5 ms·
The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.
by hoomank3 6y ago
The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.
- draw_down 6y agoThey ain’t doing it for the love of the game!
- verandaguy 6y agoOptimistic counterpoint: a high-profile, (relatively) high-value ransom payout like USC's may incentivise other orgs vulnerable to this kind of attack to take steps to prevent this kind of issue. Anything from restricting program capabilities/permissions for external executables, to keeping "colder" backups of business-critical data, to monitoring and responding to software that looks like it's traversing the whole filesystem, could reduce the harm ransomware causes.
- garmaine 6y agoYou can't really protect against this sort of thing. A lot of our IT security runs on trust. The only way to really prevent this is to make sure that ransom attacks don't pay out. EDIT: I should mention that I've managed IT services for a major private university earlier in my career, and I am now a software security consultant. When I say it is not possible, I mean that pragmatically. A FAANG company can control their IT well enough to make sure this doesn't happen to them, but a hospital or university relies on computer systems running software way outside of their control. That MRI machine? Its controller is probably running some ancient version of Windows Server 2003 with proprietary drivers. That university registration app? Custom coded by generations of CS student interns running on a shared system whose operating constraints are set by the Novell GroupWise instance that is co-hosted on it. As a practical matter, one of these organizations simply cannot reduce their risk to zero or near zero. There's too many attack vectors they don't have control over. The IT departments can't mandate proper security because they don't have the budget to enforce.
- verandaguy 6y agoYou can't fully protect, sure, but you can have a person or team alerted on suspicious behaviour. You could also try to configure your infrastructure so that any code imported via vectors that ransomware usually uses is compartmentalized in a VM, container, or other chroot-like env. And honestly, having even week-old cold backups makes this kind of attack _considerably_ less scary and cheaper, and it enables you to skip the payout (and I'm on the same page as you on that — if there's no money to be made, ransomware attacks will drop off).
- masonic 6y agolike USC's UCSF is University of California, San Francisco. USC is University of Southern California, a private school.
- verandaguy 6y agoGood catch, thanks!
- mcny 6y agoIf the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!
- strictnein 6y agoAbsolute nonsense. First of all, they are increasingly selling the data. They exfil first, lock second. Second of all, these wonderful criminals are targeting all manners of institutions, not just large universities. Proper data hygiene at large enterprise levels is, in fact, exceedingly difficult.
- vinay_ys 6y agoProper data hygiene at large enterprise levels is, in fact, exceedingly difficult. Creating a hermetically sealed IT environment where only way to exfiltrate data that remains is the employees eyeballs is definitely possible and is increasingly done well by a lot of large organizations. Defending against insider threat (malicious employees) is still a challenge for most civilian (non-military) organizations.
- mc32 6y agoDepends, those kinds of outfits tend to poke around and lurk a while before striking. In that time they can exfiltrate and you cannot prove that the baddies didn't exfiltrate data (if you had that sophistication, they wouldn't have been in the mess they got into).
- dogecoinbase 6y agoI know how much IT personnel at UCSF make -- you get what you pay for. If you want expertise, it's not hard to find.
- strictnein 6y ago
- achow 6y agoThis was a bug bounty - another way to look at it.