4 ms·
It's not clear to me from the article that Garmin did in fact get the decryption key. There's enough verbiage suggesting they didn't pay the ransom, so are we t
by bt3 6y ago
It's not clear to me from the article that Garmin did in fact get the decryption key. There's enough verbiage suggesting they didn't pay the ransom, so are we to assume they had other means?
It also took Garmin quite awhile to acknowledge the ongoing situation formally (their outage page has been accurate with red lights across the board). Could it be that Garmin just started to spin up more hardware and began a migration of their last backups? (I'm so far removed from how their service operates so apologies if this sounds impractical)
- vb6sp6 6y ago> There's enough verbiage suggesting they didn't pay the ransom It says they "did not directly make a payment to the hackers". You can't just take 10mil and convert it to bitcoin. My best guess is that a 3rd party made the payment and garmin will be reimbursing
- NotSammyHagar 6y agosaying they did not directly make a payment makes it certain someone paid.
- usrusr 6y agoThey might have paid one of those ransomware subcontractors who claim to solve the problem on a technical level while they actually just pass on the money they are paid after taking a cut. This could have happened both knowingly (on Garmin's side) and not.
- solumos 6y agoMigrating to backups seems possible. Garmin is pretty complex in that it produces hardware and software across a few verticals, but I don't think there's anything that makes them particularly unique in the way they'd handle backups/failover. I think it's also possible that Garmin proactively pulled the plug on their public-facing services in order to mitigate the spread of the attack. It would be _really_ bad if the attackers could make the hop from Garmin's web services to consumer devices.
- adwww 6y ago...or avionics systems for that matter!
- sharken 6y agoAccording to Symantec attackers first gain entry and then explores the network. This process will take anything from days to weeks. By the time the encryption begins they have explored every way possible into critical systems. Preventing the second stage attack is what Symantec has been successful in preventing, this video gives an insight into how that works https://youtu.be/p1KJiv-RjMU https://youtu.be/p1KJiv-RjMU
- sh-run 6y agoI'd be curious to know what all was actually impacted by the ransomware. It sounds like they shutdown all their services in order to assess the damage. Maybe this only affected their corporate infrastructure or manufacturing infrastructure. Looking through my connect account I don't see any missing data that would point to a backup old enough to not be encrypted. My watch does store some information offline so it could be that any gaps have already been filled in or it could be that connect was encrypted and has since been decrypted.
- prh8 6y agoYeah it's just a very poor article all around. Literally nothing to support the title of the entire article.
- stainforth 6y agoThe NSA most certainly has the keys, and inshallah I hope that's the case - our nerds better be better than their nerds. I just think they don't want make our defensive capabilities public. But the many billions per year going to NSA better show some results. Maybe our great Chamber of Commerce can insist on making the NSA's great work and capability available to the Western market forces so key to the current prosperity we all enjoy.
- Waterluvian 6y agoWhat supports any of these claims? What should I google to understand why the NSA has the keys?
- jlgaddis 6y agoAssuming the ransomers aren't completely incompetent and are using 256-bit or even 128-bit AES, why would you assume that "the NSA most certainly has the keys"? They might be good but they aren't good enough to randomly crack AES.
- hourislate 6y ago>They might be good but they aren't good enough to randomly crack AES. If they could, I'm sure they wouldn't even offer.