A Modest Proposal About Ransomware
blog.dshr.org
blog.dshr.org
This is the "Encryption Backdoor" problem in Computer Science (aka "Exceptional Access System"). It is impossible to build an exceptional access system and then ensure it is only used by good people to do good things.
At least with remote management, you can respond at scale if one of those gets compromised.
Yes, it is more difficult to manage a diverse environment, but when you survive the next big ransomware attack you'll see why it's so important (while your competition struggles to recover).
This holds true for crops, people, animals, financial investing and everything else. Diversity makes us strong and resilient. Monocultures make us weak.
Monocultures are easier to manage, audit and predict, but their weaknesses outweigh those benefits IMPO.
I know how to configure a firewall on linux. I don't know how to on plan9 and windows.
Should I run Windows, Plan9, Solaris, FreeBSD, NetBSD, and Linux on my 5 servers to ensure I have diversity?
To me, that makes it seem 5x as likely that I make a configuration error that leads to a critical vulnerability if I have to figure out 5 different ways to setup a firewall and sandbox.
What about using software that historically has been shown to have vulnerabilities? For example, wordpress has had a lot of vulns in the past, so should I host one of my blogs on ghost, one using jekyll, one using wordpress, or should I only use a static site made with jekyll because I know static sites are more secure?
If I'm allowed to eliminate wordpress there, why can't I eliminate diversity at other layers? I know linux is more secure than windows IME, so can't I just not run any windows hosts by the same argument that I won't use wordpress?
You mentioned "diversity at every level (network)". Do you mean I should run wireguard VPN for some of my networks, cisco for others, unencrypted for others, just so I have more diversity?
I'm genuinely curious because the model I've heard advocated so far is that a monoculture is more secure because you can eliminate less secure things (use wireguard instead of unencrypted traffic), and gain mastery of a small surface area to ensure it is harder to attack.
Adding diversity just for the sake of it, by its nature, adds more attack surface and requires more expertise to secure, so it seems to fly in the face of the common advice I normally hear.
Running Windows and Linux would be a good start. Plenty of business-y software runs on POSIX systems: perhaps your business processes don't have to run the same operating system as your desktops?
Having a file share appliance (e.g., TrueNAS, NetApp) would be a good step after that (if things get encrypted just revert to the last snapshot).
The parent poster is arguing for diversity for the sake of it. To me, moving from my linux monoculture to a linux+windows diaspora seems less secure.
I'm talking specifically about the idea of security through diversity, not about this specific incident, so backup recommendations aren't really related to this thread.
No. At the scale of five servers, a monoculture is acceptable risk, and as long as other businesses at that scale are choosing different monocultures, the systemic risk is limited as well.
But in analogy to agricultural monocultures, larger fields make monocultures more dangerous, and many adjacent fields with the same monoculture increase the risk even more.
But geographic continuity isn't necessary in our networked world, so the analogy is of limited use, and any vendor with enough customers, no matter how spread out, makes an attractive target.
On the other hand, a leak or breach of user privacy requires exploiting any single system containing the data. Putting the same data on a diversity of systems makes that easier, and you won't even know what's happened if you've made it too difficult to "manage, audit and predict."
Avoiding a monoculture isn't the security magic bullet you pretend it is.
Fixing small issues, on-boarding new people, explaining existing setups to already employed, adding new servers. That is nontrivial amount of money burned there "day in and day out" when networks are monoculture with centralized access. Making it a little bit of this flavor a little bit of other, will make those costs grow 100x in no time. This way you have 100x operational costs to prevent something that may or may not happen.
Having messy environment also brings other risks like some operator might mess up easier because of being tired fighting that mess.
I find it hard to blame them too much for unexpected unadvertised technical problems.
I propose something simpler: disconnect most computers from the internet, and don't put them places strangers can access them. Then build out the tools that work in that environment.
I don't actually think it would work in practice, though, because it's a race to the bottom. The company continuing to do all their shit over the public internet with commodity PCs is going to be doing things more quickly and more cheaply initially, and may thoroughly beat the competition before getting hit by an attack.
As ridiculous as this sounds, a private sector version could work. Imagine 'hacking' companies that audit municipal services and private companies. The hackers would have to be motivated to win, by payment, not just go through a security checklist. Insurance and law could demand this sort of active and ongoing security check. This would also create diversity in hacking systems instead of one governmental set of tools and strategies.
This does already exist, to a limited extent, as the security bug bounty programs that some companies have on public offer. For example, Amazon says they'll offer you $15,000 if you find a "critical" security bug in one of their services; Google offers up to $31,337 for discovering a remote code-execution bug. https://hackerone.com/bug-bounty-programs
None of this solves the problem of zero-days either. The only thing that I know of that sometimes could work against zero-days are intrusion detection/anomaly detection. They do not guarantee that you'll be able to stop the intrusion in time though, especially if the entire attack is automated or really sneaky, masquerading as normal users or third party vendors. An automated IDS that can halt an attack is a very risky thing; change your business practice one day and that could shut down your network meaning you just attacked yourself. It could be purposely triggered by an attacker also as a denial of service.
The only ransomware solution I can envision is gradual hardening, like in the old days of Sun workstations and how airplanes became so safe. Make only small incremental changes and respond to feedback so over time the system gets more and more secure, until everything is just secure by default except when rare new vulnerabilities are discovered (new zero days, but if the system doesn't change much they should get rarer and more difficult to discover with time discouraging people from trying to find new ones). This is expensive and takes time and kills innovation, but I don't think there is a quick fix. So reserve/require it for critical systems and let innovative systems be more subject to failure and attacks. The first step would be deciding what is critical (the power grid? facebook? your grocery store IT system?) and hence should be required to follow this practice. Eventually even the more innovative services will benefit from using some of the well hardened systems. Ransomware will run rampant meanwhile, diminishing with time. I view this as similar to global warming, there is not just one problem, there are thousands of problems in networks, computers, OS's, apps, services, and users, and it is not going to be fixed with a patch (especially when patches are also an attack channel). Big companies probably already do something like this (hence they continue to use Windows NT or DOS or invent their own flavor of Linux), but this is also something that should probably be a government requirement for the grid, chemical plants, ISP's and anything we can not risk having fail.
Besides, unless 2 or 3 execs can also implement the recovery procedure without any of their engineers catching wind I don't think it's likely that the secret would remain well kept.
Right. Humans don't strictly adjust their behavior according to the game theoretic adjusted risk (penalty × probability). Raising the odds of getting caught tends to work much better than increasing the penalty.
That said, one of the outgrowths from this observation has been Broken Window Theory (that credits a drop in larger crimes to increasing enforcement and speedy mitigation of other - highly visible - minor infractions), which turns out to be more of a just-so story. You mostly have to increase the odds of getting caught for the crimes you are most interested in deterring rather than something else.
[1] https://en.wikipedia.org/wiki/Foreign_Corrupt_Practices_Act
[edit] URL: https://www.sec.gov/enforce/sec-enforcement-actions-fcpa-cas...
I do think regulation making ransoms hard/impossible to collect is the way to stopping the immediate problems posed by ransomware.
More disturbingly, however, is that such hacks just underpin how vital infrastructure is exposed to nation states. When the motivation isn't collecting a ransom but rather to disable a country's vital infrastructure, such regulation would do little.
That's rather difficult to do in the current cryptocurrency environment.
But if the attack is an automated bulk exploitation of thousands of computers all around the world - why should an attacker stop targeting US computers just because US companies are banned from paying?
I think people also have this strange idea that the bitcoin ledger must represent all bitcoin transactions. But think for a minute that I can just email you a wallet and the coins just changed hands without putting anything on the ledger.
I won't trust that you destroyed your own copies of the keys, so I'll want to transfer the coins to another wallet first thing with a real transaction recorded on the ledger. Otherwise I'm risking that at any time you could take the coins back from me.
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
https://www.wired.com/story/the-full-story-of-the-stunning-r...
https://en.wikipedia.org/wiki/2020_United_States_federal_gov...
Couldn't attackers still say, "Go get some BTC and deposit it. Where do you get some? Not our problem."
Maybe there's something I'm missing.
The US has now made paying bribes in other countries into US felonies. So now US companies do not pay bribes if they are sane.
So sure, an attacker could say "Go get some BTC and deposit it. Where do you get some? Not our problem." But then the executive in charge would have to choose between (1) committing a felony with jail time attached for him or (2) possibly going out of business and finding a new job. For sensible people, that's not really a choice.
Seems like you sweep up a lot of innocent consumers who just want to use bitcoin, and if paying bribes is already illegal I'm not sure what additional incentive this adds.
I guess my point in this post and prior was: paying the bribe is the problem, not the medium they wish to use to transact.
This is totally ridiculous. If anything, the US government needs to hack people less, stop dropping broken DLLs[1] and focus on defense. Security needs to be built up and incentivized, not punitively broken down. Practically all of the organizations hit by these huge attacks were not doing basic measures. Many of them not by CVEs from this year as this post implies.
It also isn't even "ransomware" in this case since there's no ransom. It's just the government hacking your computer because the military-industrial complex (MITRE) doesn't like you. No hate towards them or CVE, but that's not a good look or policy.
---
[1] https://blog.malwarebytes.com/threat-analysis/2021/01/cleani...
Very creative. It might also be done better with an open market where companies set the price there’re willing to pay for red hats.
This also requires some understanding of how zero-days come to exist. Briefly, insiders, many of them foreign assets developed from their earliest education and helped along the way to get to their target. There are some ‘in the wild’ discoveries, but the sophisticated attack chains do not rely on luck.
Given that, here’s another viewpoint: $70m in ransom might be a far better deal than exploitation by a nation state. It’s quite possible that these guys are actually defectors doing us a favor.
So, we should consider that security is something we’ll have to pay for one way or another, and we should seek to establish markets that make that cost predictable and minimize disruption. And yes, I do understand the moral hazard this would create, and I don’t have any good ideas to fix that right now.
The author too charitably positions NSA here. When one considers the hoarding of 0-days, weakening of encryption standards, wrecking trust in US businesses by forcing compliance, failing to intervene in years of breaches, and many other malicious activities, it soundly refutes any claim of concern for protecting the country. How many billions has this cost in business terms, on top of the billions they're paid for the privilege?
So if defense isn't their actual mission, maybe it's actually population control.
https://reason.com/2014/07/11/total-population-control-is-ns...
I wonder why it is presumed that the US has the best cyber-warfare capability? Why do we think this is true?
Whether it's true or not doesn't matter. I don't think you'll find many countries making claims of weakness on defense-related topics. In the same way that no country would just announce that they have the 11th or 12th greatest military in the world, they'd never say they have the 2nd best cyber-warfare capability either.
But then we like to walk softly and carry big sticks :)