6 ms·
The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. IT departments will never have enough mon
by davethedevguy 5y ago
The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem.
IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP).
Users will always open attachments from people they don't know, click links, or even pick up random USB sticks.
The perpetrators know this. They don't need to be more sophisticated than the InfoSec people at a given organisation, they just need to trick one user in that organisation in to letting them on to the network.
- g_p 5y agoAbsolutely this - most ransomware attacks are pretty unsophisticated. You don't need privilege escalation, or an exploit. You can carry out the attack using just basic user permissions. You are exploiting a basic "problem" of most modern OSs (that apps run "as" the user executing them) - the user/group permission model ceases to work in 2021 with non-expert users. Portal-based access to individual files via secure OS-provided portals (i.e. like on Android/iOS/flatpak) help to prevent apps needing access to every file on the filesystem, but until those are widely adopted, it will be increasingly difficult for "normal" organisations to prevent ransomware attacks. You can prevent ransomware fairly simply by following best practice, and taking some steps that most companies will feel are excessive (but effective), such as whitelisting binaries, preventing running of any binaries not on that whitelist, and keeping that whitelist up to date on a regular real-time basis. Nobody wants to spend the time doing this, so they leave it a "free-for-all". Exploiting user-level access is just the natural escalation now that getting good exploits is more costly and difficult. Now attackers will "make do" wiht what they have. IT can win the battle, but with inconvenience, friction, and increased costs in IT. There's important businesses that are "critical infrastructure" still using Windows 7 on their corporate day-to-day let-me-check-my-emails-and-browse-the-web laptops, without extended support. Organisational inertia and a lack of recognition that they need to pay for the technology that enablers their business leads them to this position.
- londons_explore 5y agoI would like to see rate-limiting built into OS's. Eg. an application is only allowed to touch 100 files per second or 1000 files per hour. When it reaches those limits, it gets paused and a popup asks the user if this application really should be doing X. Then at least ransomware can't run through stuff too quickly.
- g_p 5y agoIndeed - I think Windows Defender dabbled in offering this as a feature. I at least recall seeing programs prevented from creating files in the Desktop or Documents folders. A rate limit, with group-policy controllable "automatic response" would perhaps help - you need the GPO integration though so that an IT admin can say "never allow file system rate limit to be exceeded". If you enforce a rate limit locally, and on the network, and move to copy-on-write filesystems, it would be a whole lot harder to cause straightforward harm (at least while migrating to a newer, safer OS architecture paradigm, where code doesn't run as the user). In the post-Covid world, I think MS and others have a whole host of these kinds of issues to think about - Windows in an AD environment is still (as far as I know) not something really geared for working off-prem. It still relies heavily on LDAP and CIFS etc. A re-write to get a desktop OS ready for the "web first" world (where everything is sent to the AD domain TCP/443, using HTTPS, with client certificates rather than passwords, stored locally via hardware-backed secure storage, and trusted CAs used by the DC) would be a big first step towards this. Yes, I know you could use Direct Access or whatever MS has butchered into the system, but in a world moving to zero trust, MS needs to move to zero trust. Rate limits would be a great starting point, as would some proper platform-level protections around preserving shadow copies, using copy-on-write, and locally preserving versioned user files as a priority. As soon as a ransomware attack touches the network, IT should be able to handle it, as their backup regime should take effect. At that point, if you don't have backups sufficiently separate from user-writable files (or you never validate them, and thus don't realise you're backing up transparently encrypted ransomware'd files for months), you're on your own!
- csydas 5y ago
- paulpauper 5y agoWhy do twitter scams work so well? Because the margins are high enough from the few ppl who still fall for the scams. Awareness only does so much. You spread malware to millions of ppl, just a few conversions makes it worthwhile.
- sillysaurusx 5y agoIt's interesting that twitter isn't automatically filtering those. It's basically a solved problem, they're just not doing it. I'm not saying it'd be easy to do, but rather that it'd be a nice thing for the world if they did.
- gizmo686 5y agoImplicit in this comment is the assumption that current technology is pretty much the best we can do? > IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). Why is it that even slightly old systems are so buggy that they are trivially hackable for a moderately well funded group? Modern security is based primarily on security through obscurity. As long as you stay up to date, all of the bugs you have are sufficiently obscure that knowledge about them is probably too expensive for the type of hacker that would target you. > Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. Why is any of that a problem? A user should not be able to threaten an organization's IT system even if they were outright hostile (unless they were put in a specific position of trust within IT; but even then the amount of damage they should be able to do from their personal work computer should be limited).
- fnord77 5y ago> Why is it that even slightly old systems are so buggy that they are trivially hackable for a moderately well funded group? because software is tremendously complex with a large surface area to attack. And many OS features were designed when wide-scale hacking was not a problem.
- Veserv 5y agoThen that means the software is hopelessly inadequate for the current environment where wide-scale hacking is a constant problem. To echo what they said, why do we accept and deploy systems that catastrophically fail in circumstances that we know are going to occur? Why is it acceptable to take systems that were not previously connected and actively make a decision to connect them to internet if they are completely unfit for that environment? And not just that, they are so unfit that they not only fail in the new environment, but they enable total organizational collapse in a way reminiscent of the exhaust port on the Death Star.
- fnord77 5y ago
- _wldu 5y ago100% agree. It's a trick that criminal con-men have been using forever in the physical world. There's no reason to kick a door down (draw attention to yourself) when you can convince someone inside to open it. "My puppy just got hit by a car! Can I come in and use your phone to call for help?"
- curiousgal 5y ago> Users will always open attachments from people they don't know, click links, or even pick up random USB sticks. One bank I interned at sent people an email about the weather or something to that extent and each link had a unique identifier. Shaming each individual user is the best way for them to learn.
- viraptor 5y ago> Shaming each individual user is the best way for them to learn. It's the best way for them to stop trusting the security team and never come in with any issue, even if it could be used as an early signal preventing bigger attack. Many people's jobs rely on them receiving emails from unknown sources and receiving files from them. Shaming them for "you should've known this specific link is bad" is counterproductive. That's even before we get to whether they would actually put in any credentials. Phishing tests have value. Running them to shame people into compliance is a waste of time. For better takes, there's a good thread https://twitter.com/hacks4pancakes/status/1334875739955605504 https://twitter.com/hacks4pancakes/status/133487573995560550...
- temp8964 5y agoIs it true that hack any random staff / computer of the company can lead to the ransomware attack of the machine holding the crucial data of the company?
- _wldu 5y agoIt is probably more true in "Corporate America" where MS Windows Active Directory is in use and all the computers are domain joined and have read/write access to file servers.
- temp8964 5y agoIt sounds like a problem the IT department should solve. No?
- g_p 5y agoIt is, but solving that problem would entail re-training staff, reduce "productivity", and moreover, cost money... Many companies have cut their IT provision below what is needed to simply stand still. IT is a cost to their business, not a revenue source. They don't consider the counter-factual of "well, what if we didn't use IT and computers and the internet" when valuing what IT is bringing to their business. If they did, they'd perhaps be willing to spend more. MBAs don't like spending money on something that doesn't yield them more sales though...
- bluGill 5y agoMBAs don't like wasting money. If bad IT costs them money or sales they care. If they can reduce the costs without losing that money they will. However they don't know how to solve this optimization problem and are learning the hard way when they get it wrong.
- g_p 5y agoI think part of the issue is also that the negative impact of getting IT wrong is delayed, and often lands after your middle managers have moved on to other organisations, thus don't see the impact of cutting costs repeatedly. Since there's no visible problem (nothing catches fire) the day, week or month after cutting spend on IT, it's an unnecessary expense in the eyes of beancounters.
- syoc 5y agoI agree with what you are saying, but calling it a people problem makes it harder to solve. If you organization is large enough than your users will always click on phishing links and download sketchy malware toolbars. You should also expect to an lesser extent that your internet facing infrastructure will have vulnerabilities that will be exploited before you are aware of them. These are facts of life and need to be expected. Not saying that security training is wasted money, but it is in no way a solution to for example phishing. Accept that you will have compromised clients and internet facing servers and start making a strategy with that scenario in mind.
- mikewarot 5y ago>The difficulty with ransomware attacks and the like, is that it's less a technical problem and more a people problem. The cause is definitely technical, it is a huge gaping hole in the design of modern operating systems that you could sail the Ever Given through sideways without incident. Your operating system does not confer to the user the ability to delegate only X resources to the opening of a file, email, etc. They (the users) have no ability to limit side effects. Blaming them for your bad system isn't ever going to help fix things. The missing system of limiting side effects is known as Capability Based Security. We all have a practical example of it in our wallet or purse. We can remove a unit of currency, hand it to someone else for a purchase, and that is the maximum we can lose, unless something extraordinary happens. We all have outlets, which limit the amount of power they will supply, and some even check to make sure it isn't supplied through us, or into a system that has arcing issues. We never have to worry that turning on a lamp will take down the power grid. Imagine if there were no circuit breakers or fuses, would blaming people for not being careful enough help make the system safer? No, of course not. Neither does blaming the user for your defective Operating System.
- fancyfish 5y agoCurious, what are the viable capability based systems within the next decade or so? Fuschia?
- mikewarot 5y agoGenode
- a1369209993 5y ago> We all have outlets, which limit the amount of power they will supply, and some even check to make sure it isn't supplied through us, or into a system that has arcing issues. Not that you don't have a point, but outlet safety measures only address accidental failures. A malicous device is perfectly capable of storing power in a battery or capacitor to exceed instantaneous power limits, or running at 12 amps (out of 15A fuses) 24/7 to pull much more power than you expect over time, or electrocuting you taser-style even if it doesn't have a high-current ground path. So while the safety features are useful, they're not particularly relevant to security. The wallet example is pretty good, though, as is your actual point.
- marcosdumay 5y agoThere is no technical reason for allowing any random user to delete their data, or at least not requiring some specific capability that most processes don't have. In fact, there were systems built this way in the 70's.
- 908B64B197 5y ago> IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP). It's not like Microsoft has an explicit EOL date announced for every OS release...