US travel firm $4.5M ransom negotiation open chat
twitter.com
twitter.com
While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly.
I don’t support these attacks and some of the targets in particular are insidious, like hospitals where an attack could lead to an actual death toll, but it might actually be the kick in the ass many organizations need to actually care.
It’s sad that it’s come to this point but the end result may be better for everyone.
It's not absolutely guaranteed that your warehouse is going to catch on fire, or that some guys are going to back up a box truck and clean out your valuable inventory at 3am, but there is a high likelihood of it occurring.
Obviously if there are unknown vulnerabilities that is one thing, but there is a level of due diligence you should practice as the operator.
I believe that some laws requiring notification to customers in case of a data breach would already cover this. However, from another article I found this statement from CWT:
"While the investigation is at an early stage, we have no indication that personally identifiable information/customer and traveller information has been compromised."
That appears to be a complete lie based on the chat transcripts, and if so I hope CWT is punished legally for it.
Edit: also, I don't think that making getting hacked more onerous while keeping software developers completely legally immune from liability for the software getting hacked would be politically sustainable either...
It already is a felony to pay ransomware attackers in the US, depending on who attacked you.
Many of the principal ransomware gangs are listed as OFAC [1] restricted entities. If you pay them, even indirectly, you are as criminally culpable as if you sent sponsor dollars to ISIS or another terrorist or organized crime entity.
Garmin’s execs are in for a big surprise when the Treasury agents come to visit.
[1]: https://en.wikipedia.org/wiki/Office_of_Foreign_Assets_Contr...
It may also lead to companies paying for a more aggressive response. Uber has been known to deal with fraud by eventually finding the fraudster, even in Nigeria, and having them "visited".[1]
[1] "Super Pumped: The Battle for Uber" Isaac, (2009)
And just to clarify for others, "extralegal" isn't necessarily bad, and does not mean illegal. It simply means not regulated by the law one way or the other. Calling a Nigerian lawyer and having them talk to someone is definitely not illegal.
Finding the eBook on Amazon then quote-Googling for verbatim sections of text doesn't always work, but there are sometimes nice exceptions :)
For anyone who wants to save 5 minutes, data:text/plain;base64,R29vZ2xlICJpc2FhYzIwMTkucGRmIiA8LS0gaW5jbHVkaW5nIHF1b3Rlcw
Meanwhile in the real world, a company I develop for implemented the most draconian security measures to "prevent ransomware".
Development environment is a virtual machine at the other end of the world, with disabled copy-pasting from and to the local system. A complete separation between safe internal network and unsafe development environment. No copy pasting from and to email, etc. Horrible environment to work in.
The security policy was draconian to the extent I’m sure it was well intentioned but led you to do things in the least secure way possible as it was the only way to complete a contract.
I.e the servers on the other end running Windows 7 (in late 2019) where so old they didn’t have the required cpu instruction set to run some required software. Likewise input lag was extremely noticeable to the point you hit a key, wait one second then press again thinking something went wrong only to have to press delete some seconds later.
How did I deliver that project? Developed on my own local machine, emailed the artifact to the cooperate email address obfuscated, log in to the corporate laptop, then Citrix, ssh the artifact up to the cloud ec2 servers.
That’s another one. The cloud ec2 servers. No public outbound internet, no internal trusted repositories. What was the accepted way of setting up the servers? Going to random internet sites, downloading random binaries to your Citrix account, scp’ing then to the servers. Trying to explain how stupid this is gets no where in organisations with thousands of people. When you mention trusted artifact repositories, immutable / reproducible builds, deployment pipelines the answer was we don’t have this as they didn’t meet security guidelines.
This was a tier 1 bank. Experience is the bigger the company the worse things are due to the size and different teams/departments being so disconnected.
When we little employees roll our eyes and say "this doesn't make sense," we're telling ourselves a comforting lie because the situation you describe DOES make sense- from the organizational perspective.
Management did everything their rules allow to make the computing environment safe, but you, the individual, hacked an unsafe circumvention into the workflow by finagling some personal website and using SCP. I bet none of that process is documented- and if it is, whoever made that documentation is now the responsible party and fall guy.
The setup you describe sounds less like draconian security and more like a half baked solution that confused usability hurdles for security. Just because security usually brings lower usability, it was probably (wrongly!) assumed that lowering usability will bring security.
The bank was using remote desktops over Citrix from HP workstations (thin clients). It worked really really well, including copy/paste.
If not for the initial login and citrix log, I don't think it would be possible for a developer to figure out he is working on a remote desktop.
1) App whitelisting. This is not the strongest mitigation (attackers with exploits can move in memory), but it stops drive-bys and 99% of malware, plus it massively reduces noise on the network.
2) Reduce lateral movement. If the attacker accesses an employee laptop, encrypts it, but can't move to other devices, that's not a very compelling ransom.
You don't known Carbon Black is there until something doesn't work. That "not working" propagates an alert up to the security team.
a) You just kill ~85% of malware (rough estimate, probably technically higher, but I'm basing that on stats around interpreter-based/LOLBAS malware). Anything that isn't targeted is probably dead in the water.
b) You know exactly what's running on everyone's computers, more or less, so you have a way easier time baselining and building monitoring.
It's honestly easy-mode for security. But it's hard to roll out to a company a decade after it's been running, so you really need to do it early on. And most orgs don't care about security until after a breach, at which point they're too large and slow to get something like that done.
I'm interested in learning how to do this right, because I've only ever seen it done wrong. How do you streamline the process for getting programs approved? How do you accommodate developers who need to generate and run code?
Yeah, absolutely. But I consider this to be, when done right, a good thing. A single security team is going to drown trying to scale your company's security asymmetrically with your company's growth. For every 1000 developers you might have 5-50 security engineers depending on how serious the company is about it. Spreading out security work across the company scales extremely well.
Of course, you want to minimize burden too.
There are a number of ways you can go. Personally, at my company, we're so small that it's trivial. We rarely onboard new employees and pretty much all approvals are handled within a few minutes of the employee getting their laptop.
As you scale it may make more sense to crowdsource this. 'Upvote' is one such tool. https://github.com/google/upvote
Upvote-like systems basically give you reputation based approvals. If you can convince a number of your coworkers that the app is worth installing, you can install it. I've seen a number of systems built this way that combine crowdsourced approvals with other forms of reputation.
At my company we use Chromebooks. Apps/Extensions are only allowed once approved. The Linux environment is where development happens.
This is nice because there's a strong separation between environments. That said, we don't do any sort of application whitelisting in the Linux environment today, due to a lack of tooling support.
If we did, what I'd like to do is just have simple rules like "If the binary was created by gcc etc allow it to execute". Santa allows for process-tree based rules like this.
Another option is developer VMs like in EC2. These can be nice for devs because they're often much more powerful than a laptop anyways. It requires a bit of tooling to work smoothly though with local IDEs and whatnot.
The app whitelist impairs my efficiency, and honestly takes a fair amount of fun out of work. I can no longer use many of the tools that help me, and instead am confined into the corporate-approved structure. This is both a productivity issue and a job satisfaction issue.
Trying to separate our development workstations, and dev environment overall, from the rest of the sordid mess, is extraordinarily difficult. We're trying to do similar what you recommend, with developer VMs running in our internal ESX cluster. However, that technology conflicts with Microsoft's Hyper-V (we're a MS shop). We're trying to get to Docker/k8s, but we can't run Docker inside a VM that runs in ESX. So we're trying to offload the actual execution of the system, even for local testing, into DevSpaces. But there's a lot to figure out, and DevSpaces is a young product. Further, private AKS environments are a new thing in Azure, and we've a couple of times now run into roadblocks with MS's own growing pains.
Your "upvote" system seems to have merit, but with, I dunno, 50 or 60 devs, spread across several teams focused on different tech, it doesn't seem like it would scale well. Coming up with the right mix of apps, and convincing our Risk team, is very difficult. Especially when so much of their pushback seems confusing (like, DBeaver was denied as a FOSS product, but approved when we paid for the Enterprise version).
Out of curiosity, like what?
> Trying to separate
Yeah, like I said, starting early is going to make things much easier. If you're trying to get to this place later on, it's just wayyyyyy harder and most orgs can't get there. This is often the case with security - if you build your code, infra, policy, etc, with security in mind from day 1 it's 1000s of times simpler than doing it even just a few years later.
> Coming up with the right mix of apps, and convincing our Risk team, is very difficult.
Oh yeah, a risk team can be the real killer. That's why upvote is nice - security only gets involved if something is flagged. But if your risk team isn't willing to work with you that's a problem, and it sounds like yours isn't doing the work consistently.
To me, approval should be easy. Even if a malicious app is approved that's often still a huge win - the attacker can't use many of the tools and techniques they're used to. Obviously you want to avoid that compromise too, but it isn't the whole entire goal.
We whitelist some vendors entirely. Our app whitelist request form is:
* What risks are there with this extension/ app?
* Is there another approved app that can do this, and if so, why do we need this one?
* How will this app help you? What is it for?
That first question is really important because people usually have a decent understanding of what the app should/ shouldn't be doing, or if the risk should be trivial. It's all about spreading the assessment out.
98% of the time this will be triggered by an admin performing a task that just happens to touch that resource, but it is incredibly helpful the other 2% of the time.
They didn't object to the idea insomuch as they had somehow convinced themselves that they needed some kind of security specific product. We were never able to tease the shape or color beyond a silver bullet.
When basic business continuity planning with simple tools that companies should have anyway for a dozen reasons still aren't deployed, I'm pessimistic that this phenomenon is going away anytime soon.
You make a lot of good points, but I am afraid that when such organizations start caring the cure will be worse than the disease. Some of this already leads to either draconian security policies (that make development hard but do not improve ransomware security by much) or passing the risk on someone else, for example by buying a security policy (which increases costs, but seldom improves security). Similar to most restrictions introduced "because pornography" or "because terrorism" those are likely to be mostly a drag on society.
We might eventually get to better security practices: general policies that are easy to implement and not onerous to comply with and flexible exceptions, where the damage is small and relaxing a policy leads to other improvements, but this state seems very far away. My 2c.
* US$1.5 billion in revenue * 18k employees
For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure).
It's insane that this is the case and that companies are willing & able to pay ransoms like this, but the hackers were right - the payment is much less than lost business, bad PR, etc. if the actual information had leaked. Such is where we are.
I wouldn't be surprised if they genuinely would have trouble coughing up 10 million two days after the attack hit.
If I had to guess based on the figure, I would guess gross but I'm not sure.
Almost all money going out of a business can be deducted from money coming for purposes of counting taxable profit. I'm having a hard time thinking of one that isn't.
It's seldom used and only when there's no alternative (e.g. a lost invoice that you don't want to charge your employee for).
Yet, regardless of how much you pay Bill, his wages are tax-deductible.
The only way to mitigate this risk is actually walk the walk (implement appropriate security controls).
The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claiming billions for nonexistent PPE.
As a member of society, I don’t care if I’m paying a professional ransomware group, or a professional corruption gang.
That argument could be used to justify any theft or even kidnapping.
I know many people who grew up in countries where kidnapping was a very real concern. Consequently, they had to adopt "greater security practices" and it had a very real, negative effect on their lives.
There are real harms to randomware. Companies go out of business, people lose their jobs, people lose their service providers, etc.
To say, "it serves them right for not following proper security" literally can be said for a mom/pop business in a poor neighborhood who didn't have bulletproof glass or bars on their windows. It is negating the fact that (a) the harms are very real and (b) security costs money and resources, which is effectively another tax on their business.
If instead the government made it illegal to pay such ransoms and actively audited large BTC transactions and charged people accordingly, then we could get rid of the incentives to do this in the first place.
The government should similarly hold firms accountable when they are hacked (due to the harms on consumers) and require prompt disclosure of any hacks.
There are ways to incentivize the preferred outcomes without supporting the active theft of property and destruction of someone's business.
I get where you're coming from but you can't really just flat out say "you can justify kidnapping with the same logic". Like, no, you can't. Fully agreed the government should be the ones playing the role of incentivizing security, but you can't then go back and say that security takes time and money those companies should not have to spend. They should, regardless of who keeps them accountable for it...
What should the govt so when govt agencies get hacked?
And does anyone really believe the hackers deleted the data off their own servers? They can easily double-dip by selling that information. It's valuable, so why would they delete it?
But then again, this makes the barrier to entry even higher for newcomers and gives an unfair advantage to the entrenched players. Tragedy of the commons?
The kidnapping analogy makes for a better understanding of why paying ransoms is bad for everybody else. If kidnappers know, or really just think, that they’ll get paid, they’re more likely to kidnap and hold hostages.
It’s not that companies are not solely responsible for their own lax security policies. It’s that incentivizing the exploiting of them is bad for society.
I don't think it does. It puts a much more tangible value on security, which encourages businesses to do a risk analysis like 'Do we spend $1m on security every year, or accept that there's a 0.xxx probability of a $4.5m ransom every n years?' That cost base analysis is often used to reduce the value of things that aren't obvious profit centers.
I see your point but this is flat-out organized crime, extortion to be precise. How long will it be before we're all making protection payments to ransomware groups?
> What makes crime "organised"?
Your answer is:
> Organized crime has a specific meaning
Well... what is it?
When I was (a lot) younger, I had a pet theory that the anti-virus companies were making the viruses and that it was a sort of protection racket.
If they were to start a consultancy, even if they are as skilled as anyone else, they’d have an uphill battle from the get go; and have to either stick to their home market, or heavily discount their services. Either way making less than from their ransomware.
If your backup process "isn't that simple", then you should make it that simple. Otherwise failure looms.
Particularly this conversation: https://news.ycombinator.com/item?id=23951941
If you live in the third world, that immediately puts you on the radar of corrupt government officials and organized criminal organizations that want to extort you.
The ransomware gig allows you to stay small and keep a low profile. Nobody has to know that you are raking in the cash until you pack up your family and book it to Tahiti.
> With their current approach they will almost certainly get traced eventually and end up in jail.
Prison in a first world country is a lot better than getting executed, watching your family get executed, or getting kidnapped and forced into slave labor for the local mafia boss.
Depends. If they are a couple guys (or a single guy), and it's a one shot for him, he has very good odds of getting away with it. Cleanly launder his BTC and then move somewhere not suspicious and keep a low profile. At the end of the day, $4m is not that much money (ie: not able to afford multiple Ferraris).
Could governments outlaw these ransom payments?
You'd likely still see US companies pay the ransom anyway, but just try to keep it secret. Probably less risky than losing their crucial data and systems.
Perhaps the key to ending ransomware is some high profile attacks (real or fictional) where the victim pays but does not get their data back.
https://www.reuters.com/article/us-cyber-cwt-ransom/payment-...
a balance of 16m and over 1.4 trillon usd has passed through this account.
the oldest transaction i could find was 2019-11-02 14:19: https://www.blockchain.com/btc/address/17A16QmavnUfCW11DAApi...
https://github.com/lukabuz/BlockView
It didn't really lead anywhere substantial, but it was interesting to see how many addresses got involved after the depth of the tree exceeded 4.
As another commenter pointed out, some of these addresses have obscene amounts of money going through them. Really makes you think about the scale of these tumblers. 1NDyJtNTjmwk5xPNhjgAMu4HDHigtobu1s is an example, with about $108,081,555,724 having gone through it, and a current balance of $51,644,803
$4 million once times the risk of getting hit vs. the up-front and ongoing costs of dealing with an overly paranoid IT guy.
Tough call.
The security recommendations they put forward at the end are significantly better than anything I can ever get backing to implement.
This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing.
We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity.
Instead democratizing currency, we're democratizing large scale crime. Previously only large organized crime organizations could perform such an attack. Now, almost anyone can.
I still don’t understand - how is Bitcoin difficult to trace when there is a global immutable public record of all transactions?
On the other hand, the Feds arrested a kid in Florida, so my question is... how did they find him?
If I had to guess, the attack was done by a group of people and they split the funds up. Some of them were smarter than others.
It's also possible that the people who have been arrested are simply people who have received stolen goods (knowingly or unknownly). Perhaps they traded something else of value for the Bitcoin and didn't know how dirty it was.
Then bragged about it and went for more accounts. His friends left him when he went for the high profile accounts. I think it was organized on discord.
Can you not track all Bitcoins going in and out of a mixer?
This is an oversimplification, but it should give you a rough idea of how difficult it is to trace Bitcoin.
Granted, this is all theoretical. In practice, it’s not unusual for such people to make mistakes that reveal their identity; however, there’s nothing inherent to Bitcoin that ensures they can be de-anonymized.
Usually they attempt to go after hosting providers, but when the services are only accessible by Tor and they’re using bulletproof hosting—hosting providers who do their best to avoid law enforcement—that’s no easy feat. It’s not impossible, but it can be both a technical and diplomatic nightmare.
You'd be surprised. The feds have very advanced taint analysis if they have reason to go after you.
If the mixer has a lot of users, at best you could determine that the your target is among the entire set of people who used the mixer this hour/day. Although if the mixer was compromised, you’d have everything. That does seem like a substantial risk. It’s kind of like deciding to trust your vpn. You could mitigate that risk by using multiple mixers.
Perhaps they might do this if the saw keeping the entire 4m as much more lucrative than many years of taking the percentage skimmed off the top from a number of smaller transactions, and just going into "retirement".
Why would the mixer need to reuse addresses when you could create a brand new one each time.
There's also Zcash, which applies similar logic to all shielded transactions.
It's just a ledger kept outside so there is no link between the money going in and the money coming out.
The 4.5m would have to be mixed immediately so the original wallet can no longer be an event source.
Is that the right idea?
And dividing it up between as many possible independently run tumblers/mixers.
I'm sure some additional smurfing techniques could come into play for additional obfuscation.
An order of magnitude of more drugs are sold on Cash App and Venmo -- which is why they're in rap songs. As for large scale hacking, extortion and ransom, yes bitcoin is used but it is increasing difficult to cash out in a large way.
It is actually difficult to cash out?
Unless you're best friends with an oligarch, and if that's the case, you can always get Deutsche Bank to do it for you.
But its not? You can convert 50 million usd worth of bitcoin in one order without moving the market more than 1-1.5% and have a wire transfer to your bank account same day. This happens all day every day, with the markets getting deeper year by year.
Trash exchanges for retail have nothing to do with the infrastructure actually out there. If you are moving anything over 4 figures you shouldn't be trying to use retail exchanges. They're trash, slower, randomly flag stuff, and have higher fees.
its been like this for half of bitcoin's existence
they consider themselves distinct from exchanges because they do not take custody of people's funds, in their opinion
Almost all illegal bitcoin stolen by hackers and ransomware is cashed out in countries with limited or no AML/KYC.
the recent price spike, as all other price spikes are the result of some (probably) nefarious activity that pumps real dollars in and out of the bitcoin platform.
>This kind of attack would be almost impossible in the pre-bitcoin era.... Instead democratizing currency, we're democratizing large scale crime.
Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current implementations.
A ban would do serious harm to 2, 3 and 4. If no one could pay legitimately and it would become (ever more) difficult to launder, the ransomware demands would die. The first (connectivity) could be impacted as well. What would happen when traffic shaping makes sync take longer and when every LN transaction risks losing money due to disconnections?
Banning banks from doing business with bitcoin exchanges is not banning bitcoin. Banning use of bitcoin entirely is legally plausible, but technically impossible to implement without draconian internet censorship on the scale of China. It's a 100x harder to ban bitcoin than, say, bittorrent, and banning that in a free society ended up not being possible.
If we can disrupt the network so that even criminals can't get ordinary people to 'pay' via the network, than it's for all practical purposes a ban.
I don't agree that banning it is harder than bittorrent. It's dramatically easier. Bittorrent doesn't have global state, so there's no one place to strike. The entire Bitcoin network depends on global consensus, and therefore there is one place to strike. If it is weakened so that it shrinks enough (how many miners will want to mine for an illegal activity?), than 50%+1 attack will be trivial for a state actor.
1. Bitcoin transactions don’t require access to the internet at the time the transaction takes place. There have been solutions for performing offline transactions, though none have really taken off. Nevertheless, it’s not hard to do, though it’s riskier for the recipient than an online transaction. I won’t go into the technical details, but it’s nothing fancy. The idea is that you can place money in any number of accounts ahead of time, then simply pay people by handing them the keys to those accounts. There’s little overhead for creating new accounts; often merchants will use a fresh account for every transaction. Of course, the recipient has to be able to trust that they’re actually receiving keys to an account with the right amount of currency, which is a harder problem to solve.
2. This isn’t necessary. Bitcoin was popular in certain criminal communities long before there was any easy way to convert between Bitcoin and fiat. Cashing out dirty Bitcoin to USD remains risky.
3. The UX is already terrible. The UX that criminals experience isn’t the same UX that investors experience. They can’t use services like Coinbase to cash out.
4. Prior to Bitcoin going mainstream, the cover was that you could exchange your Bitcoin for various illegal products and services. (Want to buy a stolen car?) When there’s a whole underground economy whose participants are thoroughly convinced they are outside the reach of the law, any currency will work, as long as there’s a consensus within that community.
Banning cryptocurrency would have some interesting effects, but it would be nearly impossible to enforce, and it wouldn’t have the impact you’re seeking.
This would turn a 'trustless blockchain' to a 'non-blockchain relying on trust'. Assuming this transition can even be done (what would be the point of cryptocurrency in that case?), the result would be like the known hawala networks, which at least do not enable so much criminal activity and have some decent uses.
2,4. Bitcoin had an aura around it. Something experimental not really concerned with money or big crime, maybe a way to buy light drugs. Later on as a magnet for speculation. Remove the official cover, and laundering would become way more difficult.
3. There's terrible UX, and there's 'terrible horrible UX when one could easily lose money because the ISP closes your lightening connection'.
So I think this is possible to enforce, not completely, but there's no need for 100% enforcement to have a positive effect.
You can create the transaction object and hand that over. Transferrable literally as a file.
Instead of having over notes with the private key on them.
Eventually that transaction will need to be settled onchain. This can work in a world without a familiar looking ubiquitous internet. Regional internet cafes or even radio stations can settle signed transactions. People can have stocks of transactions and they just go to the cafe to settle those and also get their updated balance.
This capability always undermines a "ban crypto" thesis, or even a "crypto doesn't survive the apocalypse when the power goes out" thesis. It is merely a concept, just like computers communicating to each other is a replicable concept even if the head of state has an internet kill switch.
Anyway, we don't need a 100% effective ban to get an effect. A 90% ban may well be good enough for any practical purpose. Your example is a good one - sure, there are ways to get around 'internet kill switches' several countries have, but in practice these (unfortunately) work.
The fact that some people in a cafe can get one cryptocurrency transfer going is no defeat for a ban, so long as the ban is effective enough to reach its intended effects (e.g. making ransomware useless).
but the utility stays the same at $2.50 or $25,000 (offline-for-most, stateless monetary system with managed/predictable supply)
the same utility is inherited by most of other blockchain technologies
How would this be done? It only takes a single node capable of connecting to both networks to keep the whole thing working. There are already many nodes working with satellite connections so I'm pretty sure this can't be done even by state actors.
Most of these countries barely have a stable internet connection or even stable electrical power, so I wouldn't surprised if these 'currencies' aren't so helpful in practice.
* Note that use by corrupt politicians to launder their ill-gotten gains is not a positive.
Yes, bitcoin can play a role but it's not like you're paying for your groceries in bitcoin. Cash under the mattress > blockchain
Perhaps these ransomware attacks are the market's way of making things... more fair.
Security improvements seem to be driven more by regulation (GDPR), competition (when did ElasticSearch release TLS support for free? Not after the Nth open ES cluster - only after Amazon competed with them), and large costs (switching to Linux servers because they're cheaper. Though there are concerns about current security practices there too...).
The biggest issue I have with cryptocurrency is that it’s an utter waste of resources. It incentivizes the consumption of electricity (and talent) purely to print money, rather than to produce value. Yes, currencies provide some value to society, but we already have more sustainable options.
I see the appeal if you hate taxes and regulations or live under a particularly oppressive regime. However, given that it relies, to some extent, on public infrastructure like internet and electricity that governments can outright shut off if they so desire, there are better options. Raw materials and bartering work pretty well. Just don’t invest in tulips.
In practice, though, it's not clear what exactly are the capabilities of each branch of law enforcement.
But, supposedly, putting a non-zero value in the "illegal income" field of the 1040 (which ISN'T fraud) both (1) can't be used as evidence against you in court, and (2) isn't reported by default to the IRS to the FBI or other law enforcement agencies, so you don't end up on any watch lists.
Of course you gotta take their word for part (2), but it is their incentive to get every tax dollar regardless of source.
That'd be the sort of counter-productive legislation we see too often. The only result would be to push this underground and to keep authorities in the dark. It might end up helping criminals.
A similar case has been made about corruption: If you're asked for a bribe by, say, a corrupt official you usually have no choice but to pay and once you have paid you are in it with them, both criminals, so no-one talks.
You may be able to clearly document the attempted bribery, and report it to the relevant authority—which may be a central agency of some form, or may be just going up the chain within the same organisation. Success will vary by country, authority and magnitude of offence. But even threatening to do this (politely) normally achieves the desired result, though it does nothing to actually uproot the corruption.
Alternatively, just indicate clearly that you’re not willing to play along with this illegal behaviour.
The zero rupee note (https://en.wikipedia.org/wiki/Zero_rupee_note) is a fairly successful example of doing this, and bear in mind that India corruption problem is much larger than any western country’s—although it’s illegal, it’s still par for the course in a great many areas. Yet standing up to this bribery is quite possible if only you have any inclination to do so.
I am currently in India, residing with another Australian who has lived in India for forty-odd years and operated business locally, and bribes were solicited from time to time, but he would not play ball, typically by either pretend nothing had happened (that is, ignoring any “hints” that you could pay for such-and-such) or by actively declining. Flunkies that try to take bribes personally are generally quite ready to backtrack once they see which way the wind is blowing (they could get in trouble with their boss), and more institutional bribery can generally be waited out, at the least. Even if it’s occasionally a long wait (like, months instead of days, or years instead of weeks).
A large part of the fight on these sorts of issues is changing cultural norms. Consider seatbelts over time in Australia (and much of the world): fifty years ago seatbelts were uncommon, but legislation was paired with a big marketing push to normalise wearing seatbelts had the effect that before terribly long society would look down with severe displeasure on anyone that didn’t wear a seatbelt while driving, so that now most people (well over 99% of the driving population, at a guess) wouldn’t dream of driving without wearing a seatbelt. The same is possible here, and will be far easier than selling ice to proverbial eskimos, because it’s easy to take the moral high ground in advertising (and moral high ground is almost as powerful as safety and “think of the children”): we will not parley with criminals.
> nd more institutional bribery can generally be waited out, at the least. Even if it’s occasionally a long wait (like, months instead of days, or years instead of weeks).
And in the real world that means you pay.
> wouldn’t dream of driving without wearing a seatbelt.
Because people understand that it is in their interest to wear a seatbelt. That's very different from paying a a bride that is often in the person's interest.
It was an Indian economist, and chief economist at the World Bank, that suggested making payment of bride legal to shift incentives [1]. You still have an incentive to pay but also an incentive to report it, while it increases the risk for the bribe-taker. Whether that would work or not, it recognises that the key to influencing behaviour is to create the right incentives.
Ehhhh, I think the overall impact of Bitcoin is negative, but the "democratizing large-scale crime" argument is a pretty poor argument for why that is. First, Bitcoin isn't "democratizing" anything good or bad--people need to stop using this word with regard to Bitcoin. But assuming you mean something along the lines of "enabling", or "empowering", I'm not sure that the shift in computer hacking crime which is caused by Bitcoin is actually negative.
Prior to Bitcoin, the people who paid for poor security were consumers whose data, money, and time were stolen. In theory if an entity exposes your data, you can sue them, but in reality, data breaches are common and when entities actually get sued, they rarely pay out significantly. I've followed the Equifax case every step of the way for years and still haven't received a dime, and I doubt many people would follow through all the hoops they've put in place--I'm mostly doing it out of curiosity at this point.
That still happens, but more and more, ransomware's biggest targets are large entities which should have secured their services better. Not only does ransomware punish the entities who should have prioritized security, not the consumers, it also makes it public knowledge whose security is lax.
Now there are a lot of complexities here. In theory, ransomeware hackers could also sell the data--but as far as I know that doesn't happen much, probably because they rely on the "honest crook" effect to ever get paid. And sometimes ransomware is employed against individuals.
And to be clear, I'm not endorsing ransomeware attacks. I'm just saying this looks like harm reduction to me: if a big business is going to not prioritize security and get hacked, then I'd rather they pay a ransom than have user's private data sold on the darkweb. In a more just system, that's just the fines they'd be paying anyway.
* I suspect that right now companies find it cheaper to pay than to improve their security.
[0] https://wtop.com/national/2020/05/texas-high-courts-hit-by-r...
[1] https://www.msspalert.com/cybersecurity-research/municipalit...
[2] https://www.wwnytv.com/2020/07/28/western-ny-hospital-recoun... https://edition.cnn.com/2019/10/11/us/alabama-hospital-ranso...
Aren't these the entities that you would most want to keep your data secure?
> Alleged better safeguarding of our data* isn't worth it.
> * I suspect that right now companies find it cheaper to pay than to improve their security.
That makes no sense, because if you don't improve your security, you'll be hacked in the same way again. There isn't an upper bound on how much it can cost to not improve your security.
I don't think the local municipality or the courts have anything I'd consider sensitive on me. Regardless, my bigger desire is for them to stay running, especially the hospitals. I'm not willing to temporarily shut some down 'for better security'.
>That makes no sense, because if you don't improve your security, you'll be hacked in the same way again. There isn't an upper bound on how much it can cost to not improve your security.
What actually happens is that the targets pay, and issue tougher mandates which may or may not be respected in their organization. These hacks are rare enough for now - I suspect hackers don't like to hit the same target again soon after (bigger risk of the target not paying you) - so eventually the organization slips back into same security morass they were in the first place, if they ever left it. There isn't a true desire to change.
Also, there is an upper bound if you're paying insurance, like that hospital did[0]. Over the long term insurers will raise their price, but at least it's a predictable bound.
[0] https://www.wwnytv.com/2020/07/28/western-ny-hospital-recoun...
More likely, other criminals will come knocking on the same company's systems and get that data for other purposes.
Yes. Or, they can get hacked again and pay another ransom until they learn their lesson.
so, no.
Bank Secretary : So, people hire you to break into their places... to make sure no one can break into their places?
Martin Bishop : It's a living.
Bank Secretary : Not a very good one.In a perfect world, everyone can be trusted, and we don't need locks on our doors or passwords on our phones. In a dystopia, everyone has to carry a gun or have a bodyguard to leave their fortified homes, and a quarter of GDP goes towards security measures. We're somewhere in the middle, but things like this push us a little further down the road to more sunk costs in security measures.
A locksmith might make a killing after a local crime wave, but they should understand that crime is bad for the neighborhood regardless. Cyber crime raises demand for white hat services, but what's good for white hats is not necessarily good for society at large.
If it was a zero-day or something newer - defined by regulations - then the company is not liable.
Your analogies are cute but I want new laws, further making your analogies moot.
That said, proponents do have a shot at enlightening us (me and other viewers of the thread). What large scale positive application are you aware of?
* Two set of fees to exchange crypto to fiat + transfer fee compared to one set of fiat currency exchange + transfer fee.
It's hard to say. The current fiat system, due to predatory and parasitic practices such as the inherent interest involved in working with it, and how the government is able to control inflation at will, is absurd.
Why?
Currently you have to setup accounts with multiple companies in many different countries and pay fees to all of them, it's an absolute mess.
Is it? VIPs are regularly held for ransom in unstable countries, so much so that ransom insurance is a thing[1]. If those ransoms can be safely received, why can't it be the case for ransomware ransoms?
[1] https://en.wikipedia.org/wiki/Kidnap_and_ransom_insurance
It streamslines it, yes, but it doesn't make it "almost impossible" to pull off like gp claims. Russia is listed as a "high risk" area in the wikipedia article for ransoms, so if they can pull off a ransom exchange (with human hostages) there, I can totally imagine russian hackers being able to pull off a ransom exchange with cryptographic keys. If anything, it's probably easier to pull off than a regular ransom because you don't have to contend with a human hostage.
Also, a quick skim of wikipedia[1] suggests that buying/selling of stolen credit card info predates the creation of cryptocurrency. If cybercriminals were able to find ways of transferring money back then, I'm sure ransomware authors can use the same methods to transfer money today.
[1] https://en.wikipedia.org/wiki/Credit_card_fraud -> https://en.wikipedia.org/wiki/Albert_Gonzalez -> https://en.wikipedia.org/wiki/ShadowCrew
From the comment you were replying to
> we're democratizing large scale crime. Previously only large organized crime organizations could perform such an attack. Now, almost anyone can.
That seems true and the main point. That it's gotten significantly easier for anyone to do this.
Why not ban the encryption while we’re at it?
Instead of bashing it, how about we come up with solutions to the problems?
Just because you don't see a utility for it, doesn't mean it doesn't exist.
More people can do this but I think "almost anyone" is something of an exaggeration.
The one area where he claims it is an enabler is as a medium of exchange between criminal organizations. It's easier to transfer large quantities of currency and easier/cheaper to verify validity, than the traditional method of brokers and illicit escrows (nothing like the briefcase handoffs you see on TV).
But those same qualities that enable those types of transfers also enable transnational transfers of currency between nations that do not have agreed on standardized electronic methods. And I'd view that as an overall win. I'm also of the opinion that on a slow and steady long haul, cryptocurrencies will eventually take over the role of the US dollar as a trading base currency. Which would also be a win in my opinion, with respect to geopolitics.
democratization works both ways. A democratized currency facilitates both crime as well as the oppressed - after all, you cannot tell the difference between them under an oppressive regime.
What you implied that we should have is a democratized currency that's _only_ good for non-criminals (and used for "good purposes"). That's impossible. It's like asking for a gun that you can't commit a crime with, but can be used to defend yourself with.
It could help middle class people get their money out of a given country but otherwise, where's the benefit?
Criminals don’t care about filing tax returns for digital assets, which is why we see them use it as currency. When you or I try to use it as a currency, we’d have to file a tax return if the value of it changes (at least in the US)
If we saw governments ease up on this a bit, we might see some interesting currency applications come if it, but I don’t see them letting go of that control.
Our current legal framework doesn’t support such a draconian suggestion as presented imho.
You want poor security practices to be painful, not fatal, to the corporate entity.
Banning ransomware payments just makes it more difficult; someone will still find a way to save their business by paying. You want to resolve the root issue: a business not taking security seriously.
I’ve done a lot of infrastructure work, so my home network is...robust. Quite unusual; even for many corporations.
Two DMZs, three routers, three WiFi networks, two NAS units, etc. Also lots of redundant backups.
But really, I expect such a law would provide for exceptions, with a maximum payout capability. And for such a law to come after an offsite airgap backup requirement for such entities.
But really, the answer is that the equivalent physical criminal action: walking into a hospital and absconding with all of their medical records, would result in criminal action against the thief. Their actions may be akin to manslaughter if deaths result.
[1]: https://www.ucsf.edu/news/2020/06/417911/update-it-security-...
Cut deeply enough - take out entire companies - and people lose their jobs.
People can't eat. People lose their health insurance that allows them to afford their life-saving medication.
At some point, it's not just "big corporations"; it's the people that work for them, too.
There's a very specific value of human life: https://www.npr.org/transcripts/835571843
Now take this scenario to every major financial crisis (e.g. USA today, Latin America for the past couple of decades, some EU countries hit 20-30% unemployment a decade ago, and are still recovering).
It won't kill them instantly but consider what it does to them, if it turns them to crime, alcoholism, depression, and the general impact on the quality of life.
Only in one country on the planet.
The idea that there are fundamental differences between human lives and corporate assets is flawed. There's a very specific value of human life: https://www.npr.org/transcripts/835571843
They said they saw a difference.
They didn’t say other people didn’t see a difference.
Which would be the point, that there are no fundamental differences between corporate assets and human lives.
You seem to think they said that ‘everyone sees a difference’. They didn’t. They said ‘I see a difference’. They’re only ‘wrong’ about that if you think they’re lying to us about their own personal position.
Thank you for your logic lesson but I fail to see how this changes the discussion.
Human life appreciates the same way. In some number of years the government will decide that the economy can sustain valuing human life at a trillion dollars. And they'll look back at us and see that we undervalued life in the same way that we can look back and see that the Romans undervalued human life. Lives are worth whatever we can afford.
Even though not paying the ransom is recommended, some companies are instead paying the ransom as part of their insurance coverage. For example, earlier this year Lake City, Florida was a victim of a ransomware attack. After receiving approval from their insurer. Lake City paid $460,000 in order to restore their systems. Since they had cyber insurance, the city only had to pay a $10,000 deductible.
Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations, I really don't have a problem with them going under. It's less burdensome than being compliant with the local tax code, which all businesses have to do already.
How many people you meet everyday that are not in IT even knows what offline redundancy means?
I think what your suggestion amounts to, is effectively a mandate on SMBs having either an in house security team, or a contract with a consultancy on cyber security. That's a huge burden. It's not really easier than local tax code. These things change much more frequently and it's not like you can just walk into a local H&R Block to take care of your cybersecurity needs. Ransomeware, as it is now, didn't even exist (or is that popular) 10 years ago.
Incorrect. The black hats almost always encrypt backups, too. You could say "what about offline, glacial backups?" But then you're no longer talking about "the simplest of backup solutions"
A big part of the threat is the disclosure of sensitive data that they exfiltrated. Backups don't help this.
Not to mention that the pros delay encryption until they've managed to screw up backups, too.
Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.
Uh, have you looked at all the corporate scandals of the last, say, 40 years?
White collar execs never do hard time anyway. At the absolute worst they get 6 months at some cushy minimum security... aka Club Fed.
I don’t know much about this travel agency. They may or may not have had a security team. What they did have was mentioned in this article: liability. They took steps to reduce or eliminate this liability. I think we all know that there’s no proof these attackers acted in good faith past the actual decryption, but now CWT can at least say they attempted to recover lost data.
I think we can only realistically hold companies liable for transactions like this when we have better government resourcing and oversight. Getting the FBI involved in stuff like this is difficult, as they’re over loaded with such cases.
I also feel we should never hold individuals liable for stuff like this. It’s unreasonable to expect people who aren’t security professionals to know how to defend or respond to threats like this given how rapidly the landscape changes.
Figuring out a good way to holistically deal with cyber criminals will probably be a problem we struggle with for years, if not decades.
1. Taxing only the victims is adding salt to a wound: these companies are already hurting from being attacked, lost money to the ransomer, and are likely to lose more shortly thereafter due to bad PR. They'll need this money to fix things and hire/consult appropriate experts.
2. Taxing all parties likely to be hit by stuff like this spread the financial burden amount companies of all sizes. Larger companies/targets can thus help protect smaller outfits that aren't well enough funded to field a robust security team or program.
3. Some kind of revenue stream is required here to beef up federal/regional programs relating to cybersecurity. There's no real source of funding for this that doesn't come out of a larger budget. The scope of the problem is large enough that I feel it justifies a specialized agency with it's own budget. Having a dedicated tax applied to parties with need for the service/support seems fair and progressive to me.
Jokes aside, I absolutely agree that this is a failure of the US federal government and congress. We should have answers for these things for now, or at least the beginnings of a national security program to combat cyber crime. The FBI is seriously overwhelmed and the other three letter agencies can't be bothered to play the blue team as far as I'm aware.
You are running the company. You spend all your life getting to CEO position. And then boom breach and your company has massive loss, lawsuits and you are out of the job. Probably 9/10 CEO types will just engage in a crime to avoid that situation.
Current situation is way better. All breaches are public, prices are public, so the correct answer is to invest in security and if you get caught with your pants down, just pay the fee Let justice department handle it from that point on.
The way bank robberies are handled is the best. Just give them everything they ask for. In the end of the day it is either insured and even if it is not, it is stupid to risk anyones life for money created in fractional-reserve banking system.
It's somewhat more difficult for actual businesses to buy drugs, though, isn't it? The money would show up in audits and all that.
If drugs distributor has money in cash, they will probably engage in loaning short-term to ligitimate businessses with very predictable massive cashflows that pay in cash: construction, cleaning, farming, gambling etc. They don't even have to pay in cash, as long as they have cash receivables that will work as well.
They probably called something like Farming Loans Inc and deliver cash in the beginning of the month for business to meet their cash requirements. They either use it to pay their workers or will just deposit into their account as revenue. Month later they just send me back the check,that is loan pay back that is 100% clean money.
Obviously they will need to manage Farming Loans Inc balance sheet to explain where the seed money for loans are coming from, but that's where white colar crime comes in, where not so good accountants and lawyers will cook books.
For ransom money, the system will be even more cleaner. Somebody will create offshore consulting security firm, that will engage clients in return for consulting fees. So if somebody has breach, they will call them and like we need some consulting. Consulting firm will talk to ransom guys, get keys and then bill the client. So if you accountant and look at the balance sheet of multimillion dollar company, you will see consulting fee invoice and that is pretty much it. For IRS or FBI to dig any evidence, they will have to get a whistleblower plus somehow get the documents of offshore company, which makes it impossible.
In the end of the day white colar crime is 100x bigger then anything to do with drugs/ ransomware and it starts early, because the system pushes people to behave this way and 100% trust base and a lot of behaviours are 100% legal.
The good example is retail brokerage companies that encourage day trading, options trading, FX pares trading. This is just a scam, but hey why not.
It shouldn't be the criminals penalizing them, but here they are filling the gap that the regulators ignored.
The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.
You really need comprehensive, air-gapped backups that date to years back.
Not really. A sister company of my previous company had ransomware incident, and as far as I've heard this was not the case. They had just purged local backups. The attack was stopped quite early by an engineer noticing abnormally high IO activity and shutting the whole infrastructure down as soon as they realized what's going on - while a lot of data was lost and had to be restored from backups, most of the files were untouched. Still, the recovery took really long while to audit every machine before they could be even powered on again.
Poisoning backups requires backup systems receiving encrypted data for a while. Which means live systems running off the encrypted data (and most ransomware encrypts at the file level, which is much harder to do transparently, compared to the block device level). Which requires effort to make sure this is extremely transparent and goes unnoticed. Doubt that attackers do expend their resources unless they see a necessity.
One may not recognize the real value of something (or costs of losing something) until it happens.
And its also about your threat model. If data leakage of any form threatens your business you need way more security than if you just want to be able to recover from exploits in your publicly facing infrastructure (or the ability for a rogue actor inside the company from sabotaging the business from the inside).
At the most extreme having physical separation of infrastructure with physical token based auth and multiple signature verification to interact with data is going to be a heavy price in diligence to maintain secrecy. At the lowest end having a redundant backup storage array with a cron job on all employee computers to versioned backup files every minute that doesn't have network signin access.
Buy insurance and pray. There is not a single readily available enterprise solution that would even dare to put that in writing, let alone deliver. If there is one that does dare, ask to test their claim by having the deal conditional on them putting out an open $4.5M bug bounty and nobody collecting on it (you should also be the one to determine if they have to pay). Every company will either back out or get collected on, no question. This is a good test because if it costs more than $4.5M to do such an attack, then it would be unprofitable to collect on the bug bounty. It is also unlikely to give a false positive (their system is good when it is not) since $4.5M is more than than almost every other bug bounty and it is totally above board, so you will get the best of the best trying to break into the system.
If they expect a decent ROI, the attack can't cost any amount up to $4.5M to execute.
The $4.5M isn't a guaranteed outcome from such an attack. Some targets may not be willing to pay, or may only be willing to pay a substantially smaller amount.
Also, part of the execution cost is the non-monetary "breaking the law" factor. For instance, would you rather make a legal $1M or an illegal $2M?
If you are not, I am not sure what you are arguing since all of your statements show how the test overestimates the difficulty. The test is designed to identify, with reasonably high confidence, whether any attack is profitable given a specific upside. Therefore it should be as easy as possible for a legitimate bug that could result in at least a $4.5M upside to be paid.
A 100% guaranteed legal payout clearly minimizes the risk and thus allows more attacks below a $4.5M cost to execute to be profitable. Any other form of payout means the cost to execute must be lower to be profitable. Put another way, if it is unprofitable to do it totally legally for some amount of money, it is probably even more unprofitable to do it illegally for the same amount of money (obviously this excludes cases where you might be able to gain a higher upside, but then we are not talking about mitigating attacks with a certain upside), therefore this estimate should be no lower than the true cost to execute (on average).
To use your examples:
If they want a decent ROI, the cost of attack must be significantly less than $4.5M to execute to be a good investment. ROI of illegal actions usually needs to be higher to make up for the risk since you would almost always choose a legal action with the same ROI.
If the probability of payout is less than 100%, then the cost of attack must be less than $4.5M to make up for the reduced probability of success. The probability of payout for a bug bounty is usually higher than the highly variable payout of an attack. Also since the buyer is using this to make a quality decision and has authority to force the vendor to pay out with the stated scheme, it is in the buyers best interest to pay out credible attacks.
If the non-legal nature is a serious cost, then the cost of attack must be less than $4.5M for the illegal case to make up for the extra risk and cost. Non-legal actions usually come with extra costs compared to legal actions and thus have to be even more profitable to be worth doing.
Therefore, if a $4.5M bug bounty (where payout is decided by the product buyer) is not claimed after some reasonable amount of time we can conclude, with some reasonable amount of confidence, that the lowest risk option is likely unprofitable. Therefore, higher risk illegal options with the same upside are even less likely to be profitable. Thus, the test is a relatively good lower-bound for identifying if attacks with a $4.5M upside are actually being mitigated. If you can not even institute this lower bound, then you are nowhere near the necessary level.
I would be curious to learn the % of origins for most attacks.
[1] Incompetence by dumb employees
[2] Insider attacks
[3] Paid cybersecurity protection racket that take down strong systems with stolen tech
[4] Unskilled or understaffed security employees
Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.
For example, one way to get around that is you could sign a contract with a foreign consultant firm for "security services", say for 1 year, and they would take your money, and pay a portion of it to the ransomware authors and profit on the rest.
It's very hard to find individuals to hold criminally liable for things like this. When was the last time you saw a CEO go to jail when their company killed someone?
I'm against ransoms, but if I was CEO of company that's about to release COVID19 vaccine, or provides jobs to 100k of people, you bet I'd pay that ransom.
But even if that would happen, it's naive to think that corporations wouldn't work around it. They already do, by outsourcing payments to 3rd party companies - they can proxy it via other countries, fake identities, etc, etc.
Is this based in reality? What countries have banned ransom payments for human kidnapping and what people did it “suck” for?
My hunch is that if your spouse gets kidnapped and you have the means to get them back, you’ll risk it.
They are not the only ones, just the first I found on Google.
Good to know you weren’t just talking shit there.
How does a legit company purchase $4.5M of BitCoin in 24 hours?
I would assume using a “K&R” style broker but, without one of those how would you do it?
Let the money sit in a Bitcoin wallet for a while. Maybe move it around a bit here and there and cash out a few years down the road. Good retirement egg.
Immutable, versioned files in managed cloud storage eliminates the locker threat (not the disclosure one though).
You made a very good point about Windows GPOs. The delivery mechanism for them vs. how macOS does it shows how dated of a paradigm they are. It's bringing back memories to me of importing ADMX templates, gpupdate.....
Scenario 2: Sell solid security and backup principles to management, fighting annoying budget and corporate culture battles along the way. Company does not get attacked. Nobody notices.
Scenario 3: Quietly set up an immutable backup service with hourly backups for your enterprise without anyone really noticing. Company gets attacked. "Actually, we do have backups. We can just reformat all those Windows machines." Hero!
Well, except this is similar to #2 as it will likely stand out in the budget - especially the initial setup. IT being a cost centre has to fight for every penny in most non-IT-centric organizations.
Plus, the hackers will still threaten to release your corporate data (i.e. emails, client info) which would compel most companies to pay-up.
Bottom line: every company needs good backups, intrusion detection, and system hardening (with 3rd party review).
I hope.
Got to imagine there’s a well-established laundering system for just that
They're not out of the woods yet. Whats the bet they get crypto locked again next week?
Malta enables Binance to enable users to "clean" approximately ~2 bitcoins/day per an account.
Binance has ~5 times the daily trading volume of the 2nd leading exchange.
There has to be a stick or these folk will keep demanding more carrots.
So they have to get their security in order, or this is just the beginning of their problems.
Hypothesis B: There are North Korean hackers who have mastered English, an enemy language whose speakers they have almost no interactive exposure to, to such an extent that they can, in real time, simulate the subtle mannerisms of another, completely unrelated set of non-native speakers of English.
Take your pick.