Bitstamp Incident Report 2-20-15
scribd.com
scribd.com
That makes me pretty sad. Who needs bare-metal/firmware rootkits or virtualization escape exploits when a DOC file + some VBS let's you rob some crypto currency?
However, the point is, how do I know what will happen when I click this button? Will it run a helpful macro to format my data or will it delete all my files? Why is a macro language allowed to do that? Why do those two things have the same security level assigned to them?
You should run executables only from trusted sources - that's what we're told, right? Now - do you trust an email appearing to genuinely be from a very prestigious honor society from the world's largest CS authority? Why not? Why was the person not able to cryptographically verify that, yes, that is indeed where this file came from? What is that - you say that since they didn't know the sender personally, they shouldn't have trusted the file anyway? A different example: What if, say, someone used windowsupdate or apt-get as an attack vector? I bet you're trusting those strangers already, as we speak, and you have pretty much no say in the matter.
"Oh, we'll put in a warning dialog" is the most crappy duct-tape there-I-fixed-it style solution to this extremely nuanced problem, and blaming the user does nothing to secure real world systems.
No, that's what computer savvy people know, normal users don't think twice about running an executable from any source, that's the whole point. Nothing you suggested will stop what people simply do continually, open anything from anyone without caring who the sender is. Sandboxes don't just protect things, they forbid necessary and useful things so you can't simply sandbox everything because users will simply refuse to use your crippled software and opt for the less secure but more functional version. Users don't care about security, that's the problem; it's a social problem, not a technical one.
If you opened a txt file in your editor, which then installed spyware on your computer, wouldn't you put the blame squarely on your editor?
Off the top of my head, macro execution shouldn't be a boolean choice. Don't let Macros modify the file system or connect the network, without additional prompts/warnings. Default to not allowing these at all, and the user can't just click a "OK" dialog to start allow it. Bury that setting deep in Control Panel.
OS X/HFS+ has an interesting feature of using meta data to tell where files came from. You get security prompts even days later when doing certain actions with files downloaded from the Internet. Word/Office could act differently with Macros based on whether this file was an email attachment or downloaded vs. a local file the user created.
When enabling VBA scripts, they could be run in a sandbox for a few seconds to see what it modifies on the system. Yes, there are ways around this, but lets raise the bar some.
It's striking how often reports of exploits conveniently omit that Microsoft Corporation software was involved.
If this is public now, presumably they've finally airgapped wallet.dat? It sounds like Kodric is getting the blame for this, with his boneheaded doc opening, but with the architecture they had this might have been just a matter of time. After all the CTO had previously opened another doc, but the embedded VBA didn't run for unspecified reasons.
http://www.symantec.com/content/en/us/enterprise/other_resou...
While the total number of emails used per campaign has decreased and the number of those targeted has also decreased, the number of spear-phishing campaigns themselves saw a dramatic 91 percent rise in 2013.
and
http://blog.wombatsecurity.com/spear-phishing-everything-eve...
91% of cyber attacks begin with a spear phishing email.
94% of targeted spear phishing emails have attachments
Here is the referenced report in the above article:
Spear-Phishing Email: Most Favored APT Attack Bait
http://www.trendmicro.com/cloud-content/us/pdfs/security-int...
a) labelled confidential and
b) scanned and OCR'd with some problems visible on the first page.
If this is officially public I would like to read it, please provide a legible copy. If this a leaked document than I can't use it and don't particularly want to read it.
Motive: I write this sort of thing from time to time and I would not enjoy seeing it leaked and discussed.
Why?
:(
> ...we need to be very careful not to educate other criminal hackers about how we safeguard our assets and information. Accordingly, no part of this report may be made public or given to a third party without the prior express written permission of Bitstamp Ltd
Well I was going to quote it but it's been taken down already, wish I still had it open in a tab. The line was something to effect of "This document should not ever be made public as it outlines our weaknesses and we don't want to give future attackers any more tools to attack us"
Edit: I've updated the above with the quote, I found it after all
Edit 2: All of that said I too would love to read more in-depth post-mortems on hacks/breaches/thefts. I knew phising like this was possible but I would have fallen prey to some of that probably. Now I don't use a windows computer so I might have been marginally safer but there is nothing to say that the attacker didn't have linux/osx tricks up his/her sleeve. The graphic that shows the different avenues of attack and the one that finally succeeded was a really cool way to visualize the attack as well.
How is anyone supposed to trust nincompoops who open word documents from unsolicited emails on Windows while connected to a sensitive VPN? Furthermore: with your money.
Also when dealing with sensitive stuff like this, I expect them to have better monitoring of their services, like notifications on access, etc.
OSX is a *nix based system and has had far worse security than Windows for ages (lagging with basic things like address space randomization). Just because Unix is not considered a primary attack surface area for viruses and alike, it does not make it inherently more secure. That kind of attitude is indeed even more dangerous than having a well secured Windows computer.
(Disclaimer, Mac user myself)
Both systems have unpatched root exploits if you have access to the display subsystem. Both were initially developed for trusted local environments, then adapted for public network use some ten or fifteen years later and whatever security issues that brought was patched as they were found. I'm just not sure how to argue more or less security in that environment. Users still get owned by running Flash (so no ASLR for you) and Outlook.
[pdf] https://bitstampincidentreport.files.wordpress.com/2015/07/2...
[docx] https://bitstampincidentreport.files.wordpress.com/2015/07/2...
EDIT: I'm referring to a scribd doc. For the reasons you cite, GDrive would not be appropriate for this.