CryptoLocker's crimewave: A trail of millions in laundered Bitcoin
zdnet.com
zdnet.com
Let's face it, computer security has been pretty bad trough pretty much the entire personal computing era. I don't need to point any fingers, the guilty know who they are.
Now unlike some others, Apple and Linux do try to do a few things about that, in different ways, with varying degrees of success. But it's better, by far, than the teeming mess on that other platform we won't be mentioning.
I believe if we want to use IT in the future, that this stuff's got to get pretty much bullet and foolproof. And without a credible threat it won't get there. Now, one of the things that held the development of a credible threat back, was the limited ways in which security holes could be monetized. "Fortunately" that's no longer a problem.
And now that I think we have a credible threat. Will we now, please, with suggar on top, get computer security right? Isn't like, kinda time?
These people must be getting the money out somehow via the visible blockchain.
Not really holding out much hope though.
It's pretty likely that the major reaction to crypto locker will not be "darn it, let's breakout a can of OpenBSD on our systems." It will be let's buy more norton, let's disconnect from the Internet except Wednesdays, let's print out our important emails.
Anyway I still really really struggle with how anyone can get stolen / hot money off the block chain and into their hands, cleanly. There is a limited supply of fools who will accept 10M from a Nigerian in return for laundering it.
I don't have the time to find the exact reference I'm thinking of right now, but consider taking a look at one of the papers that give a background to CapDesk [5]:
> Which addresses, among other things:
> "All Windows and Unix operating systems (referred to as “Winix” hereafter) utterly disregard the concept of POLA [Principle of Least Authority]. When you launch any application—be it a $5000 version of AutoCAD fresh from the box or the Elf Bowling game downloaded from an unknown site on the Web—that application is immediately and automatically endowed with all the authority you yourself hold. Such applications can plant Trojans as part of your startup profile, read all your email, transmit themselves to everyone in your address book using your name, and can connect via TCP/IP to their remote masters for further instruction. This is, candidly, madness." [6]
Since then, things have changed slightly - UAC under Windows, for instance, means applications now only have the ability to steal and hold your highly valuable and personal documents for ransom, but hey at least these sneaky trojans don't have admin rights! Which is of course the exact scenario that Cryptolocker happily exploits.
There's really no reason a piece of junk attached to your email application should execute any more authority than you explicitly grant it. (And no that doesn't require clicking a bunch of buttons to "Allow" access -- intelligent UI design can make much of this completely transparent, provided the host platform is capability-based.)
It's not that companies like Microsoft aren't well aware of capability-based security [7], it just seems to be that the appetite isn't there to really solve user's problems (breaking stuff like the Start Menu appears to be more important), despite the valiant efforts of some really smart people [8]. To be fair, shifting to a capability-based system would be a significant engineering effort, but definitely well within the realms of Microsoft or Apple's capabilities.
(Interestingly, some of the ideas on erights.org were influenced by Nick Szabo, who created "Bit gold" and who a few people think might be Nakamoto himself [though he denies it] [9])
[1a] http://www.cis.upenn.edu/~KeyKOS/ConfusedDeputy.html
[1b] http://erights.org/elib/capability/deputy.html
[2] http://www.cis.upenn.edu/~KeyKOS/Gnosis/Gnosis.html
[3] http://www.cis.upenn.edu/~KeyKOS/Key370/Key370.html
[4a] http://www.skyhunter.com/marcs/capabilityIntro/index.html
[4b] http://erights.org/elib/capability/3parts.html
[5] http://www.combex.com/papers/index.html
[6] http://www.combex.com/tech/edesk.html
[7] http://research.microsoft.com/en-us/projects/singularity/
[8] http://en.wikipedia.org/wiki/Capability-based_security
[9a] http://erights.org/related.html [9b] http://unenumerated.blogspot.com/2011/05/bitcoin-what-took-y...
I think that's actually a bigger problem than you make it out to be. Probably because people involved in this particular field tend to be dismissive of "lusers" and "marketing", it seems to me that almost every security tool out there has terrible UI. Just think of GPG, something we know we should be using since, uh, the 90s? and still nobody really does, because even just managing keys is a total pain in the neck. UAC? "Oh, I'll just click Yes all the time". Mobile apps asking for extremely-granular permission to marry your firstborn child? "Yeah, I'm sure they don't really need it, whatever".
Building secure systems is hard, but building secure systems that users will use in a secure way without having to think about it is much harder, IMHO.
I think Android security has proven to be pretty solid - there have been a few spyware apps, mostly killed quickly, but nothing that was able to spread on it's own like the big desktop viruses.
One thing that I'd like to see added that Android doesn't seem to have right now is a more limited Internet permission. Right now, apps have to either request full permission to send and receive anything on the internet, or no connection at all. Why not a permission to communicate only with specific domain names? Like Evernote can request permission to only communicate with addresses resolved from evernote.com, instead of anything on the internet. It might also have the effect of pushing apps to use the Android ad API instead of their own.
What is needed, is for trusted third parties to verify if a given list of permissions is needed, and give (via a security software add-on) a popup with an assessment of how safe it is to install that app -- green, yellow, or red, for example. That is about the only thing that most end users (and even busy geeks) can really comprehend.
Capability-based security is ultimately just another buzzword, no more of a perfect solution than any of the others. I don't think you can call any type of security problem solved by your pet technology until it is deployed at scale in the real world and proven to work. Until you have had tens of millions of users and hundreds of thousands of developers bashing away at it for years, you just don't know if you've really solved the problem.
Android's capability-based security is good, but IMHO the more important security innovation is secure app-specific data stores. You might request more permissions than you should, and some clueless users might install it anyways, but you still can't ever get access to the data or credentials stored by the banking app, the social media app, etc.
I don't have much experience with iOS, but I expect it does something similar.
The challenge is more widely used apps that ask for permissions that make no sense to me as a developer. App developers should be able to provide a justification for each permission.
Ideally I'd like to be able to reject specific permissions, and the app should just tell me what functions are disabled... or I'll take my own risks.
Basically, IMHO, Android permissions is almost as broken as UAC in Windows, with all but a very small % of people actually reading and bothering to understand application permission requests.
Starting a Disney game has Windows ask if you'd like to hand over your personal identification (age, gender, location, some other stuff) or not.
In my limited experience, it seems apps work if you deny the permission (I'd hope MS enforces that via the Store approval process). And having an in-your-face dialog that you can dismiss without penalty is far better than "click yes to continue" installers like Android.
That would seem to be a bit meaningless, since the same people that control Evernote also control evernote.com, so if they want Evernote to connect to some other place they can easily add a name for that place under evernote.com.
The problem isn't technological, it's how to pitch programming-level permissions to end-users without overwhelming them. And then hoping to get them to make informed choices.
I've seen Linux users blindly take patches from a mailing list and apply and then recompile a certain software - considerably more effort to run arbitrary code than the average user will put up with. I don't believe there's any real solution to get users to make intelligent decisions about execution policy.
So far, the only thing that appears to work is to simply limit what users can execute.
Yup. This is really the only 100% way to have control over your stuff, local, physically separated storage.
> notice that something has gone wrong sometime between when the infection starts and when you connect the drive.
This assumes a chronological/incremental order for complete backups, which in practice is lazy and not related to the value of your data. Your only enemy should be the hardware. Dealing with the ugliest virus/worm/trojan turns into a mere nuisance when you have that kind of headroom.
Look, if I think I'm safe from being punched in the face, and someone says "we'll see about that!" and punches me in the face, they haven't done me a favor.
If we didn't have immune systems the species would have long been extinct in the primordial soup. Strong systems are built from living in a hostile and competitive environment, not from living in a utopia like the first academic computer systems lived in. We have to go through these growing pains at some point.
You can't have your cake and eat it too.
Still, it is a mere slap on the wrist that is guaranteed to have no permanent repercussions to deter such behavior. It's a clusterfuck and I don't see a solution emerging without both the war on drugs ending and multi-year incarceration becoming mandatory for financial crimes.
> Disabling
Or alternatively, just not enabling tougher controls. There's no evidence, or indeed suggestion by prosecutors, that controls were deliberately set low to deliberatly faciliate money laundering.
The only people making cash deposits of this size, in Mexico especially, are drug cartels. The HSBC employees at the branch knew what this money was.
I wish there was an "only run Microsoft approved applications" option I could enable for my parents. Kind of like OS X's Gatekeeper.