Ransom gangs increasingly outsource their work
krebsonsecurity.com
krebsonsecurity.com
The “encrypted” Swiss phone of choice by narco traffickers (and others) in the 1980s run by the CIA:
Police ran that service for quite a while before cracking down simultaneously across multiple countries.
They just sat back and let it continue until they decided to move on the information gathered.
"EncroChat sent what it called an "emergency" text to its users on June 13 saying it had been compromised"
Well, they really weren't considering they could have just not raided. The circumstances changed and they decided to act on what they had.
It's a pretty interesting bust when you get into the details, highly recommended.
He’s not the judge and jury and he shouldn’t be doxxing anyone. It’s a big problem with him, and one of the reasons I wish people would stop linking to his website.
If you can provide the references, I am open to reviewing them and act accordingly in the future.
He doxxed notdan and gexcolo most recently on Twitter.
He's not been shy about telling you about when people have tried to retaliate.
Any ideas why that is? I thought s/w companies have gotten smarter about securing their infra, e.g., strict https-only access, linux server (not windows), and so on.
If you're a startup with limited resources, what essentials do you need to be aware of to secure your systems?
If you are a startup with limited resources, keep things as simple as you can. Back up your code, artifacts and customer data somewhere that automation and malware can not tamper with it. Encrypt your customer backups. Challenge your staff to automate patching of your endpoints, your servers, your virtual machine images, etc... Challenge them to create build systems that produce lean, fully patched images with software that only comes from trusted sources. Images for laptops, images you run in dev, images you run in production. Have a manifest of every piece of software, every library, every snippet of code your teams utilize. This will be helpful down the road when you have grown and your legal team want to do a software license review. If using AWS, set up automation to audit and report on public S3 buckets.
I think after doing the obvious stuff with your core infrastructure and making sure you have good data backup and recovery procedures in place, the next best use of resources is in trying to make sure your employees don't fished.
The less glib answer is that while best practices have gotten better, companies aren't necessarily better at following them (your company or your vendors). Additionally, on average people have not gotten all that smarter (while scammers have become more sophisticated).
Its all about defense in depth. Plan for compromise, trade off the costs (nothing is free).
At a technical level there are basic things like: separating dev from production, requiring 2FA across the board, strong passwords, certs, separation of privileges, up to date software, secret management, etc that form strong defenses.
Another way to approach this is to pose scenarios and understand defenses:
* What information could an employee give away that would then lead to a compromise? How do you stop it? Password to a phisher? Check in credentials to github? Wire money to a fake vendor/wrong account?
* If X was compromised, what is the impact? What would it take to recover? Where X is: dev box, production box, customer facing service, etc.
Two insidious scenarios that happen way too often:
* Latest malware distributed via legitimate sites (ad networks, sharepoint, dropbox, etc) -- Hard to prevent beyond up to date systems and content filtering. If paranoid, all browsing through VMs or other forms isolated environments. It won't stop compromise, but it will restrict scope.
* BEC -- Attacker studies your company. They impersonate an employee or partner (down to linkedin profiles) and convince someone to wire money. Or worse -- account compromise of a trusted partner. The attacker then uses this partners' account to hijack an email thread or send a 'normal' request like: "Our account has changed, future payments goto account YYYY."
Which brings us to vendors. Can a vendors' weak security break your company? Is it a good idea that your Microsoft Office 365 account allows unlimited password attempts (at least MS used to by default)?