Nokia 'paid millions to software blackmailers six years ago'
timminspress.com
timminspress.com
http://www.irs.gov/publications/p17/ch25.html#en_US_2011_pub...
A solid showing by the Helsinki police
It also had to be a pretty big vulnerability for them to have to pay that much in the first place.
At least the money exchange took place in Tampere.
In Finnish: http://www.aamulehti.fi/Kotimaa/1194907965691/artikkeli/mtv+...
Or a very well planned getaway. Given that the culprits managed to steal Nokia's signing key, I suspect they knew what they were doing.
Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on?
... makes me wonder what else we don't know about all the other vendors...
It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.
Also, for those that still remember Heartbleed, read again the above comment and think what embedded hardware is running around you. It is a bit scary.
I recall doing an s60 software upgrade and having it crash halfway through, which somehow bricked the baseband and the operating system of the device. Go figure.
Imagine, for example, openssl being told about the heartbleed vulnerability, then being pressured into paying big money to prevent disclosure, and then keeping their mouths shut about it for six years. Except this is even worse because at least then someone could look at diffs. I can't even think of a proper analogy here.
Back in the day, I had an S60 phone but no way to even connect it to a computer to get the firmware.
Heavily control and packet sniff anything moving between levels.
If that were the case, they didn't buy the promise the evil doers wouldn't use the keys, but the ability to start using it themselves again. They still would have to phase out the compromised master key real soon, but that might be easier to do if one has it in hand.
Disclaimer: I know to little about key management to know whether the above makes sense. In particular, I doubt that having your compromised key makes any difference in the difficulty of phasing it out.
I wonder how exactly the criminals came to have them in the first place, but would be willing to bet it was ultimately incompetence by someone at Nokia.
"Information obtained by Helsingin Sanomat from two different sources indicates that Nokia believes the blackmailer to be a Finnish citizen who participated in the development of the user interface. The suspect was able to obtain the highly-classified encryption key due to a data security vulnerability."
[1] http://www.helsinkitimes.fi/finland/finland-news/domestic/10...
The question is: would it have been worth it? I don't know, but hiding things rarely goes well. Then again, I don't know of any public instances where this has happened, but I'm sure Nokia aren't the only ones to have been hit by this.
Like a rootkit then ? It's a classic case of robbing the mob, as in 'the people who actually own the phone you think you've bought'.
BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!"
Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.
This would be like someone having the GPG signing key for the Red Hat official repositories. It would give them the ability to insert their own (malicious) software package into the Red Hat update stream without the signature throwing any warnings.
Losing signing keys would be pretty bad for Red Hat, too.