80% of orgs that paid the ransom were hit again
venturebeat.com
venturebeat.com
Now just wait to see what will happen to your insurance rate after you pay the third ransom.
They certainly will begin to understand the need for backups.
Another issue with backups, is are you restoring to an already infected / immediately infectable state?
I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.
It sucks locking things down for each employee, and subjecting them to bureaucracy to unlock things they need to do, but it's better than ransomware.
It's unrealistic to expect every employee to catch hacking attempts 100% of the time.
It's like compartmentalization on a battleship. A single hole won't sink it, in fact, many holes won't.
Good post. I don’t mean this criticism for you specifically. But, why is there an assumption among HN types that there are no bad-actors among the insiders? You can have all the safeguards you want, but if an insider deliberately installs something, you’re screwed.
In some industries — armored trucks, banks, military stuff — there is a huge emphasis on background checks, security clearances, and the like to weed out bad actors. (And, even then, it often fails.)
I sense there is nothing similar for employees handling the company’s data. Obviously, there might be background checks and the like — hell, McDonalds has background checks. But, I’m not aware of the intensive FBI-style screening you see in the aforementioned realms.
Am I wrong?
How many thousands of people, for instance, could corrupt or lock the data at, say, Amazon? Are these people scrutinized to the same level as standard Brinks Armored Truck driver? I doubt it.
- is protecting against internal sabotage actually different that protecting against external attack. I don't think it's all that different. It comes down to authenticating actions and enforcing the principle of least privilege. If you built a system that was actually secure (i.e. one that depends on reasonable inconveniences, rather than one that depends on people to be perfect all the time or is so inconvenient it inclines them to do the digital equivalent of jamming the door open) it is likely that it will be secure enough against most internal saboteurs.
- is protecting against internal sabotage going to pay off? Most people probably aren't inclined to deliberately target their own company. It's far more likely that there is a bad actor in the world who wants to target your company, than that there is in your company. And making a person's job secure less stable is probably going to make them more likely to be a saboteur, so you should carefully evaluate whether gratuitously adding stress to someone who might get behind on their mortgage is a good idea. (Which I suppose is what this kind of background check would cause.)
“Most” people are law abiding. So, I agree with the first sentence.
The second sentence, however, has little support. The universe of people who can do these types of attacks is large, but not universal. You need computer skills. Necessarily. Those with computer skills are usually already part of the industry. How many disgruntled people pass through the FAANGs each year? Now add in all the IT positions at the banks.
In short, there are probably tens of thousands of domestic ‘bad actors’ who have (or will have in their careers) access.
Probably more.
Your argumentation doesn't challenge the truth of falsity of the statement, nor does it go towards challenging my conclusion. It seems to assume I've said "there are probably no internal bad actors", when I've said "securing your system against external bad actors will deal with the cases more likely to occur, and will usually be sufficient against the less likely cases".
'X is more likely than Y and preventing X mitigates Y to a tolerable level' is not equal to saying 'Y probably doesn't happen'.
> How many disgruntled people pass through the FAANGs each year? Now add in all the IT positions at the banks.
Obviously the probability increases significantly with the number of employees, but I don't think that switches the probabilities. Still, the most important companies to consider are the companies which, unlike FAANGs, aren't really in a position to make independent judgement about their risk profile, but whose existence depends on their records/data. And even someone with as many employees as the US government probably has more people outside of their employ who want to target them than inside, although surely they always have some of both.
I'm not sure what the relevance of your reference to computer skills is. In order to ransomware a company, as far as I know, you need to buy software off the darkweb and run it from a vulnerable location. I suppose technically that requires computer skills, but it's surely not what you mean. And the companies which are vulnerable to ransomware are not all employers of significant numbers of technically skilled people.
In any case, I don't think even a gratuitous reevaluation of the probabilities significantly changes my conclusion. Even if we assumed the improbable notion that every single company in the word has a disgruntled employee and that there are no external crooks, the process of securing the system against external crooks will make it far more survivable against single internal bad actors, and the effect it has on the employees will be less likely to produce internal bad actors.
The entire issue just leaves me with a nagging feeling that something fundamental is being overlooked. There is something profoundly different in modern companies that didn’t exist a few years earlier; namely, a very tight concentration of data/ops/control. Whether it’s external or internal, it seems a single person can do catastrophic damage to the company AND the customers. Fifty years ago, for instance, in a typical auto plant, I doubt a single person could have truly devastated the company (short of a bomb or arson or something). Nowadays, we’re moving towards systems where not only could a single bad actor cripple the company but also cause all the cars already sold to stop. (I exaggerate a bit, but you get my point I hope... )
But in the corporate world, theres gotta be huge variance, but so many don't give a flying flamingo who's scoping out what, unless somebody is forcing the issue (and also auditing and reporting to the compliance department, whatever thats for).
They know the people in the NOC/SOC, the C-suite has equity, there may be physical access control, cameras and proxcards out the wazoo, but when Marge from bizdev needs those emails for the marketing newsletter or whatever, she is gonna get them immediately and hand them right over to the intern or vendor or Doug, whatever his job is.
For all the obscene value that the data and access represents, its encrypted, right? What could go wrong? Want to background check the sales people? But... look at this guy's resume! He's only asking 80% of the market rate! These dialysis machines sure won't renew their support contract by themselves.
Best case scenario is that the costs mount even higher into the stratosphere and people start demanding a second look. It's been a while, Maersk, JP Morgan, TransUnion, Colonial Pipeline, Beef, Hospitals, Schools, the OPM (for god's sake...) billions or trillions of dollars. It doesn't seem to be a priority.
No. It never takes only one employ clicking a bad link. It takes that click, plus a browser/email/os system that allow for random code to executed. It take an IT department that has allowed individual non-IT employees to use computers with elevated privileges. It requires a management structure that has failed to invest in proper off-site/cold backups. It requires an organization that doesn't have a proper business continuity plan.
And at the top of the incompetency pyramid, it requires a vendor that sells an email system that allows evil email messages to somehow infect entire operating systems. Want your email to connect to your office suite? Sure. Want to install random software based on clicked links? Sure thing. Want to update your firewall, install a new browsers and simultaneously backup all your encryption keys to a random server in the far east? Why not! Anything to make your operating system experience seamless.
Locking down admin access is less about protecting the local machine and more about preventing the laptop from becoming a jumping off point into more important pieces of infrastructure. It's by no means fool proof, but it adds another security feature that has to be countered.
I don't know whether it's worth the trouble it creates, but I don't think it's totally without justification.
- A phishing email which can pwn you without user interaction is basically unheard of.
- Even malicious sites generally can't do anything bad simply by visiting them. (and yes, I'm aware browser exploitation exists, but it is exceedingly rare)
- Ultimately, it's entering your credentials in a malicious site which is what puts users at risk. A user must click a malicious link (sometimes two) and then intentionally enter their credentials into the malicious site.
Between this, and the fact that users must read emails, visit sites, and enter their credentials over and over, just to get through their workday, I believe the outcome is that user education doesn't amount to much. It would be much better if a normal user's workflow didn't usually require clicking on email links and then entering their credentials. The fact that this is required means that even a savvy users will eventually be tired / rushed / working on automatic and get owned.
If you extend from "email" to the other communication tools that companies use today (and do use for inter-company communications too), there actually have been a number of these in the past year.
Outlook [3] had one that didn't require downloading the file, exactly - the "Preview" window from just clicking the attachment once, was enough.
Microsoft Teams [0], Jabber [1] and Slack [2] were all hit by real 0-interaction RCEs.
[0] https://github.com/oskarsve/ms-teams-rce/blob/main/README.md
[1] https://nvd.nist.gov/vuln/detail/CVE-2020-3495
Why? Secretary gets a call from a nigerian prince, starts that letter.exe she gets in her e-mail, her computer gets fscked, IT takes her drive, restores a clean image, and she gets back to work.
If the only copy of some important document is on his/her pc, or that pc can overwrite/delete the only copy, then they've fscked up by design... and yes, now better backups would help.
Thank goodness I didn't have access to a script that would lock up at least two of my past employers when coming up years ago? Then again, I personally haven't been that mad, but boy do I know employees who were.
I could say that we are all choir boys, but you piss on an employee, especially during a recession, well let's just say I have seen unpstanding guys rub magnets over hard drives over pure apathy. (The guy didn't know about strength of magnents, and it did not hurt anything.)
Plugging in a usb, or downloading a suspicious email is something I can see happening, especially to "those" companies.
I imagine Xfinity employees dream about it?
Open up a spinning rust hard drive and you will find two very strong magnets inside, positioned opposite each other.
We got bought. Big corp enforced Endpoint Management and a whole barrage of corporate spyware.
I am not an admin anymore. I can't even use an AdBlock solution anymore.
And guess what. I don't give a damn anymore. If the device enforces an update, so he it. If I have to double approve every external mail address when sending, so be it.
But I don't feel ownership or responsibility anymore. Should corporate overlords care. I am out.
Guess what? The big-corp IT managed computer which I only use to check email and edit Word docs is almost unusably slow, weighed down as it is with antivirus, surveillance software, centralized updates, etc. The project machine which I manage and have admin access to remains snappy despite its workload (Visual Studio) and older hardware.
Also, you gotta love the "cost savings" of let's outsource our IT, not let developers be admins on their own machine: now we have to buy secondary machines that developers ARE admin of, so they can get their work done.
And I'd argue this isn't only true for kernel development. In some cases, sure, but certainly not enough to make such a blanket statement.
Though I will agree there are exceptions, you are not one
I kept my machine as it was, explaining that if anything happened to those units (bad updates, blah blah), mine would be unaffected and mine was completely necessary.
Lo, and behold! That very day everyone was complaining how slow their computers were, how even basic websites now took ages to load, and they did.
The owner refused to admit he made a bad decision and stayed with that 'IT' 'company' for over a year, and didn't get rid of them until I'd left and no one was available who could triage, and they saw just how little that 'company' did, and just how much I was made to cover for them
That last part leaps out at me as particularly interesting: highlighting behind-the-scenes firefighting work is always tricky. Management doesn't want to acknowledge that it's necessary, while engineering maybe shies away from managerial caricaturization of what ultimately amounts to implementational minutiae. How'd you end up conveying the behind-the-scenes work you did in these kinds of situations?
And the accounting folks will not be fans of anything that costs money. They will just say "But we haven't been attacked a second time, why should we pay for mitigation services and implementations??"
Organizations can and do take many decisions of which "the accounting folks" are not fans of, the accounting people can and do say such things about the costs, but they don't have a veto. Arguments about cost of mitigation are valid in general, but leaders and owners can choose the priorities, and the responsibility and blame for these choices is fully on them (for their will or lack of will), not on "the accounting folks" arguments.
Also, sometimes that accounting argument is entirely valid. For example, look at the recent case of First American Financial - https://krebsonsecurity.com/2021/06/first-american-financial... - if the consequence of leaking the sensitive financial documents of millions of customers is just 500k, then it definitely is cheaper to just accept the hacks and pay the compensation, because investing in proper security would be much more expensive than that.
They used to (and probably still) do this. But more recently these folk are paying access brokers. A bit like bank robbers teaming up with criminal locksmiths.
> It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups.
You'll ideally need:
- Better security awareness training to cover human weakness such as spotting dodgy email and what to do if you click a link
- Patch vulnerabilities quickly as this will reduce risk considerably
- Company wide tested and sufficient backup strategy (most companies fail on this) to protect key identified data assets
- Regularly pen-test both your internal and external environments
Obviously it doesn't stop there, but those are key.
Snapshots aren't backups.
Backups that aren't physically-isolated, typically offsite, aren't backups.
1. Test and encrypt backups.
2. Don't get hacked. Defense-in-depth philosophy and rigorous, routine social-engineering training/testing. If you get hacked, it's usually game over. Defend systems like the business depends on it because it does.
3. Limit exfil: extra security for PII, exfil detection, and [HN]I[DP]S.
What OP tried to demonstrate that backups need to protect from bad changes, on physical, logical, and business layer, from data corruptions to 'oops' scenarios (i.e. drop table). Standard snapshots for sure don't protect from all those.
Also for a good backup strategy, you need - "a full start" once in a while, because corruption in "full backup" will invalid all incremental snapshots - regular restore of a backup for e2e validation
I suspect you mean filesystem snapshots and as long as the snapshot lives on the same physical media you are correct. But when you take the snapshot and transfer it to a physically separate location where it cannot be altered it sounds like a backup to me.
Vaulted offsite on at-rest storage media is the only valid way to store backups. Every other "convenient" "backup" service or snapshot replication process is a liability businesses must avoid. Lose all your data, 50%+ you're out of business, and The End.
Relevant analysis here:
http://www.vendormanagementoffice.net/2021/06/cyber-insuranc...
---
But we've proved it again and again, / That if once you have paid him the Dane-geld / You never get rid of the Dane.
--- https://www.poetryloverspage.com/poets/kipling/dane_geld.htm....
By paying, you’ve just proven that you are a profitable target to hit.
I was just throwing some complexity into the Danegeld narrative.. not sure what it means in terms of the metaphor. Maybe ransomware hackers eventually build operating systems?
> 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group.
The same group!
Some groups will hack you AND also uninstall viruses emanating from other groups, or they will hack you and patch other flaws so that other malwares cannot take their spot. It's all game theory.
All the good guys shut up, and so you're left with the criminals who then exploit the flaws instead.
"SCHWIRTZ: What DarkSide does is they're a ransomware creator. So they create the program that is uploaded into a victim's computer system that locks down their data. But what they do is they basically contract out to these affiliates who are other hackers. And these are the people that are responsible for actually penetrating the victim's computer services. And what they do is operate basically on a subscription service. You, as an affiliate, can sign on to DarkSide services, in which case you get access to their malware, their ransomware to use for a fee that operates on a sliding scale depending upon the size of the ransom."
https://www.npr.org/2021/06/10/1005093802/inner-workings-of-...
I think these negotiations are fine, if you're just buying time to gather your backups; I've assumed the payouts were made by insurance companies, so go ahead - buy a zero-value promise from a gang of crooks, if you want.
But your org has been rooted (at best, you can't prove it hasn't). Compromised systems can't be really be cleaned, they have to be reinstalled from scratch, if you want to have confidence in them.
And an attack can be stored in data - which you're about to restore from backup. That's a problem I have faced, and I chose to ignore that threat. No choice - I didn't know how to address it then, and I still don't now.
My half-baked opinions about ransomware are largely based on watching this documentary: https://www.bbc.co.uk/programmes/w172wx9056p6bd6
I'm curious how one would enforce that. From the fact that the ransom got paid in the first place, we can establish that there's no legal body that's able and willing to exercise any authority over the ransomware group. So it's not like you can sue them for breach of contract.
Perhaps you can rely on the honor system? Though, given this is a group of professional extortionists we're talking about, if you choose to go that route, you may be at elevated risk of getting what you deserve.
If a ransomware group has a reputation of not actually delivering the unlock upon payment, or of re-infection shortly afterwards, the decision to pay them becomes harder to defend.
I hope the authorities find a way to go after these people, but it's obviously got to be difficult, because they might well be in China or Russia. It would take some international cooperation that's probably impossible right now.
In the meantime... Switch to Linux, have a competent offsite backup strategy...?
You know they’re vulnerable to the attack (the hard part?) so why not keep doing it until they shore up their defenses.
As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable.
The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.
And I'm sure they'd just invent or go back to some other method -- possibly riskier and more violent -- so they can continue to ransom money from people.
The effect would not come from the criminals being able to cash out, it would come from the company not being able to cash in. If cryptocurrency were to be banned and public exchanges were closed purchasing cryptocurrency to the tune of millions of dollars worth becomes practically impossible for a regular company without connections in the space. If the company is not able to pay the ransom, the entire venture is pointless.
> And I'm sure they'd just invent or go back to some other method -- possibly riskier and more violent -- so they can continue to ransom money from people.
Sure, there will be other methods of transferring some amount of money. To the tune of millions of dollars, though? Unlikely. Cryptocurrency enables these companies to pay ransoms of this amount. Without cryptocurrency you might be able to ask for a 50K ransom instead of a 5M ransom, but that reduces your payout by 100X. 5M is enough to retire from. 50K is less than the yearly wage these people can make.
It's not like ransomware didn't exist before cryptocurrency, we know what ransomware without cryptocurrency looks like. What cryptocurrency changed is the scale of the payout. Instead of getting a few thousand dollars in gift cards the hackers are now rewarded with millions in bitcoins. It is hard to deny that the change in incentives caused by cryptocurrency is the primary driver behind the huge increase in ransomware attacks in the last few years.
Sure, it would be more difficult if crypto is illegal, but I think because of the difficulty of getting it, crypto prices would skyrocket.
Everyone will also move to using the privacy coins too. So, banning crypto might actually be beneficial for it as it would incentivise crypto projects to improve privacy and decentralization even more.
A ban won't stop people from using it or developing it in their homes.
Sure, nowhere in my post do I deny that an underground market won't exist. In fact, I directly hint to the fact that it will exist. What matters for this problem is how easy it is to buy $X million worth of bitcoins for a company. Currently this is easy. If you have $X million in your bank account, you can go to one of these exchanges and buy $X million worth of bitcoin.
With the exchanges shut down, how would a company buy $X million worth of bitcoin? Where do they go? How do they not get scammed while doing so? It's not like companies can easily move $X million to another country where it would be legal to buy crypto either. After all, if they could move money in a bank that easily, crypto would not be required at all for the purpose of ransomware. They could just move the $X million directly! People use crypto for ransomware because it is not so easy to move money of this magnitude.
> Sure, it would be more difficult if crypto is illegal, but I think because of the difficulty of getting it, crypto prices would skyrocket.
That seems unlikely. A bank run seems the most likely scenario with a massive drop in price being the result, even if only a few high-impact regions would make it illegal (e.g. the US and EU). Regular people and large investors would cash out almost immediately upon hearing the news. Why would regular people want to own an illegal currency that they cannot trade for anything besides maybe drugs on the black market?
The reason the majority of people own crypto now is not because of the utility - it is because there are legal crypto exchanges that they can use to trade them back to the actual currency that they use (generally dollars or euros). If people have to go through illegal networks in order to perform these exchanges (and remember, exchanges for fiat money would be illegal and hence risky) the entire value proposition is lost.
> Everyone will also move to using the privacy coins too. So, banning crypto might actually be beneficial for it as it would incentivise crypto projects to improve privacy and decentralization even more.
I wouldn't even propose banning cryptocurrencies entirely. Shutting down the exchanges and banning the trade of cryptocurrency for fiat seems more than sufficient for this purpose. Cryptocurrencies can continue to exist on their own and perhaps find a use/purpose of their own. The back-and-forth exchange for fiat is what is problematic.
This might even be good for cryptocurrencies as a platform, as the focus would shift back to the underlying technology and its use cases rather than the investor crowd that doesn't give a shit about the technology and only cares about making a quick buck.
Sure, there would be an initial bank runk, but a ban would also have unintended consequences such as making coins more scarce, thus unintentionally driving speculative demand and cause people to turn to the black market, especially if there are bank runs on fiat itself (I know, extremist, but you never know - I've personally eyewitnessed a national currency imploding once).
> This might even be good for cryptocurrencies as a platform
I guess we have something we agree on. Also a ban would encourage more activism and push cryptocurrencies to their full potential (of side-stepping the bans by going to fully decentralized exchanges and peer-to-peer) and weed out a lot of the snake oil in the space.
Do I see a ban to be successful for what what it intends to do? Maybe temporarily, but in the long term it will fail and backfire.
It's like nobody has learned a thing from the war on drugs, my point being: you deal with the root cause of the disease (infosec in most companies and even government offices is a joke and bad people have taken notice), not playing whack-a-mole with the symptoms (crypto use) that hint towards systemic decay.
If the goal is to stop companies from paying ransom, then why not just make that illegal?
https://home.treasury.gov/policy-issues/financial-sanctions/...
There's just no other form of payment which would work for them. You can't easily go "can I have $50k worth of giftcards" and on the receiving side you can't easily validate or sell millions of them without tanking the value. Any kind of wire transfer would expose the source immediately at that scale. There's only so much money you can move through services that give you kickbacks of various kinds. What else is left?
Basically unless ransomware teams know of a new really good way of laundering money without a trail, or are happy to take a massive pay cut, that would be the end of most of their operations.
Money grows on trees, there, too.
I'll bet you dollars to donuts that if you made crypto illegal, there's still a whole lot of countries that won't give a shit and the problem will only get worse.
All these situations are nebulous and complicated, something as simple as legally banning crypto is not going to solve the problems.
Paying the ransom a second time would guarantee nothing. Neither was paying the first time either.
Like, is a company who runs its IT infra on Windows XP and pays the ransom likely to switch to the latest and greatest, no expenses spared, in a total and utter overhaul of all their systems? Or will they only try to patch the holes that were already revealed and gloss over the rest? Blame it on the intern, all that.
Somehow, that's a quite believable scenario.
Fire fighting in Rome had a similar premise.
In both cases it’s the market at play.
This is instead a dysfunctional government approaching anarcho-individualism.
edit: Actually, Plutarch wrote that Crassus did buy the burning buildings.
Plutarch was closer to Crassus than I am so I guess I can't argue.
[1] https://penelope.uchicago.edu/Thayer/e/roman/texts/plutarch/...
https://www.youtube.com/watch?v=9zoXk1vnmcg
The real Bowery Boys would sometimes sabotage other companies' insured buildings by setting the fires.
Also, please do the work to expound on your claim.
A free market system requires protection of property rights. Arson violates property rights, and so is not free market.
When I hear people describe a free market, the respect for property rights is sacrosanct yet many also push back on regulation. This confuses me. Regulation typically seeks to ensure rights are respected.
Or Backblaze's evil twin.
I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.
Some of these guys encrypt over a period of time which is long enough to exceed the backup rotation. Their code decrypts on request, until the trigger day, when it posts the banners and deletes itself.
Also, one should use "append only" backups (such as tape), or a disk drive designed to be append only with hardware write enables.
This is commonly suggested, and entirely useless.
What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely useless.
Even if your backup does couple the data and compute together, if it's simply time based (not sure what other event you could use really, perhaps some pure probabilistic function), then it seems like you can just trick the environment that the time is something else to get back in.
The real underpinning issue is that this stuff breaks the state of the infrastructure and the business can't afford the downtime to go around and repair these issues.
If you have your infrastructure build out mostly automated, that automation is backed up, and critical data is backed up, then you can reasonably sidestep these issues (I supposed a real thorough breach might integrate the ransomware in this very automation system but it should be reasonable to root out). The other issue is of course if the intruders threaten to release private data (empkoyee and customer PII, financials, so on). There's also business integrity but that doesn't really seem to matter anymore.
But as for an event to use, what they can do is have the machine check a remote URI to see whether it should let the system run, and if it should then set itself up to lock things at a specified time. In order to restore that you need to have it starting on a network with networking to a system that has the attacker's private key to sign the request. This is not an environment that you are able to create.
If you are penetrated, it's not so easy as just restoring your data from backup. You have to sterilise the machines you are restoring to. And you have to sterilise the data you want to restore. CM automation can deal with the system sterlisation, but I don't know how to sterilise data without using human judgement.
Don't get penetrated.
If they earn a reputation of coming back for seconds...
Two things:
People fix things faster to prevent double dipping.
People opt to not pay the initial ransom if they’re going to be taken hostage again.
It’s a kind of tragedy of the commons where the commons are the potential victims.
Plus, if the original vuln used to gain access is still open, there’s no reason why somebody else doesn’t find it later.
Though I suppose those thieves could also pay for the encryption key, or just go directly to the "service provider" for a paid copy.
Ransom gangs are business oriented.
I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
Cheapest way to avoid paying ransoms.
You can never be sure about 100% hacker safe but backup/restore system can be life saver
It's interesting to see the various reactions to a perfectly innocent idiom.
https://en.wikipedia.org/wiki/Alice_and_Bob#Cast_of_characte...
Maybe it's all automated shotgun based attacks and they don't close the holes and so the act of paying the ransom is statistically meaningless
This is shoddy journalism. Might as well just say "X%". It implies you shouldn't pay lest you fall victim again but they don't actually say that.
Things that implicate what they refuse to say is kind of suspect
[0] https://www.cybereason.com/ebook-ransomware-the-true-cost-to...
One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway.
That’s a hard one to swallow, hard enough that govs also sometimes can’t follow the mantra and just pay the ransom.
It’s crazy hard to get people to sacrifice themselves for the better good, it’s yet a bigger ask for corporations who already screw the public day in day out.
And on a purely primal level it's common to prioritize one's offspring over one's self. I think most cultures recognize this intuitively.
What a grand delusional statement, like the sibling comment here. It’s literally arguing moral superiority while ignoring pragmatic reality.
Maybe you watch a little bit too much television, but there are plenty of spouses out there who would, for example, not want their wife to die in childbirth if they had the option.
Not to go too sideways, but hostage (with humans, not data) situations are typically about other people. When you’re the target, it’s not your life on the line, but your loved/valuable ones. So you’re not defending just yourself, you actually have to care about at least someone else to have it happen to you. And some care about a lot more than just their loved ones, they’ll also think about their friends, family, sometimes the rest of the society.
Everyone is different and there is no absolute best, but let’s at least recognize it’s complex and there’s lots of ways to think about it.
https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u...
Having US govt. on your ass should a decent deterrent.
Just take a look at how hard FBI came down on cartels and individuals who were involved in killing Enrique Camarena. Cartel leaders were arrested in Mexico and several individual in the US.
The US cannot really send special forces there without risking a massive escalation.
But sending a spy to a software developers house and assassinating them probably isn't going to stop the problem - more people will spring up doing the same.
Russia has always been notoriously hard to spy on.
I would not be surprised if there was only a handful of well placed assets and most of the spying being done electronically.
Also, the US and allies can enforce Russian AML laws as written on paper. If, say, the UK freezes all of Oleg Deripaska's assets there, Vova will absolutely get the message. We're not going to bring down the Russian government with military force for a million different reasons, but doing it with sanctions and prosecution is a totally different story.
It's the sort of thing you say publicly, but then privately you settle with your adversary.
Absolutism is never a useful tactic.
That sounds pretty absolutest.
You might even want to establish an isolated society, but if you try, good luck dealing with the IRS.
That's the theory. But much like war on drugs or TSA, whether its real-world outcomes match the theoretical ones is debatable.
https://www.newamerica.org/international-security/policy-pap...
This has nothing to do with that idea.
The reason the orgs paid the random once was because they had a severe lack of backup and other data safety protocols in combination with a vector to be infected (from all what we know, the latter is common and difficult to avoid): paying the ransom is likely their only choice to maintain the business.
It is not surprising at all that these orgs can and will be infected again, and will continue to show a lack in the security and data safety departments, and so they will continue to pay ransoms.
It's sort of an inverse survivorship bias: if you get infected once because you're susceptible, you're likely to get infected again unless you fix your susceptibility.
I would be totally fine with legislation making it illegal to pay in the case of ransomware attacks. Some companies might be completely destroyed by an attack that they can't pay off, but that is for the greater good of society: if criminals know companies have a low probability of paying since they're legally barred from doing so, they're less likely to target them.
https://threatpost.com/ransomware-hits-hospitals-hardest/162...
In order for this to be a useful tactic, there needs to be no defection. The only way there can be no defection is if the legislature prohibits defection.
At that point, the hospital is on notice that they have to apply adequate security measures against this kind of attack. For instance, hospitals normally have power supplies that are capable of getting them through foreseeable blackouts. If they're going to rely on computer systems in the treatment of patients, they had better make sure they're secure. Right now, today, it isn't a surprise.
And the hackers are on notice that they are effectively killing the patients. The hackers are after the money. If the threat of death will get them the money, they're all for it. If it won't, they'll move on to a country where it does work.
My opinion would be the hospital should open up to the police and accept their fate whatever the outcome. The gov./police makes the calculation of the impact of X people dying a very public way, the Y amount that is requested, and the ton of other wildcards (e.g. can we catch the gang now ? after the ransom is paid ? void the ransom some way afterwards ? limit the number of death in other ways ? what will the other victims take away fom this case ?).
At the end of it there should be a custom approach to that specific situation and not some blanklet policy application.
This also assumes a cooperative and somewhat decent police force, which might not be the case everywhere (but then I think we're screwed anyway)
The word 'terrorists', for one. It's mostly used to mean 'my opponents' these days.
What we are facing with ransomware is not insurrectionists or protestors, but gangsters. They make their living by stealing from people, cheating them, and threatening them. Many insurrectionists are honourable people that you can safely make a deal with. There is no gangster with that property.
Take backups, test the recovery procedure, don't make bargains with gangsters.
And then everyone clapped at the high-brow analysis.
There is much confusion and many bad analogies surrounding this issue.
Some claim - without evidence - that nation states are behind it. Which, with a moments reflection, is absurd; nation states may have an interest in disabling certain systems for military purposes (at the appropriate time), but no nation state needs ransom money. Easier ways for a government to get money; namely, just print some.
Others liken it to the mafia or cartel or other well-organized criminal organizations. This too misses the mark.
Like most business crimes, the culprit is almost always an insider. Period. As the tools to pull this off are trivial to come by on the internet, the obvious suspect would be some disgruntled IT person within the company.
It’s as if — after a bank robbery — everyone claims it must have been some crack team of Russians flown in under radar in helicopters. Instead, they should be looking at the numerous employees who have access to the security system and the safe.
But, it’s much more exciting to pretend that Putin is sponsoring hackers to get trivial amounts of money from companies across the globe. Ha.
I’m not even an IT guy, but at my last job, even I had access sufficient to destroy or corrupt all the data. That was before cryptocurrency and the like... I assume assembling a ransomware set of tools off the internet is no more or less difficult than it was to assemble a set of tools to make pirated copies of AdobePhotshop back in the day.
Sure, this is obvious, makes intuitive sense, except...it explains why something like Iran-Contra or the equivalent in other countries can't happen.
What is money? If a government wants more domestic resources, it can get it by printing money. If a state is so limited in domestic resources that it fundamentally needs resources from outside, printing money doesn't help. Printing money can help a state devote more of its country's resources to trade, but if no one wants to trade with you at any cost, it doesn't matter what parts of the local economy the state controls.
North Korea has incentives compatible with these kinds of acts, and relatively few interesting ways of deploying software engineers locally.
Typically:
* Password spraying from previous data leaks
* Good old-fashioned fishing
* Bugs in anything that's common in enterprises, exposed to the Internet and not patched fast enough, including MS Exchange, various security/VPN products, vcenter, you name it. All of these had pretty critical pre-auth bugs exposed just this year
* malicious browser plugins
* malicious O365 apps
... and so on.
- ActiveX for legacy ad-hoc software
You'll never be rid of the Dane
But the similarities are there, although the person's behind the ransomware attacks are probably not vikings.
Outsourcing it to el-cheapo, offshore middlemen is not going to cut it.
Alternatively, Cybereason are probably in a really good position to snarf passwords and then parallel construct an attack from a third party who gives a few major individual shareholders a kickback.
Does endpoint security even work?
These people are just financing the next generation of cyber criminals.
Once people stop paying, people will stop attacking.
https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u...
But it would be very interesting to see if the ransomware gangs can devise a scheme that gives the payer plausible deniability.
It looks like you can download the full report by filling out a form [2]. (So I didn't.)
[1] https://www.zdnet.com/article/most-firms-face-second-ransomw... [2] https://www.cybereason.com/ebook-ransomware-the-true-cost-to...
Wait - is this how the market fixes poor security practices?
If you pay the terrorists they just do it again. If you pay the ransomers they just do it again. And the payment increases their capabilities.
I think, except for rare conditions where a temporary need exists, it’s a net negative to pay.
But I think the security flaws that allow random ware typically are a sign of institutional incompetence so it makes sense they would also be incompetent to pay, and pay again, and pay again. Rather than to prevent the attack or to correct the flaw that allowed the attack.
[1] https://www.foreignaffairs.com/articles/2007-01-01/negotiati...
Fool me once, shame on you. Fool me twice, shame on me.
i.e. An attacker breaks into a system using one vulnerability, spots a few more vulnerabilities while snooping for data, files them away for future reference, extracts a ransom, and then repeats the process later after the victim fixes the first vulnerability but fails to address the others.
The takeaway lesson appears to be that, if you are hacked and fix the vulnerability that made it possible, you shouldn't stop there. You're marked as a target that pays and detailed information on your system is now out there. Even having fixed the first hack, you're more vulnerable than ever.
- These Companies (probably)
Most are created by companies looking for media coverage and are just made up.
This isn't true and I'm not sure why people think it is. This is not how the world works. Ransom crews are not cartoons, they are people like the rest of us running a business.
At a very high level, sure, ransom paid then they might be 'hit again' by a random hacker testing the defences next year. Is that 'hit again'? 'Hit again' is not 'ransom again'
If this is cookie cutter ransomware that's automated and you pay an automated system to un-encrypt. Sure the worm or what not will attack again is you don't fix that worms hole.
This has zero to do with REvil and all the famous ransom crews that the title implies. That should be pretty obvious.
This is easy in a containerized env, if you don't have that luxury having batch scripts that can provision all the critical servers quickly does the trick. This combined with reliable database backups should be enough to make the impact of such an attack trivial.
At my last place, they only kept 1 year and monthly, but the problem was it was hundreds of terabytes of data on lots of VMs. We tried to restore backups and it was going to take longer than the long weekend just for file transfer.
I don’t know what normal process is, but I believe I saw file locker Trojan that didn’t hit every byte of the drive; but rather crawled the file system and did a bit on every file header for speed. So I imagine it’s still faster to pay and fix than restore from backups for some.
Only 43% of organizations invested in data backup and recovery after a randsomware attack? I would expect that number to be closer to 100%!
The fast growth desires lead to a lot of vulnerabilities, yesterday I signed up to a service and they emailed me my own username and password, simple plain text. Incredible.
> After an organization experienced a ransomware attack, the top 5 solutions implemented included security awareness training (48%), security operations (SOC) (48%), endpoint protection (44%), data backup and recovery (43%), and email scanning (41%). The least deployed solutions post-attack included web scanning (40%), endpoint detection and response (EDR) and extended detection and response (XDR) technologies (38%), antivirus software (38%), mobile and SMS security solutions (36%), and managed security services provider (MSSP) or managed detection and response (MDR) provider (34%). Only 3% of respondents said they did not make any new security investments after a ransomware attack.
So attacks will continue, the level of impact will hopefully be reduced along with the commensurate justifiable ransom payment.
But we've proved it again and again,
That if once you have paid him the Dane-geld
You never get rid of the Dane."
https://www.poetryloverspage.com/poets/kipling/dane_geld.htm...
> 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group
Why would victims pay them? Why would the attackers bother to reinfect? Just up the price on the original infection, after the first payment.
What percent of orgs that did not pay the ransom get hit again?
orgs that completely ignore payment as an option spend their time identifying the entry point, and vulns, and close those before restoring or rebuilding.
(Also, implicit in the claim is the argument that any activity is good activity. I don't think that holds: I think paying for security guards and spending disk space or CPU cycles on security measures are necessary, but not beneficial. Probably, the world would be better if there are no bad actors. But I can only assent to your claim if I believe that the world is better if we protect against bad actors than if we have no bad actors and no protection. This is probably the cause of you getting downvoted.)
> The least deployed solutions post-attack included web scanning (40%), endpoint detection and response (EDR) and extended detection and response (XDR) technologies (38%), antivirus software (38%), mobile and SMS security solutions (36%), and managed security services provider (MSSP) or managed detection and response (MDR) provider (34%). Only 3% of respondents said they did not make any new security investments after a ransomware attack.
uh huh. uh huh. uh huh. uh huh.
Meanwhile, for example, earlier today: a web search for "cat /etc/passwd" blocks my IP. What even is the point of this article? _Of course_ if you don't patch they will just hack you again. _Of course_ if your company follows terrible 90's practices, it will get owned again.