware, then the business is going to have a lot of expensive downtime while you rebuild all the infrastructure. "cattle not pets" approach and automated provisioning of machines from config files helps in this regard, but almost no company has that for all their critical infrastructure, especially if we're talking about non-IT companies whose critical infrastructure is not some single consumer-facing app (e.g. Twitter), but a diverse, distributed collection of third-party IT solutions for various business-critical needs.
It is quite challenging to recover from this kind of breach since the attackers had every opportunity to touch every system connected to the AD and leave backdoors behind. I have seen companies trashing their whole AD, re-imaging all machines and basically starting from scratch at great cost.
(They might still have to reimage all their machines but at least they still have a list of employees and customers)
It may also have been a matter of servers getting infected, infecting hosted files in shares, and client machines open the files to get infected.
Or, as another user points out, domain controllers can readily do this.
https://www.bleepingcomputer.com/news/security/evil-corp-blo...
> The initial compromise of an organization involves the SocGholish framework, which is delivered to the victim in a zipped file via compromised legitimate websites.
> The zipped file contains malicious JavaScript, masquerading as a browser update.
So are people just like "this random website is trying to download a browser update, ok I'll unzip it and run it, even though I never normally have to do this". Seems plausible.
Then:
> Privilege escalation was performed using a publicly documented technique [there's a link] involving the Software Licensing User Interface tool (slui.exe), a Windows command line utility that is responsible for activating and updating the Windows operating system.
> The attackers used the Windows Management Instrumentation Command Line Utility (wmic.exe) to execute commands on remote computers, such as adding a new user or executing additional downloaded PowerShell scripts.
It's not really clear to me how local privilege escalation allows you to execute commands on remote computers though.
If it's a privileged user, then you can move to many more workstations, if it's a non-privileged user then you may be able to use their normal access (email, network shares, access to internal applications) to try and trip some privileged user into compromising their workstation in a way that you could not from the outside. Or you can wait a month until some tech support person logs in to that workstation and you can steal their credentials.
In the case discussed in this article, attackers took three months between the initial compromise and the ransomware attack. One can do a lot in that time.
Some leverage known exploits against elements like LSASS, so if the person infected has credentials for another computer, why not slurp up all the credential tokens on remote computers that you can log into too.
If you use Linux/Unix on the other hand, you can do descent things to contain access. Firstly, elevated management accounts can restrict login sources, either by ssh authorized_keys or deny rules in sshd_config. Secondly, and very importantly, you can contain what applications can access through SELinux.
Running Windows these days is like walking around with "Kick me" hung around your neck.
As far as I am aware, the last time there was an actual exploit in LSASS was in Windows XP.
https://www.wired.com/story/new-mac-ransomware-thiefquest-ev...
But still, a lot less of these stories than for Windows.
Perhaps there's some issue with what you mean by "pure ransomware" - if you mean automatically spreading worms, then those aren't that relevant, prominent examples like Petya was four years ago; NotPetya was not ransomware but a destructive weapon, etc. In the current environment, and also in the attack described in this article, a "ransomware attack" means a takeover of your systems by a ransomware crew of hackers manually working on your specific network. They generally start with a spearphishing which targets Windows desktop machines because usually the easiest way to target Linux servers is through client-side attacks, obtaining user credentials and a foothold inside the network that helps with firewall restrictions.
Yes but those are somewhat human errors; my point is more along the lines that linux might be the primary target for the entire attack, but it always starts with attacks on Windows. I was looking for a case, specifically with ransomware, that started with Linux/Mac OS X instead of Windows.
In my opinion (and to be honest, PCI DSS actually enforces this some extend) it should not be possible to gather linux credentials from singular hacked machines. If you hack my system, you will not be able to login to our prod linux machines; you will need my hardware device to generate OTPs. This is what we actually do for a living, but it is rather weird that people don't just have google-authenticator as standard for lack of a hardware token; then your private key would still not get the hackers anywhere. Use hardware tokens + non-windows then basically none of these attacks would work.
document.querySelector('.paywall-inline-tout').remove();
document.querySelectorAll('p').forEach(e => e.style.display='');Many companies just get by, rather than doing serious security design. How do you change that culture in a company? Will paying the ransom do that? Probably if it only costs $1M to do. If it costs them $100M to do, would they do it?
I don’t know how much data Garmin has company wide. But it’s a lot different for me to consider offline backups as a simple service than a company this size and complexity.
There is complexity, yes, but it's mostly a solved problem.
Disclaimer: I work for one.
I think the people who are the worst off have petabytes of business critical customer data, but don't do massive datamining projects on top of this. Then you end up with a data center that is 90% (business critical) prod, and triplicating that becomes much more relatively expensive than having a data center that is 20% prod.
"Three weeks after the attack, Hydro had a total of four functioning PCs in all of the U.S."
You should expect that any backup of systems (instead of backups of 100% pure data) will contain backdoors, that any weird systems (routers, printers, phone centrals) may be compromised even if they seem fine, and that the credentials of all the employees and any private keys/certificates have been exfiltrated, so they need to be changed.
So, yes, while you’re technically correct that 100% inert and uncorrupted data files are safe, you have to prove that those files are not corrupted. And, so many data formats either are code or contain embedded code, so these need to be treated as suspect until proven otherwise, as well.
You could restore a dump of pure structured data to a known clean system and that would be safe - but once you include arbitrary files as you describe, no way. Embedding malware in some periodically-accessed document on a public file share is a reasonable persistance mechanism for an attacker.
There's no reason for the secretary's computer to be able to connect to the onsite SQL server... unless she uses an application that uses that SQL server.
The same is true for most things. Problems are often well known, solutions are often understood, but doing things is where the actual work is.
Also replace your IT security provider and/or person.
And even if most data were backed up, most computers still have to be wiped and reinstalled. I don't think most companies backup the entire disks off all employees, it's normally just a dedicated file area. So while the data can be restored, the IT department still have to set up hundreds of computers for all kinds of different workers or machines on the spot.
Nothing is ever easy, don't be so dismissive about things you haven't thought through.
- It should be easy to reinstall to a known good image with all the relevant software, settings, drivers, etc. then restore the backed up data. This is relatively common in corps.
- Once you observe the malware and know how it reaches the C&C server, you can push rules blocking that host or block the bad binary network-wide.
Of course there will be companies that didn't have good enough system in place and once exploited are doomed.
It should be, but enterprise servers are often the embodiment of configuration drift.
Even if they could comfortably restore a backup from a year prior, they are left with hackers who know how to penetrate their network until they determine how it occurred..
It's the fault of companies for never upgrading their machines, giving full administrators access to every employee and using Admin123 as the domain administrator password account.
If we believe the article, the virus came from an attachment in an email to a random employee. Why are executable attachments not blocked? Why is an executable running as an unprivileged user able to storm through every computer in the company?
> Why are executable attachments not blocked?
Because there are dozens of weird Windows extension types that execute automatically on Windows, though yeah the attachment should have been blocked and a customer service machine should have a whitelist of programs that need to run (or only run signed ones)