US companies hit by 'colossal' cyber-attack
bbc.com
bbc.com
I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the castle to some mid-tier company is just a recipe for disaster, and the bad guys know how extremely lucrative these targets are.
Embedding this kind of software deep in your internal networks/systems, with access to basically everything, is a recipe for disaster. I expect these sorts of supply chain attacks to get more and more common, they’re excellent back doors into basically every government agency and megacorp.
I should just edit the wikipedia page, but they won't accept edits from my current IP address.
Anyway, here's a good introduction: https://en.m.wikipedia.org/wiki/Technical_debt
Often the most maintainable solution is simple and elegant, but it takes a lot of refactoring to implement, so a hacky, complex solution is implemented instead, because it’s faster/easier to implement. Such solutions tend to either contain bugs, or lead to bugs when built upon, and a lot of security vulnerabilities are basically bugs in hairy parts of systems that are hard to understand.
Let's say you are designing a system - any kind of system - with the philosophy that everything should be connected to everything else. Your first part goes in quick with no connections. Your second part goes in quick and has one connection. Your third part has to be connected in two places for it to work right, but that's not a problem. Your hundredth part has to be connected in a ninety nine places for it to work right, and now you're spending more time wiring than you are on making parts.
Then we ask, "what can we do when that happens?"
You have to put effort into the design of the system, reassigning duties and studying the nature of the problem it's solving, so that you lay down the connections along the true contours of the map, and not between every single component. Afterwards the next component you add has to be connected only to the three other things it's actually related to and you're back in business. This results in a period of time with no new features or even bugfixes, but afterwards you move faster.
Then we ask, "why do people call it debt?"
Because you pay interest on it when you have it, you run it up when you're short, and you better have a plan to pay it down or else you will go out of business.
Should I attribute you or someone else? :-)
Edit: added as a private bookmark to pinboard with tags:
technical_debt quotes by:whatshisfaceLike when you need to fix all the support columns in your building, but instead of spending millions to take them down one at a time and replace the corroding rebar inside, you just patch over the exterior cracks. They will look fine from the outside and get the job done on a day to day basis, but they hide structural problems and one day that debt will come due. Most of the time it's in the form of a giant project to finally fix everything, but sometimes it's catastrophic failure.
"Softhwair", if you will :D.
Technical debt is like not cleaning your house to save a bit of time everyday. When you actually have to clean it, it's going to take longer than the time you saved. And until it's not clean, everything you do will be a bit worse because the house isn't clean.
"Remember when you were a student and didn't do the dishes, and then when you finally did them everything was dry and sticky and stinky, and it took you a lot of time to wash everything and you felt terrible? That's dishes debt. Technical debt is the same. When you make a change, you produce dirt in the codebase, and if you don't or can't take the time to clean every time, dirt accumulates."
If you did it when building a plane, and it killed people, you would go to prison, but in the technology industry, this is acceptable as "the cost of being first"
(I jest. A bit cynical but that's often how it comes out in practice).
You can cook a bunch of times ignoring these secondary results but over time cooking will be slower and of worse quality due to the mess and at some point it will be impossible (too dirty, no usable pots and pans, etc).
There is significant cognitive load in understanding the code and what it does and why it does it that way etc. Keeping all the important bits in one mind is challenging and a lot of the little fixes can lose sight of the big picture in a way that comes at a cost and, over time, this can really add up.
Over time, different people may work on the code and have different reasons why they made different choices and at some point it may all stop playing well together. Then there comes a point where someone needs to try to reconcile all the different bits and understand what needs to happen and why and rebuilding the entire catalog of goals, features, etc. in one mind at one time so someone actually understands it all and gets it right is a substantial future cost that only grows as you keep delaying that step.
(From one lay person to another -- I do write code, mostly html, and run some web projects, mostly blogs and Reddits, and spend too much time on HN. So technical debt isn't alien to my experience though I'm not really a programmer.)
1. Knows the wider requirements but isn't involved in the implementation. They can't fully specify what's needed without doing the actual implementation; the map is not the territory.
2. Is told the broad requirements but probably can't grasp the things they aren't told in the imperfect spec. So under time pressure, in good faith, they do the simplest workaround possible.
3. Is given the next set of requirements. Instead of re-engineering the original design, under time pressure and in good faith, they add a workaround for the workaround.
Each new workaround is "tech debt".
When you add the next feature you now have to deal with multiple levels of complexity not in the original spec.
Understanding the actual implementation now takes more time than expected. The chances are that no one fully does, which leads to further mistakes and workarounds. So more tech debt.
Either you pay the debt down and re-engineer or you pay the compounding interest forever.
...and so on. Each new level of complexity gets harder and harder to understand and debug because no one really knows how the real design, held in the actual works.
So when I became CFO I fired them (outside company), not just for this, but it didn’t help.
It’s bad software. 24/7 full low level access is exactly what it is. We had an add on that stored admin credentials in a JSON… so looking back on that, it seems this should have happened sooner.
https://doublepulsar.com/kaseya-supply-chain-attack-delivers...
There was an AV integration, and then Kaseya changed to Kaspersky. I don’t remember what the prior AV software was.
I always thought it bizarre we were actively installing AV software from Russia on banking and medical office PCs.
I viewed it as safer to buy products from anywhere other than someone that has ANY potential at all to go to war with the government of the country I live and work in. I really hope it never happens, but 'cold war' tensions might be waged with little cyber attacks and that software came to mind as a risk.
I wouldn’t run K, but I know from experience it’s actually effective.
- Can you articulate specific reasons to buy anything beyond the default windows defender?
- If anyone went to an actual war with the US, would the source of your antivirus software get even close to top 5000 things you care about at that point...
And yeah there's a decent chance if the US went to war with another country it might not impact the majority of US businesses very directly especially in the short term IRT their IT plans. McDonald's kept selling burgers when we invaded Iraq (multiple times). Ford was still producing vehicles during WWII. There have been lots of military engagements the US has been involved in where things in the mainland US weren't massively affected in day to day operations. Who knows what some potential future war with Russia would look like. Would it be a true head to head war with tanks rolling, fighter jets scrambling, cities bombed? Would it be more skirmishes testing how far the other would really go? Would it just be escalation of supply chain attacks and attacks on infrastructure to weaken the other? Of course this greatly varies based on the specifics on what that potential future war looks like, it would be naïve to think wars will always look like WWII, Korea, Vietnam, Iraq, etc from a US mainland perspective.
Is your opinion of their products the same?
On the other hand, all of the other networking HW sucks just as much. E.g. here are Netgear vulnerabilities published just this week: https://www.microsoft.com/security/blog/2021/06/30/microsoft...
IMHO, the worrying things about Ubiquiti at the moment are:
1. Their handling of the security breach/downplaying/whistle blowing fiasco which came to light some months ago. Check our Troy Hunts podcast from around that time.
2. Requiring a cloud account to manage your local device. Everyone seems to do that these days. It's not impossible to remove the cloud account management but it is an extra post install PITA step to work-around. And has some consequences if you do.
I'd like to see if they've learnt their lesson from at least the first point and become less opaque security-wise going forwards. Not sure their security is passing the smell test at the moment.
It's been wallpapered over as just cutting unnecessary expense for too long.
I get it at a pretty deep level individually but even knowing this I make enormous mistakes.
It sounds to me like if it means anything, it's denying that any probability depends on the exact dimensions of your ignorance.
There is no statistic that applies to everyone, unless that person is a completely generic person with no known qualities.
I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with massive risk reviews, but for some reason those security zones then share subnets with the entire LAN.
They also have a default configuration which makes everything access the standard intranet directory once its deemed secure. Enterprise security tools like Cyberark are deemed more secure than say yubikey HSMs, which may result in root ssh being enabled in a lot of settings. They have system configurations that are done with massive Excel sheets. Their cloud VPCs basically only have one risk profile and once its deemed secure it gets access to things in the intranet. They also vehemently refuse to do threat modelling when designing anything.
These people can tell you so much about the theory of security by heart that it will make you dizzy but then won't actually understand the underlying problems.
And the offenders are always the same, advised by Accenture, Infosys etc.
It doesn’t tell me whether they understand how it all works together, or if they understand the organization’s environment, or if they are a good worker.
I don’t hold it against people who fail (I’ve seen good people fail the test) or who don’t have it - I just have to ask a few more probing questions to ensure they know the tech I’m discussing. But I don’t outright ask if someone is a CISSP, so typically I ask the clarifying questions anyway so our understanding of the problem is accurate and aligned.
And cert or not, I’m still more interested in whether you know what you’re doing than what you put on your resume.
It's just a cram-and-forget vocab test, it doesn't mean anything other than that they could afford the training and the test.
It's as if someone sells you a laser that shoots intruders and tells you, you can leave the front door open from now on, but that laser only works 1 in 3 times.
it follows that
"Centralized hosting and management (SaaS, PaaS model) has the advantage of insecurity at scale."
None of this is rocket science and these people probably aren't stupid, so somehow, somewhere, something is going horribly systemically wrong (incentives? Training? Organisation? I don't know).
It's not like Colin Percival or Theo de Raadt , perfect as they are, could just audit and secure all of the Fortune 500.
I've thought greatest failure of many professionals in this field is in the "protect the network" perspective rather than "protect the data". While many of them fess up to "we can make it difficult but not impossible" to breach the network, that is not evinced by the protections instituted.
If companies actually understood that they WILL be hacked, the focus would turn to protecting the data. Actual resting data protection would allow a "I don't care if I'm hacked," posture. Either behind encryption, VM's, segregation, or architectures, preferably all, if data is actually protected, then a hack can be weathered. It's still a pain if the computer-touchers have to rebuild and reload, but that's what you pay them for. If the data is protected, a hack is just a painful exercise rather than a newsworthy event.
I do understand that segregating (through protection and architecture) data is difficult, but I do not understand why it is not the focus.
Imagine if the solution to Covid was "the virus can spread to anyone, we need to replace all humans"
It's only prohibitively expensive because most of these enterprise tools and servers are actually very much focused on manual setup.
That's quite interesting. Where can I read more about that ?
https://www.csoonline.com/article/3247848/what-is-zero-trust...
Protecting the data means encrypting it (which Google also does) such that the client needs a key to decode it.
But if the client is hacked, the hacker can get their keys! so encrypting the data isn't a magical cure-all.
Moreover what if a hostile party constantly hammers-disrupts your IT, letting you teams "rebuild and reload" 24 hours/day (in other words you don't have any information system anymore)?
That being said, RMM tools have plenty of examples that they need to beef up their security practices or get replaced.
But not every person who has executive oversight of operations thinks like I do, and all of them are represented in the company's finances as a 'cost center' that is second only to Payroll in terms of how juicy a 'cost reduction' target it presents.
So when the going gets tough, the company cuts back its IT budget.
There is a common misconception that CFO's fiduciary duty to their shareholders determines that they should protect the long term stability of the company, but now most shareholders are in the company for 6mths tops. The duration of a CFO's fiduciary duty is arguably about 6mths out. The devastation of large companies in the economies of the west since 1980 is a testament to this.
Fake Numbers: sales "generates" 100,000,000 in revenue and "costs" 1,000,000 however IT "generates" 0 in revenue and "costs" 2,000,000
So to an bean counter, clearly the "investment" in sales is better because they make money for the company, where IT just costs money...
Thus IT is often treated like a utility service, say something like custodial services, where they want to find the cheapest way to keep the bathrooms not disgusting... not clean mind you, just not disgusting
If you are looking at US curriculum, my experience is that you will see the discussion in terms of dollars and their "flow" through the firm from the customer and perhaps ultimately to a bank account (in the case of having positive cash flow) or how much 'short' the company is when it comes to a negative cash flow situation.
Understanding the cash flow dynamic for a company is critical to the company's success. If a company does not understand how they make money and how they spend money, they will not be able to manage themselves to a sustainable level.
As with engineering, it is a simplification to group "like" costs, and "like" revenues together. So for example all the money made by extended warranties and charging for repairs might be grouped as "service revenue." Similarly, all the money spent on leasing office space might be grouped of "real estate costs."
Every accounting program I have seen (and it isn't exhaustive of course, just consistent in my view), facilitates this grouping of costs into larger and larger groups. Depending on the size of the enterprise, the manager at a particular layer who had "profit and loss" responsibility could see a small number of these groups (which I have only ever heard referred to as either "revenue sources" or "cost centers") and they could get an idea of the health of their part of the business by seeing if their margin target (total_revenue - cost) / (total_revenue) was being met.
And at the managerial level, they typically would split their activities into ones that "improve revenue" or "cut costs." Doing either increases the gross margin which is what they are measured on by their manager, whether it is another person at the company or the board of directors. Because these are fundamentally an accounting thing, increasing money coming in by say raising the price of the product or restructuring pricing plans is called "growing top line revenue" because that usually the top line of a financial report. And when they cut costs or improve efficiencies so that they can make more product for less money, that is called "growing bottom line revenue" because the amount that gets subtracted from the top line is reduced and so the number at the bottom of the page gets bigger.
Finally, nobody is an expert on everything. And the larger the enterprise the wider the expertise needed to understand the costs and expenses of that enterprise. What is worse, is that sometimes the people in that role were experts at one time but the area where they developed their expertise has moved on and so they believe they know what is the right answer and don't bother to check. And sometimes they don't know the right answer but don't want to "look stupid" and they buy all the reasons the sales guy gives them for using their product as pass that along as justification without knowing the risks.
It adds up to a bad choice. And when that choice is to move to open offices (for example) the impact of losing productivity in people who cannot deal with that environment isn't readily apparent. And when it leads to outsourcing something which wouldn't be outsourced, the error might only become apparent when you're suffering a ransomware attack.
Meanwhile, best practices are slow to reach the curriculum and so there is a lag between people doing things poorly and it being taught as a bad thing in business school.
Redteams / hackers now target the infastructure, because it's way easier and they're more outdated in regards of code, stability and used libraries.
Most enterprise-grade VPN solutions still use OpenSSL from decades ago, and most of their fixes (even if they react to CVEs) are always too late.
As SOCs need VPN access because they are usually not on-site, especially at larger corporations...the result is when you exploit the VPN gateway, you are the new administrator because you have a large time window until the SOC team arrives on-site. These couple hours are usually everything you need as a time window to raid the place, install and run ransomware, and clean up afterwards.
From a cybersec perspective I cannot even begin to write how stupid it is to put literally all your company's value in the hands of a single security company - which is legally not responsible for anything by contract. Security through obscurity never worked, why should it do in this case?
Last year showed that we desperately need an open source OpenVPN based graphical and scalable alternative that uses a standard TOTP based token generation mechanism and not some proprietary crap for authentication.
Using a token generator with embedded analytics was just wrong in the first place, but...yeah.
Personally I'd love to see better Wireguard support and adoption outside the Linux world.
It sucks, because I know my company is quite small but we take security extremely seriously (we have 9 people, 4 are security engineers, and the other 5 have varying degrees of experience in security). I think people might worry that, because of our size, we won't be as secure as a larger company. But the irony is that larger companies are often far less secure than us, because we've done shit right from day 1.
There's just not a lot of ways to prove it. Compliance is meaningless. You could get a pentest report, but it really comes down to who's doing the pentest, and so if your pentest becomes a public doc the incentive is to have them go easy on you - not to mention that lots of reports contain "findings" that are nonsense but a casual reader might misunderstand.
We plan to give talks and blog about how companies at our stage can do things that would make companies 100x our size jealous, because that's kinda the only thing we can do to really explain that it's possible.
I think it's totally criminal that companies ask for RCE on all of your devices and then push out some closed source C++ app that's probably parsing all sorts of random shit, reading poorly authorized commands from some C2, etc.
Sounds interesting and rather extraordinary, would be great to read more on your thoughts on that. Do you refer to the Grapl blog?
To do the same is trivial at a small company. What would take years and lots of effort becomes something you can do in spare time.
Of course, we put considerably time into security, it's not just something that one does once in a while with spare time. The point is that we can go much much faster.
You can be compliant and buy insurance or you can be secure. Pick one.
Yeah, sure. We should have a person on each of hundreds of sites whose only job is to check manually every router, switch, and vending machine. Maybe in the best HN traditions you will train the necessary workforce in a weekend?
> tools that have extreme low-level access to networks and systems
The emphasis being on the low level access. The solution is not having hundreds of people checking things by hand (though I'm sure that could contribute to security). The solution is more privilege separation; so that when the "remote monitoring tool" is compromised, not every part of your infrastructure is also compromised by default.
Having hundreds of people in each location whose only task is to do a boring monitoring an very occasional management tasks is a waste of your resources and their intelligence. We do automation to escape doing stuff that we can but which are to mind numbing. The illusion that every one of those hundreds of people will do their job to the necessary level of quality and without lapses of diligence is optimistic to say the least. Doing automation badly is not a reason not to do automation at all.
Management is always going to have access, so maybe you should not enable remote management access of everything to a centralized system? Make it lean and secure, possibly segmented, dual-factor, use HSM etc.
Monitoring - there is no good reason why it should have access to anything. Make it ingest only (use firewalls and reasonable protocols), and you've cut out most of the "monitoring and management" vulnerabilities.
At the same time, you don't have a way to solve a problem that your monitor has alerted you for. Every solution proposed includes either a person at the location who does the job manually or a way to connect to the network from the outside which is vulnerable to similar attacks as before with added costs and possibilities to mismanage keys and passwords.
Security vs convenience is a well-known dilemma that people very often love to solve in the most absolutist way.
As for remote management. I'm saying you should wisely choose what needs to be remotely managed, what doesn't, what are the foundations for your security and then balance it with reasonable methods to secure access. Which would probably not be "Kaseya VSA Remote Monitoring and Management" for all your systems and devices.
Yes, make sure you don't need on-site personnel to restart your web server, but maybe also don't expose management of your switch that you never reconfigure to your monitoring SW, and maybe use separate HSMs¹ or at least HSMs instead of the enterprise management system for the most important parts.
¹ e.g. FIDO2 ed25519 for ssh
I have the bad feeling that this achieves security through unavailability.
For the record, I think none of your points apply.
I discussed this with their security team leads, and they answered with a straight face that it's okay because they had to spend their budget before the end of the financial year.
And everyone knows this is how it works too – so the Powers That Be keep setting the wrong incentives too.
This is why I never worked for a large Enterprise company or government agency. I'd go crazy.
Well then I guess we will have a lot threats from hackers for days to come.
1) How secure is the software? Where are the audits?
2) If your software compromises my business, how much of the losses I incur as a result will you cover?
Security by obscurity is laughable nonsense. We should all be demanding transparency in hardware and software from our vendors. I'd pay handsomely for it.
Any code executing in privileged mode can bypass security, and is therefore inherently part of a system's trusted computing base (TCB). (Linux is a monolithic kernel running in ring 0)
Most companies are not Linux contributors, they are trusting the kernel developers to write bug free, secure code.
Minimizing the TCB and opting for an auditable open source TCB are really useful concepts in security.
But the cause of these breaches is much more trivial than what you are worrying about: these companies are basically installing whichever piece of software can decrease their costs without thinking about what they’re doing.
>Any code executing in privileged mode can bypass security, and is therefore inherently part of a system's trusted computing base (TCB). (Linux is a monolithic kernel running in ring 0)
It's way nicer to be able to look at the code running in Ring 0 =)
[1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...
Patients in Region Skåne were also unable to access their journals on Friday afternoon (possibly unrelated) and Coop's competitor ICA's apothecary company Apoteket Hjärtat seems to be affected by Kaseya/REvil attack also.
What urks me is the obvious "never let a crisis go to waste" where we have visa etc marketing that cash might spread Corona.
Yes, I've put CHF 200 in coop register before. Funny, they don't care but if I scan a tiny bottle of alcohol I need to wait for someone to approve it...
How does the cashier open the safety box to reach the money?
Or open the cash registry?
I don't even think it is legal to accept money without a working cash registry for tax registration reasons.
* I'd wager that if you know the prices and keep track of what you sell, you'd be fine recording the transactions after the fact.
https://www4.skatteverket.se/rattsligvagledning/edition/2017...
My understanding was that it was just payment processing that was affected, not the point of sale systems. The scanners and things probably work fine, and I think they could accept cash payments without issue. It’s just not worth it when almost no customer pays with cash.
They likely closed to avoid issues with rejecting customers who didn't get the message. Or perhaps just to be on the safe side because they didn't know who the attack was aimed at.
In related news, I saved money by replacing all my house's circuit breakers with old pennies.
Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor.
The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly after.
Companies need to ensure that risks raised by senior engineering teams are taken into account before deploying company wide software.
They essentially are enterprise level back doors with good intentions.
Think firewall/antivirus/backup software suite run by a remote team.
https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom...
When these things happen, I feel like there's a predictable response. A few smaller vendors (above, Huntress Labs) provide a great running commentary. Then two weeks later, the dust has settled, everyone's patched, and I'll start receiving sales calls from Enterprise Vendor X wanting to talk about how they were all over it.
| We received an emergency call from our Kaseya rep to shut down our onprem VSA
https://csirt.divd.nl/2021/07/03/Kaseya-Case-Update/
> we were already running a broad investigation into backup and system administration tooling and their vulnerabilities. One of the products we have been investigating is Kaseya VSA. We discovered severe vulnerabilities in Kaseya VSA and reported them to Kaseya, with whom we have been in regular contact since then. Additionally, we have, in confidence, also reported these vulnerabilities to our trusted partners.
If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the ability of a country to respond. There's only so many recovery specialists and IT contractors available to respond in an emergency. Encrypt only a few hundred targets and they can all recover. But if you encrypt a few hundred thousand, then there wouldn't be enough warm bodies available!
Thinking about it, I wonder if these attackers have set up permanent operations, with staff, payroll, and everything. Maybe they just to fly under the radar and collect a nice steady income instead of a risky but potentially huge one-time payoff...
Also, at some point the military gets involved.
So it's a spectrum
The administration left it alone for days saying they'll let private business sort it out. (Default investigation notwithstanding.)
When a bunch of news media started reporting the group was Russian and then insinuate it was a state sponsored attack, DarkSide said something along the lines of, "We didn't realize this would start geopolitical conflict. We will be careful to vet clients more carefully in the future."
The FBI investigated the crime as they always do. It was treated as a standard international monetary theft.
Also you want the company to stay in business so it can continue generating revenue to extract future ransoms, and not have it lose a bunch of its customers from your repeated attacks.
This is combined with a business model resembling patent trolls: you want to extort just a little less than is worth fighting for. If a company gets hit on its own, it's probably not in a position to really do anything about it, but if there is some major hack affecting tons of companies, the odds of an actor with significantly more tech capability like the US government getting involved go way up, and suddenly fighting seems like a good option.
That doesn't jive with your market manipulation hypothesis.
It’s as much a political game at this point as anything.
If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves.
They’ll either end up hacked beyond their wildest imagination or facing literal hellfires.
It’s brinkmanship. When the devs literally die, they think twice.
Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker.
Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters didn't pay. There were no further attacks. The Teamsters declined to comment. (For those unfamiliar with American labor history, trying to push around the Teamsters Union usually ends badly for the pushers.)
[1] https://thehill.com/policy/cybersecurity/558066-teamsters-re...
“Ultimately, the union decided not to pay the ransom based on advice from its insurance company, and instead rebuilt its systems based on archived materials, NBC reported.”
Was Edward Snowdon "https://www.youtube.com/watch?v=1GtVt6quoD8&t=78s" or a psychologically manipulated patsy for the good/bad guys & girls?
https://en.wikipedia.org/wiki/Full-spectrum_dominance isnt just about hacking a few computers, its about getting inside the brain of each and every one of us/you like a https://www.youtube.com/watch?v=lG7DGMgfOb8.
Or is this line of thought just a https://www.youtube.com/watch?v=wmin5WkOuPw&t=48s ?
Source: https://searchsecurity.techtarget.com/news/252502519/Repeat-...
Wait, what? Have you notified the Department of State?
https://www.state.gov/state-sponsors-of-terrorism/
Iran is still on there. I'm pretty sure some people have been "annoyed enough to do something drastic" for quite a while.
https://en.wikipedia.org/wiki/Assassination_of_Iranian_nucle...
The reason why 2nd stage was only given to (relatively) small number of organizations - because the attack wasn’t ransomware, attackers didn’t have economical motives (in fact they were spooks on a government payroll).
EDIT: I can’t spell
If it was me (it was not), I’d use it to gain persistance in companies like Kaseya, extending my beachhead as first priority. After that is basically game over, cleaning it would take making new IT systems from scratch. And lets not forget firmware…
Sure…
No worries though, the ransom from this round should serve nicely as a Series B round of financing & enable rapid scaling of the post-hack ransom extraction process.
What's not is managing big sums of money, turning crypto in to a more traditional currency/assets. That side of the operation probably has more people doing leg work than you'd think.
It's even conceivable that if they go too far and political pressure in the US builds high enough, and Russia &/or their countries of residence are also put under pressure, that they could find themselves on the wrong end of a drone strike or no-knock flash-bank assisted rapid entry to homes and business locations. All they have to do is pick the wrong target that directly leads to deaths-- hospitals the most obvious, but industrial accidents or "rapid unplanned disassembly" of something like a chemical plant...
I was shocked at the pipeline attack, followed by one on the US's food supply. These rise to the level of terrorism, and when fear & anger become dominant motivating factors the event horizon for any ability to predict what happens will become significantly shorter and less certain.
And in the middle of all of that will be a team of techies and support staff struggling to cope with day to day realities of running a thriving organization. There's an IT Crowd satire show somewhere in there that Netflix should consider.
Yes much can be automated but there is usually a human element to these deals and that costs the hackers money.
They also want to be careful to limit their hacks to companies their handlers are happy for them to hack. Go too wide and you risk hitting a company directly or indirectly linked to your state/handler/patron.
Sorta playing into stereotypes about engineers here.
Perhaps not the largest groups, but the smaller ones, posssibly.
There are thousands, if not tens of thousands, of such deals done every year.
Why couldn't they have bootstrapped years ago? I suspect the real reason is they actually want to avoid extensive media coverage.
1) Scale of the attacks. Taking large portions of a country's petro-chemical/energy pipeline is far above the threat level presented by most prior hacks. The same goes for shutting down ~20% of the nation's pork & beef food supply. And now hundreds of companies impacted as a result of a single breach. Ransomware isn't new, but it is in hockey-stick growth mode.
2) Increased market for crypto currencies. Criminal activity may not, by far, be the dominant activity, but the more legitimate transactions there are, the easier it is to hide criminal transaction.
3) Bootstrapping this type of thing takes time because it's not just about capital in this case. It's also about accumulating vulnerabilities and compromising systems long enough that backups-- for example a week or month old-- are still useless (also encrypted). And going back to earlier backups will lose the company too much essential data.
4) And as you said, avoiding media coverage that will bring too much attention, and with it the potential for a crackdown. The slow burn on increasing ransomware over the years has acclimate people to it in a way that makes even the most recent massive attacks a little more normalized, especially when they pay the ransom & get back up & running in a few days. That limits the amount of public pressure to fight this head on with mandated increased security and massive resources thrown at pro-actively going after these hackers.
5) In 2016 ransomware wasn't quite as mature. 2020 is different, and the political landscape is different: I'm not making a partisan comment here. I'm not saying the previous US administration prevented these things better or the current administration dropped the ball. What I'm saying is that when there's any new administration, there are threat actors that will test the waters, see how far they can go. I definitely thing that's a factor here, especially so close after the Biden administration delivered its list of 16 untouchable sectors to Russia & Putin. There's going to be a lot of adversarial interest in just how firm those limits are, and what the response will be.
Otherwise, from a national awareness standpoint, you do approach an important point: It may not be a new phenomena, but for the vast majority of Americans that don't follow tech news, this is new and, given the scale of recent attacks, somewhat scary.
The solarwinds attack seemed to be about using a supply-chain attack to gain persistent access for recon and lateral movement. Pivot to Azure via Microsoft via SolarWinds software. Whomever it was tried to stay invisible for as long as possible. Once the game was up, they were not so careful about visible actions.
RansomWare is more smash and grab though it's interesting/sad to see the current trends of Supply Chain attack prevalence and Ransomware attacks converge.
Was that down to slow patching cadence at 99% of companies?
In which case those customers have different vulnerabilities to tend to.
I suspect the attackers know this. Or else they aren't in it for the money. One or the other.
Depth can be provided by reverting to older skill sets. Fallbacks. Businesses should not go down because their computers locked up with ransomware.
I pitched and wrote some software for a company a few years ago to automate a very rigorous daily process that used to take a lot of man-hours. Occasionally, local networks would go down and people would have to revert to the old way of doing things on paper. But as turnover happened at the company, fewer and fewer people knew the "old way". Now they've reached a point where they're locally paralyzed if there's a network outage. They have to call in senior management on their day off to run the shop. I realized I didn't do them a favor. I solved one problem for them and saved them a lot of labor, but I created a whole new problem of reliance on a system that's more convenient, but much less robust than the paper system they used to have. And this doesn't even take into account the potential for security issues.
I think we should try somehow to architect things with offline fallbacks and training for those scenarios. The pace of attack is unsustainable and we're losing the war. If the point is to keep business running, we will lose the war if we lose the skill base and knowledge that we had which was capable of running the economy without a screen in front of them.
[edit] Come to think of it, there's a great startup idea in systematically re-paperizing businesses for failover. Take all that business logic that got written into software, and turn it back into a set of worksheets and training manuals.
Windows, right?
Health IT here: won't happen.
You need your CT NOW. The patient is about to be opened. There is no time to wait for the printer and it's Sunday night. The radiologist is at home examining the data while the scanner runs.
And man...security is so bad and it's so hard to convince management to invest into proper security. Also everything that breaks or even slightly slows down workflows is just unacceptable.
I'm sweating hard with every wide scale attack out there expecting the next big thing to hit us. The targeted ones I just don't even want to think about.
Most of the times I still "sneak" in improvements where I can without disturbing operations but the whole thing needs a proper overhaul and it always is, as we say here: "a dance on the razor blade".
What I hear from other colleges and contractors in the sector: it doesn't look better there. I don't want to leave out that there is a certain amount of IT personal which is responsible for it too. Most of them older guys (yes...they really are all guys) who also follow the mantra I mentioned above.
There is hope though...there is a certification requirement coming up here in Germany. It covers most of the basic security measures. We fail to cover a significant part of it. We've just passed one of the deadlines. Two are coming up and than there is a certification process. I've presented management with the measures we'd have to take to fulfil those. They've been ignored. The whole issue is being actively ignored or played down. The day will come when it'll be too late and I wonder what will happen. Wouldn't be surprised if I lose my job about it since somebody will have to be blamed or the certification issue will be "made to work out" somehow. Seen that happening before.
However, from what I’ve seen, most of these attacks are successful because these organizations are simply neglecting best practices (e.g. patch management, whitelisting, security awareness training).
everything in corporate america is derived from the growing wealth inequality and these shake downs are precisely targetting the glut. soon enough, itll still be cheaper to have a bribe fund, just like tax evasion lawyers, lobbiests and the rest of the feeder classes than a holisitic defense.
Yes there is corruption. No not everybody is corrupt. No it does not only exist in USA nor is USA anywhere near the worst. No you can't blame anything and everything you don't like on corruption and greed.
Our healthcare, prison, and student loan systems, for example, prey on US citizens without repercussions at lengths that don’t fly in most developed countries.
I think it’s safe to say that corruption and greed are at the root of most problems in the US, and it’s important to call it like it is.
I would contend with that. The US government is just very visible. I know HN likes to glorify European nations but we're really really good at wasting taxpayer money, too. It's just less lobbying and more knowing the right people here.
I really feel this. Any new piece of software needs a level of ongoing maintenance that no one seems to realize, not even many software engineers I've worked with.
You can't "just" toss a binary onto a VM and forget about it. But all the work required to secure that and keep it secure is so invisible to management.
And because the work is invisible, it might even hamper career growth. So good luck getting either management or devs to prioritize all the security tasks they should be prioritizing.
> It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details.
So why "colossal"?
> "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency.
The BBC is going with "colossal" in their headline simply because the guy who discovered the incident said so?
You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for one of the most impactful cyber incidents yet. Hell, if you invested in January, after most of the stuff blew over, you would be up nearly 20% on your investment.
There is even a perverse incentive to not do things and just get cyber insurance to cover you. Since these underwriters generally have no fucking clue what they are doing, you can actually make money on a cyber intrusion if you play your cards right. Only now that insurance companies have paid out the nose with ransomware incidents have they started to wise up. Having worked in the space, its absolutely bonkers what we accept as normal business practices with regards to cybersecurity.
As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done. Some of these expenditure campaigns are low-visibility, some even to the employees of the company, and they are usually not very sexy or noteworthy, so you won't read about them on the front page of CNN but they do happen and they are very costly to the company (in the ballparks of tens to hundreds of millions of dollars).
I do think there should be harsher punishments in the form of fines, etc. But to say that there is "zero impact" just isn't true.
I mean, I'm looking at Solarwinds last earnings statement and comparing quarters from last year to now, they are up about 3.5% in revenue (3/31/2020 vs 3/31/2021).
I'm looking at Equifax's 2018 statements right now. With Operating Revenue of $3.4 billion and profits of $850 million, they had $400 million of expenses related to the breach. "No major impact" my ass.
Don’t you think stronger consequences than that should happen when a company unintentionally discloses tens of millions of people’s personally identifiable information that has been collected without any particularly explicit permission given by those people?
Credit agencies hold a special place in the US economy, and when they messed up this badly, the team threat of some near-going-out-of-business level consequences seem like the only way to truly get other companies to take this seriously. Especially considering that there are other credit agencies in the country - they don’t have a monopoly on this.
And you would think that given their one job is to supposedly safeguard this info, the consequences would be more severe or we would re-think this entire business model of consumer credit, but our society is not capable of that kind of consumer advocacy. Likely due to some powerful interest's bottomline.
Lets say you are a CEO: If you underspend on technology/security by ~50-100m/year, for 5 or 10 years... then have a bad breach, which costs you 400m, what do you get?
A: A Ferrari, because you saved the company 500m dollars and got a cyber insurer to pay for your technology/security program.
I'm not even joking you, I have been in meetings with a CEO, CIO and CISO, where they literally joked around that they should have more breaches because they actually made money on the intrusion and that they were able to upgrade a bunch of stuff they were planning on upgrading next year anyways.
No, it's not. Read the 10-K. It includes pages upon pages of the breach-related expenditures, including hundreds of millions of dollars spent on extra stuff like credit monitoring, legal fees, and professional services costs. That's not "just IT/overhead costs".
Just because a company was planning to spend $400 million anyway doesn't mean that having to spend that $400 million on breach-related expenses is no impact. The budget doesn't just come out of thin air, it gets allocated from other places. Spending $400 million on breach-related expenses means not spending that $400 million on something else like product development, research, marketing, or other company initiatives. The impact is enormous.
>In the grand scheme of things, it really isn't a huge impact to them.
You have no clue how businesses work if you seriously think that an additional, unexpected $400 million in expenses (almost 50% of their yearly net profits) "isn't a huge impact to them". That's really all that has to be said here.
You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building burns down.
define: impact
2) have a strong effect on someone or something.
My point still stands... If a company can weather the storm, there is no long term impact. If you look at equifaxes breach, it hasn't depressed their revenue. They haven't had to massively changed how they operate or had to pivot into new businesses. Over the long term, it has had very little effect on the company long term, which is my entire point.
I sit with CISOs daily discussing this stuff. $400m expenditures is enough to scare the shit out of them. A $400m building burning down would have CEOs fired (see: Equifax CEO being fired after breach). I don't know what fantasy land you live in, but you're either delusional or lying.
>If a company can weather the storm, there is no long term impact.
That's not what impact means.
>If you look at equifaxes breach, it hasn't depressed their revenue.
This means nothing. It's possible that with an additional 50% of their yearly net income freed up, they could have massively increased their revenue by spending that on product development or sales efforts. You cannot draw any conclusions simply from the fact that their revenue hasn't decreased.
>Over the long term, it has had very little effect on the company long term, which is my entire point.
On the other hand, it may have had an enormous impact. In a time period where every other company is seeing massively rising profits and stock prices, Equifax has been relatively stagnant. Your point has no standing.
That could be because the $400m would likely have gone on dividends and remuneration, not investment.
In what world does getting 90m $ to leave the company constitute "getting fired"? That's early retirement.
> In a time period where every other company is seeing massively rising profits and stock prices, Equifax has been relatively stagnant.
So, it will take them 2 or 3 years longer to reach some arbitrary stock price. Certainly an earth shattering experience.
Remote monitoring\management? in COVID year? just 3.5%
that's horrendous
The customers who had experience with remote work and already knew that SW products would help them in this situation was a fixed number.
The number of companies who had no clue about how to do remote work, and after haphazardly had to switch to it may still have no idea that you need to use products provided by SW.
Also do you really need any of that to do remote work?
Of course not.
More than anything, it proved that their model is flawed.
Just the number of gov agencies that are forced to stop working with them is a major blow.
I agree they are not doing well, but I also do not see why they should’ve, even if the breach didn’t happen.
Revenue != bottom line. Bottom line is profit, ie revenue minus expenses.
The SEC EDGAR database [0] is where you can find public quarterly financial statements and forward guidance from management (which will definitely mention the security breach related expenses), for every US-listed publicly traded company. Good luck!
[0] https://www.sec.gov/edgar/searchedgar/companysearch.html
>During the year ended December 31, 2020, we incurred $66 million of incremental expenses related to the remediation of and response to the Cybersecurity Incident, offset by $39 million of insurance recoveries. To date, we have incurred $138 million of incremental expenses, offset by $73 million of insurance recoveries pursuant to the cyber risk insurance coverage we carry. These expenses mainly consist of customer notifications, credit monitoring, technology costs, and professional and legal support.
Go look at Equifax's 2018 10-K and it has pages upon pages talking about the impact, including:
> During the year ended December 31, 2018, the Company recorded $401.2 million of pre-tax expenses related to the 2017 cybersecurity incident and insurance recoveries of $75.0 million for net expenses of $326.2 million. Costs related to the 2017 cybersecurity incident are defined as incremental costs to transform our information technology infrastructure and data security; legal fees and professional services costs to investigate the 2017 cybersecurity incident and respond to legal, government and regulatory claims; as well as costs to provide the free product and related support to the consumer.
For Equifax, there is also an additional $112 million (net, after insurance recovery) in breach-related expenditures in the 2017 10-K.
This was a conscious business decision to not make the necessary changes to address their infrastructure.
Losses would be their customers abandoning them in droves, or having to pay out massive fines.
It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after the public became aware of the breach, with a $90m severance package.
https://fortune.com/2017/09/26/equifax-ceo-richard-smith-net...
Equifax and the other ratings agencies have plenty of problems, but none of those problems are solved by having the government run things and many new problems would be introduced.
It is also worth pointing out that both the credit ratings and audits of publicly traded corporations are conducted by private-sector companies, not government agencies. The SEC's primary role is to ensure that the rules are being followed, which is a straightforward law-enforcement/regulatory role that makes sense for a government agency.
Do you think the abuses are any less rampant when power is privatized? The main problem that would be solved by a government institution is a pathway for transparency and citizen recourse against questionable practices. It's admittedly not a lot of transparency or accountability but it can be far more than currently exists.
People talk about government corruption and sure, there's lots of it, but there's just as much if not more private corruption hidden behind privacy protection veils. At the very least, there is some degree of transparency with the government and we can in theory hold them accountable with explicit rights granted to us (more-so than private institutions).
I cannot hold these private institutions that have gamed the system so far they're beyond my grasp accountable for their actions. Ill start a credit rating agency tomorrow and compete with Equifax, Transunion, and Experian so through market forces of competition I can fix these problems! Consumers and market forces will fix these problems! Yea, right, give me a break.
This whole government bad, private good, anti-communism/socialism/whatever argument has grown tiring because we're at a point now where you can chuck private institutions in the same gutter of corruption as different systems of government. We played that fiddle and gave private institutions the benefit and here we are, with rampant corruption in concentrated pockets of business as well, governing our daily lives with little oversight or means of recourse beyond avoiding the system or hoping some competitor can actually change things.
Privatization works well when you can actually hold institutions accountable, when there are competitors that actually compete and give consumers the option to vote with their wallets. When that doesn't exist, it's far worse than a US government agency managing it. It might be cheaper but there's probably a good undesirable reason it's cheaper than a public institution that isn't related to poor management and basic optimization practices to improve efficiency. Those efficiency gains probably exist because the institution is doing something it shouldn't be doing, focusing on profit margins over implications on the consumer.
There is no reason to think that a government agency would be any more transparent than Equifax et al. are right now. Consumers have the right to receive a free credit reporter from these companies, and the right to dispute information in that report (also free). Maybe there is a need to adjust the regulations in order to combat particular abuses or problems that are happening right now. That does bring up the question of what specific abuses you would like to see fixed -- you did not actually mention anything in particular that Equifax is doing or how a government agency would avoid such a problem.
The previous president spent 4 years trying to use government agencies to punish political opponents, and just before leaving office he filled those agencies with loyalists in an attempt to sabotage his successor, all without regard for the effect such actions might have on the public. Those are forms of abuse that is specific to government agencies and it would be a disaster if it happened at a credit rating agency. This is not an argument that the government is always worse than the private sector; it is an argument that when it comes to something like credit scores the government should not be in charge.
We don't have such databases. The difference here is that the bank's mortgage divisions have much lower profits, because checking somebody out is actually done by humans. It costs the credit provider more. US style mortgage broker do not exist.
Low- and Middle- income people here do not have houses because of high real estate prices due to very restrictive zoning (the country is small), and on average much, much, much more expensive construction than in the US. Here people expect a fully concrete house, near-to-passive level insulation, with 30-40 years free of any big renovation.
In conclusion: we do without an Equifax just fine.
It's not as good as it once was, and purchasing power is slowly but certainly going down. Everything is tightening up. Switzerland is extremely integrated into the western money circuits. If it goes to shit in the US, it'll follow suit at a much slower pace.
However, Eurasia is replete with countries which try to imitate Western European successes by applying the same receppies. If you can swing it, the purchasing power is 3-5 times larger on the same net income, and you don't have pesky invasions of your private sphere at each corner.
Also, as a Swiss, I can tell you that past the superficial welcome, we're a mountain people. We're really not as warm as others peoples. Over time, depending on your character, it may accrues and impact quality of life.
We are also very disciplined in a lot of aspects of life, even outside work. That is a problem for some over time.
But if your character fits, you'll have a blast.
You say that interest rates are not higher, but that is a meaningless statement if people do not generally buy their homes on credit. Low- and middle-income Americans typically buy a home using a mortgage, and credit scores are an important part of that system.
Your position is that the lack of a well informed credit market would make interest rates high, precluding acquisition of houses, hence the need for rating agencies.
My position is that truthful, complete information is enough to keep rates low, a market for that information is not necessary for assets which are not liquid (houses, mortgages). Swiss mortgage rate oscillate between 1-1.5%, depending on your financials.
Absolutely everybody buys houses and buildings on credit in Switzerland, due to huge tax deductibles. Those who don't are a rounding error around 99.9%, mainly due to some rare people's estate planning triggers.
Selling cheaper houses and apartments at lower prices has been repeatedly in the last 20 years (as low as a third of the usual price range). They doesn't sell.
Swiss are conservative, they tend to like long term investments with low degradation risk, regardless of current market price levels. Hence high prices, because they want high, long lasting quality.
Again nothing to do with credit information markets.
Background checks and investigations, healthcare related policy information, etc. e-QIP, managed by OPM specifically, collects a lot of highly sensitive information on federal employees working in the national security ecosystem was hit:
I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin.
The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!"
I sometime find wisdom in the approach from olden times :-)
The OPM hack wasn’t ‘snuffed out’ by any means - it was fairly well covered for a cyber attack of it’s era. Perhaps it wasn’t covered much in your part of Eastern Europe, but it was definitely not covered up.
The fact that some people have forgotten about it is a completely different issue.
But it's true that I don't remember it at all, even though I worked in a field parallel to CompuSec and usually notice those events.
Major mission critical systems are managed by the country's Ministry of the Interior, and haven't had a major hack (yet), as far as is publicly known.
And besides, how are those poor souls gonna connect to Facebook during their mandatory 10 o'clock coffee pause ?
It's always such an odd criticism to think of "shareholder returns" as a pejorative.
We have 20-30 years of data on cyber attacks and Cybersecurity is not that important - https://ubiquity.acm.org/article.cfm?id=3333611
Larger the dumps get the harder they are to exploit or do serious damage. I can hand you all my orgs data and 200 people who work with it everyday and it will still take you years to figure out what anything means.
VMS now "open" and recently running in a VM on Xeons.
I have always suspected that the silence that resounded suddenly about security prowess of VMS coincided with the release of extensive POSIX compatibility layers and the vaunted ports of years old open source nix wares as a excuse to play buzzword bingo at that time. But anyone writing a native VMS application I'd firmly embraced by a deep architecture designed to provide accounts for the time when DEC silicon and their own leading fab was creating a explosion in processing power and the number of users capable of being supported by a OS that has still incredibly well integrated system programming tool chain languages including Digital BASIC that can do about anything BLISS can low level. This virtually (sorry) made it a overnight imperative to get the security right and tight. Alpha had hardware security rings almost certainly to give VMS the chance to serve the maximum number of users and steal account wins.
Ye what are you supposed to do with the information. I worked at a place that is paranoid for data leaks of non personal data, like source code.
Even if their direct competitor got the sources they would have almost no use for it since it is an undocumented mess. The source without the dev. departments is useless.
The same applies for business strategy if it leaks. Which competitor is nimble enought to change anything based on that data.
As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market.
SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time).
Insurance is a trap. once you read the small letters, they don't fully cover the damage, usually only direct. Some have refused to pay due to some shady conditions that they insert into contracts to deceive customers(like any other insurance sector)
Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.
We can definitely build castles in the air for two years.
I dont understand the problem with inflation..
People short-squeezing stocks, shooting their "value" by 30x in 2 hours making them millionaires.
Hedge funds manipulating stocks to meet their portfolios
IPO's in billions of dollars for new, non-profitable startups just because of hype. when you look at the balance sheet it makes no sense.
The market is volatile and inflated, it is as clear as day. Whether there will be a crash? that's beyond my level.
No it's not. The performance of stocks was always only weakly linked to actual company performance.
There are countless examples of companies that are hardly profitable and not even a tenth the size of their competition, but are valued at twice the price of some of their competitors. It's mostly made-up prices created entirely on hype that often make less sense than the soccer trading card market.
I disagree with you on SolarWinds being fucked... Sure, lots of folks are going to drop it, but they are closing new deals. The types of people that buy things like SolarWinds aren't buying the products because its a good technology.
Not sure what insurance you have been looking at, but many of the larger businesses will essentially write out what they want covered (for example IR, infrastructure replacement due to hacking, business loss due to downtime, professional service implementation, support, PR assistance, etc.), and then the insurance company will come up with a price based on their calculations of risk.
Sure, if an SMB goes and gets a "cyber policy" they are gonna be lots of technicalities, just like a mass market homeowners policy.
Being bad at your job is not negligence, nor is underestimating the threat.
It’d be nice to see consequences but I really don’t want to have the government locking people up for being well-paid fuck-ups.
Don’t some of these companies have… shareholders?
I think there’s a (very simplistic) view of IS, where it’s a black and white process of just engineering everything ’correctly’. It’s not like that in the real world…
If you go to a doctor and he fucks up: he (or his insurer) has to pay you. If he really fucks up, he ceases to be able to practice medicine.
The same with nurses, lawyers, accountants, architects and other professionals.
Software's much better—then they point to the "we take no liability for any errors" clause in the contract and everyone carries on as if nothing ever happened.
I think a top down approach to enforce anything at scale is never gonna work until people decide to respect their place in the world and do the due diligence from bottom up
Those negligently responsible should be fined and go to prison for leaking private data, endangering physical safety, possibly for compromising national security, damages from the toxic sludge they produce etc.
Note that the US does deploy it's national security forces to fix some of those fuck-ups, and at least threatens to use physical forces, so it's not just a private or civil matter.
Some jobs come with certain responsibilities. Of course we need to have some leeway for e.g. doctors making honest mistakes – they're only human after all – but at some point that stops.
It's quasi-monopolistic. It has the same problems : nobody gives a flying furry about actual performance.
A 1977 case precedent established in the event that a director relies upon the advice of a accountant for making company directions, he or she will be liable to be banned from holding a directorship for life. The appeal failed. This is because the only essential role of a director is to be themselves a competent assessor of the company affairs.
If you can't knobble the board of a UK limited liability company for letting go their own primary competitive asset (the more important consideration for the law designed to govern the behaviour of directors in fulfilling two goals : justify public indemnity to the extent of any shares they own in the company in the event of collapse ; and do their job without prejudice to the shareholders or the crown treasurer to pay negligence.
Summary criminal charges are convicted on bringing proof and a judge not being shown disproof. Criminal intent doesn't come into it.
Yeap, I did that with Ubiquity after their incident. Bought at $275 and the stock now is 12% higher. Seems like a good strategy, and I'm looking forward for similar incidents in the future.
Exactly right, and eventually they will GET A CLUE, and require serious security audits to get a sane price on incident insurance. Otherwise they will make you pay gobs and gobs of money, and it will just be cheaper to be sane about your security posture.
Otherwise there is zero incentive for the insurance companies to keep paying out the nose on policies they aren't making money from.
This has happened to police stations, as they get mismanaged by idiot police chiefs, the insurance providers say.. uh we aren't going to insure you anymore unless you fix your sh*t. As but one example: https://www.theatlantic.com/politics/archive/2017/06/insuran...
I see this happening to cyper security policies also, they(insurance companies) will wise up or go broke.
Nothing will change until government regulates it. Same with auto, airlines and rail. They did not make their products and services safer by choice, they were regulated to do so.
strategy: find SaaS corps responsible for catastrophic cyber-attacks and buy them on the the dip?
tl;dr tl;dr REvil just pulled off a colossal ransomware supply chain attack” @vxunderground
Thread includes samples.
https://twitter.com/vxunderground/status/1411058433558786049...
I used to run a small security consultancy and nearly got into this business to expand our operations and get some of that sweet sweet recurring revenue. The problem I found at the time was that none of the software companies selling products that I would use were building in a security posture that I was even remotely (hur dur) comfortable with.
These are what they’re sold as and literally what they’re used for daily to manage and monitor thousands upon thousands of endpoints of all flavors. In a traditional on-prem Windows corporate environment these functions would have been offered by the on-prem Microsoft stack like domain services, group policy, WSUS, SCCM, SCOM, RDP, etc., and the overhead was enormous. In a diverse and dispersed environment, these toolsets have adapted accordingly - multi-platform, over-the-air, asset light. Now even internal enterprise IT shops use flavors of RMMs that MSPs would use for SMBs. MSPs can simply apply these systems to more SMBs via economies of scale, whereas an SMB could rarely afford the overhead of maintaining the tooling let alone the circus that is device management. So if you break an RMM platform used by an MSP the impact can be quite broad, and include larger enterprise IT operations. It’s easy to say “don’t use RMM tools, or switch to Macs”, but this kind of simplistic reaction belies an understanding of the environment and the need.
The same sort of software is used by all governments and corporations.
I've been told several times this is because AppSec is considered by higher management to be mostly a clerical type position or at best, Application Support. Which would be fine if that were the level of experience and bundle of skills they were trying to hire, but it's not. What makes things even more difficult is that many companies have a policy of only hiring citizens and permanent residents for these positions but have outsource rates floating in their heads.
If you want to have an AppSec group populated with people who can explain (and often argue) security vulnerabilities in the code of others, you're going to have to pay for someone with enough experience to do so credibly (or you'll lose buy-in from developers) and knowledgably (so you're not wasting developer time with false positives).
( Not saying this "colossal" one was state sponsored :-) )
"The Lazarus heist: How North Korea almost pulled off a billion-dollar hack" [0]
[0] https://www.statista.com/statistics/701020/major-operating-s...
https://www.zerohedge.com/geopolitical/cyber-polygon-will-ne...
Intel without ME
AMD without PSP
Work for a better future with a fully open chip architecture
Given the fairly vocal resistance to the TPM 2.0 requirement, if the answer is nothing, then I wonder why it is even necessary.
As a Mac/Linux user, I’m out of the information flow on this topic except for a surface level understanding, so please person my ignorance, as I’m genuinely curious.
Some form of remote, unauthenticated SQL injection then?
1. https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e
> We are severly fucked. Up to 2100 endpoints are infected right now, most are desktops but also servers.
> We have been hit as well 1000 endpoints. What is your plan of restoration?
Happy 4th of July weekend everyone.
If every CEO and CFO's first priority is "How do I not go to prison?" and the second priority is "How do I enrich shareholders?", then security _will_ be fixed. Simple as that.
However, in general I wouldn't be so fast to blame victims. Strong security isn't cheap nowadays and adds to cost of doing business. To make things worse, cyber-attacks become increasingly more sophisticated, so the "security tax" will only grow and fewer organizations will be able to afford it. That's why consolidation is inevitable - it will just become more economically reasonable to share the cost of cyber-defense.
And how do you codify that? It’s possible to be breached when following best practices and doing everything right..
Who is the bad actor here?
I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware compromise to date.
copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe
Why append a random number to a copy of certutil.exe other than to change the file signature?
Making a copy with a new random name defeats this detection logic.
During obama administration companies were reluctant to go after culprits. i think they do not deserve our sympathy now
1. Any company that makes software with low-level access to systems (i.e. admin privileges on Windows, root privileges on UNIX systems) is criminally responsible for any security breaches of its software, unless it can prove that it took all reasonable steps to keep their software safe.
2. The CEO and CFO will receive a mandatory 30 day jail sentence on the first instance of a breach with consequential damage.
3. The jail sentence will be tripled if the company downplayed or omitted to report any security breaches.
4. The minimum sentence increases by 30 days for each subsequent breach linked to an executive, and resets after 10 years of no breaches.
This sounds like a concession of major weakness on the part of the US. I guess we already knew that Russia has outmatched US’s cyber capabilities, but I was surprised to see it acknowledged by Biden in this way. And if Russia ignores this edict, it means they’re doing so in the full knowledge that it may be seen as a declaration of war? Which would lead the US to respond with its own war-like actions? High stakes.
Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)
Instead of crypto-randomware, it would be an all out worm or booter that would crush a service who would have to acquiesce to demands. Luckily, there weren't too many good services in existence, Cloudflare didnt exist, c10k was a mind blower, webdev was AJAX, XMLRPC, and CGI. The term TLS hadn't been coined, it was still called SSL, and nobody used it.
Instead of a money orders, they would trade trade calling cards, NEXON codes, gift cards, other stolen data like "fulls" or exploits or accounts for compromised infrastructure.
People would operate DDoS botnets for cash, spam you with V1@GRA ads from cracked boxes or hijacked relays, and the evergreen scam of fake RMAs. Let me know if "LOAD A PALLET OF CATALYST CHASSIS ONTO A BOAT OR ELSE ILL RELEASE YOUR SERIAL NUMBER DATABASE AND ALGORITHM ON MYSPACE" sounds scary or not.
The real difference is now we're 28 years into "Eternal September"[0], the whole planet is participating more or less. Cryptocurrency is possibly an enabler, but if it weren't that it would be Apple or Google Play codes. Just straight up exfil and sell.
In conclusion, these attacks didn't happen before Apple store or Google Play.
I don't think Apple or Google credits would be effective for large-scale ransomware. Not anonymous, could be stopped by a slightly-motivated central authority. It works for preying on individuals, however, because they don't have enough clout to force the issue.
The workflow is:
Target->Crack->Retrieve->Store->Sell on hackforums
Maybe there is a way to automate this old school method, but nobody developed it because why bother.
e.g. this 2013 article from a quick web search, where the payment method dropdown contains Bitcoin and MoneyPak payment cards: https://arstechnica.com/information-technology/2013/10/youre...
I don't have any hard evidence but I'm sure you could find some. I certainly don't remember ransomware attacks being very prevalent prior to last decade. They all seem to request cryptocurrencies (I can tell you're a coin head because you refer to them simply as crypto).
Without cryptocurrencies ransomeware would largely go away. Sure there'd still be cybercrime, hacking, data breeches etc...
I remember that Walmart or the govt or both made some change where these didn’t work the same way and lost their shine for ransom payments.
Thin on details but the as I recall the options for paying ransoms easily prior to crypto were tightening up.
That said, I’m 100% against the idea of fighting crypto to solve this problem. The liberty of humanity needs anonymous cash despite the risks that come with it. Better to address these problems on the data security and resiliency front.
Judge me how you will, however, I do think I see your point that crypto might be contributing to this new form of extorsion. I was only trying to get more detail. Which has now been provided.
One way is to demand that a smaller amount of money be wired to 1,000 accounts throughout the world.
You — the bad guy - own merely one of them.
Difficult to trace them all before you empty your particular account.
BTW are most of these hackers transferring to fiat through U.S. exchanges? I can't imagine that's the case but maybe it is.
Drugs (and yes, earlier, alcohol) present kind of an unique situation with respect to noncompliance with the law; not sure I can see the case for suggesting the government is destined to fail in enforcing the prohibition of anything whatsoever.
ION We may have underestimated the depth of the solarwind attack back in late last year.
I don’t understand how Putin can stop these attacks unless he is personally responsible for them.
Imagine someone in the US hacking systems in Russia or China. How in the hell Biden would know who did that and stop them?
The naivety of US government is just astonishing. I’m sure Putin just laughs when he hears such accusations.
We can’t stop these attacks by asking people not to exploit the systems. We can only stop then by building more secure systems and improving the processes within organizations.
Why do you think he wouldn’t do so? American sponsors the same cyberattacks on Iranian and North Korean entities.
Imagine if Merrick Garland announced that he was using prosecutorial discretion to effectively decriminalize cyber attacks on foreign countries as long as they didn’t affect US interests and the best of its allies. The federal government wouldn’t need to fund the entrepreneurial ambitions of the US talent pool. They’d self-fund and make a mint in the process.
It’s privateering of the modern age. So Putin only “funds” them in the sense that he allows them to operate, providing them implied letters of marque.
By providing cybercriminals a safe harbor to carry out their attacks.
By refusing to cooperate with foreign LE unless they have targeted RU citizens.
By using the LE/MLAT requests that are sent to them to track down these criminals and force them into moonlighting for state intelligence services or be arrested.
Or at least that's where we're headed if companies keep giving in to the ransom demands.
The delicate ecosystem of the unwatched computer.
But if REvil etc. are going to branch out like that, they really need to follow the traditional protection racket and engage in, let's say, aggressive counter measures with the potential for rapid bodily disassembly of any competitors that come along.
Or better yet, what happened with privateering amongst the nations in history? First each nation unleashed its own privateers, then they built up and deployed their own navies, and the countries that couldn’t keep up fell under a new Pax Romana aside from fits and struggles. Where are we in this process today?
I don't want world War 3 over stupid ransomware because of bad sys admin work and some stupid criminal groups.
We should stop with this blaming. It is in Russia and other states interest to stop the ransom attacks even if they may be coming from some small group of people in their country. They have just as a hard time finding these criminals than we do finding them in the US.
Russia isn't really that big a player globally (GDP quite a bit less than Italy's for example), but they've realised they can wield a substantial amount more power by just chaotically screwing things up for their opponents.
It's the same pattern in their cyber attacks, election interference, middle east policy, online disinformation spreading, etc etc. None of it's directly for their own benefit, it's purely to harm opponents.
Nominal. Closer to Germany if we are talking PPP and notably higher than Italy of course
So yes Russia might be blamed as they consciously choose to let these guys do their thing. China and NK do the same, as do US, UK and Israel with similar stuff on the other side, done by NSA, CiA, etc
Any attempt to avoid conflict under the guise of avoiding current hot war actions is merely understood by these actors as weaknesses and permission to take more territories, libreties, and/or criminal actions. This will eventually lead to conflict, and the longer the delay, the larger and mor damaging the eventual conflict.
If you want to avoid large war(or even "WW3"), the solution is to take serious diplomatic, financial, and kinetic (all 3) actions immediately, si that the perceived costs immediately escalate beyond any possible benefits to Vlad and his ilk.
If you want more information, read people who have a deep understanding of the situation and have skin in the game, such as Garry Kasparov, former world chess champion & Russian presidential candidate currently in exile, and Bill Browder, former Russian investment fund founder & progenitor of the Magnitski sanctions being effectively deployed around the world. Both have been there, done that, and buried their friends for their efforts.
Peace is a wonderful goal, but not at the expense of allowing autocrats & criminals free reign - they will stop at nothing and eventually take everything.
Here's a list of popular Ransomware onions, REvils is called "Happy Blog" https://www.kiledjian.com/main/2021/3/4/popular-ransomware-d...
It's hard to guess how big REvil would be. From their job ad -
"Teams that already have experience and skills in penetration testing, working with msf / cs / koadic, nas / tape, hyper-v and analogues of the listed software and devices.