4 ms·
My big question, and I would love an answer: Why is it that an organization can topple to malware and ransomware by some L1 tech clicking on a "bad email"? Pe
by duckfang 5y ago
My big question, and I would love an answer:
Why is it that an organization can topple to malware and ransomware by some L1 tech clicking on a "bad email"?
People are going to click on shit. That's a 100% guaranteed fact - be it intentional or not. But WHY is our computing and communications paradigm so brittle that any Jack or Jane can click a link and pwn the infrastructure?
- CountDrewku 5y agohttps://www.cisecurity.org/resources/advisory/?type=advisory https://www.cisecurity.org/resources/advisory/?type=advisory Take a quick look at all the vulnerabilities out there. Google has been releasing 1-2 fixes a week for the last month or so. It's a constant battle keeping this stuff patched.
- bena 5y agoAs I've told someone today, we're shooting lightning through sand and somehow it all works. There are network effects of network effects at work inside computer systems. We can harden a path. Two paths, sure. Three, why not. 4 billion? No way to be sure. It's also a matter of it being an aggressor's game. The defense has to be perfect every single time. The offense just has to win once. And they get infinite tries. And they suffer no penalty for failure.
- muttled 5y agoYou're completely right in your thinking that it's largely ridiculous and avoidable. The answer is generally lack of separation of duties and least privilege. That L1 tech in a smaller organization might be a member of the domain admins group. And to avoid UAC prompts, might sign into his computer as domain admin account. If something runs as him, it runs as admin. Large file shares where every user has edit permissions are also extremely prevalent. Every user has the ability to destroy the shared drive. I've seen a lot of small organizations where the owner insisted on being an admin, despite having no technical knowledge. He clicks something wrong and the malware's got carte blanche. Old line of business applications will often require exact versions of Flash/Java/whatever which are riddled with security holes. Outside that, there's the 0 days and exploits. But a lot of what I see are setups that grew from small, insecure setups where it didn't matter to big, insecure setups where it did. Combine that with the ROI on security not being immediately tangible, and it's hard to get approval for projects to fix it. Even if you design the most secure systems, unless you've got a seat at the executive table someone will probably overrule you and make exceptions.
- rini17 5y agoImagine hypothetical L1 techs which would only accept "good email" such as plain ASCII (I mean really, 7bit) text email without attachments. Everyone would consider such a service broken and route around it.
- Veserv 5y agoImpacts were small. Just a few years ago, one of the most high profile financially-motivated ransomware attacks, WannaCry, hit the NHS and various other government agencies and companies around the world and demanded the unbelievable sum of $300 per computer [1], an amount that most of those organizations could only find by looking through their pocket lint for amounts so small. They spent 100x-1000x more money solving the residual problems than they did or would have needed to pay dealing with the ransom itself. Just a few years ago, the worst case impacts were so small that the problem was not even worth caring about. What they did not realize is that the amounts were small because the ransomware groups likely consisted of young people with more technical ability than business sense. They did not realize how deep the money well went and how much they could really ask for, the criminal equivalent of a bunch of college students making a B2B startup and being worried that their $1k price tag might be too expensive since they would personally think that is a lot to spend. This is borne out by the fact that the targets even a few years earlier were mostly personal computers of random people who might actually have a problem paying $300 to get their family photos back. However, these ransomware groups have been rapidly wising up and now realize they were doing the effective equivalent of robbing the bank for their pens. They are starting to ask for reasonable amounts of money that businesses might actually worry about and with that money they are expanding their operations as fast as they can to try to exploit the entire market. They just have not gotten there quite yet since they do not have access to vast gobs of VC cash and need to instead bootstrap themselves up to a multi-billion dollar criminal enterprise. The unfortunate problem for all of their targets is that none of their things work and they did not think the problem was serious since the impact of failure was so small. They did not realize that was not because more could not be done, but because the people doing it did not know what they were doing and that they were actually at the start of a serious exponential ramp. If you want more technical reasons, it is because every commercially available solution is completely inadequate for an environment where people with modest amounts of money want to attack your system. Nobody selling commercial IT systems has the first clue how to make systems that are actually robust against credible threat actors. The absolute best of the best can maybe protect a system against attacks funded at the ~$10M level, but when you are talking about companies with literally $100B revenue streams, that is a rounding error of a rounding error. Exactly 0 executives at such a company would think that being defenseless against attackers with $10M is acceptable if told directly and I think most of their shareholders and customers would be horrified if they had to put that in their commercials in big bold letters, but that is the best that they can get. [1] https://en.wikipedia.org/wiki/WannaCry_ransomware_attack https://en.wikipedia.org/wiki/WannaCry_ransomware_attack