4 ms·
> At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. Even if that's true, it doesn't affect backups. Bac
by abraae 5y ago
> At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack.
Even if that's true, it doesn't affect backups.
Back your fucking systems up properly, and if you are attacked by ransomware, then do a scorched earth restore.
- Veserv 5y agoIt absolutely does affect backups. If you stand to gain $5M from an attack you can also target the backup systems and still easily end up profitable. Only if you stand to gain less than $100k does the budget actually start to get tight. As for how you attack the backup system it depends. If it push based you send your payload during the push. If it is pull based you craft your payload in the data that will be backed up. If it is not append-only you can easily nuke the entire available history. If it is append-only, but that is only done in software you just need to take over the software. If it is in hardware you just infiltrate then silently encrypt any new data until it would be painful to revert that far back in time. Given that the mean-time to discovery is on the order of months that is quite painful. If they regularly test their backups you just silently decrypt the data on restore until it is time to strike. There are plenty of ways to beat vulnerable backup systems in that sort of budget. Like, seriously, with a $5M budget you can literally purchase and burn multiple zero days for every system in the chain and still come out ahead. You can hire 10-50 full time software engineers for a year per attack. Most systems have serious vulnerabilities discovered by lone individuals working for a few months in their free time let alone a team of 50 people. The current backup systems survive because most of these attacks are being done with budgets closer to $10k-$100k to maximize profit and growth rate and that is not really enough money to pay for the second arm of the attack. But with a $5M return they could easily allocate a few million to capitalize on the opportunity if that is what is needed once all the juicier targets have been eaten.
- elliekelly 5y agoI can’t speak for other industries but in the financial industry (in the US at least) periodic backups are required on physical tapes both off- and on-site. Barring a Mr. Robot hack of the institution and Iron Mountain to burn the tapes the absolute worst-case scenario in a ransomeware attack on a financial institution is an afternoon of data lost.
- whitexn--g28h 5y agoIf you knew in advance of the timing of the data loss you could do billions in damage to a bank.
- Veserv 5y agoYou just hack the machines that are loading the data onto the physical tapes or the system that is collecting the data to put onto the tapes. Essentially, at some point the data goes from where it is being used to the tapes and you just takeover one of the systems in that pathway. You then wait for 6 months silently encrypting the data before you make your demands. Now the absolute worst case is that 6 months of data is lost or however long you were hiding. Industry studies indicate that the average time between infiltration and detection of an agent actively exfiltrating data is a few months, so a few months for an agent not even pushing data out over the network, just silently corrupting data going to your off-site backups that you are not looking at is very reasonable. Backups are not the end of the story unless you are dealing with attackers with only $10k to their name which is essentially what everybody without backups is losing their minds over and being defeated by. That is a literal rounding error of a rounding error of a rounding error for the financial industry. People spend more on lunch than that. A moderately sophisticated attack with a few million behind it is literally 100x the resources of most of these attacks and that is still just a microscopic pittance compared to the financial industry. Think about that, if you want to reach the $1M level you need a system that can defend against an adversary with 100x the resources of a basic ransomware attack. The gap is so large that the capabilities fundamentally change and intuition for how to defeat a $10k attack does not generalize. And, we have not even considered a system that would even be considered barely adequate for the financial industry. If you want to get to something barely adequate for the financial industry, like say protecting against an attack funded to a level comparable to one day of disrupted operations for JP Morgan, you would need to protect against an attack on the order of $500M, literally 500x more than those "good" systems and 50,000x better than these basic systems. The gaps are ludicrous and the lessons at one scale do not really apply when you go up another 2 or 4 orders of magnitude.
- abraae 5y agoIt seems appropriate to regurgitate the one about the bear and the hikers.... Two friends are in the woods, having a picnic. They spot a bear running at them. One friend gets up and starts running away from the bear. The other friend opens his backpack, takes out his running shoes, changes out of his hiking boots, and starts stretching. “Are you crazy?” the first friend shouts, looking over his shoulder as the bear closes in on his friend. “You can’t outrun a bear!” “I don’t have to outrun the bear,” said the second friend. “I only have to outrun you.” In our scenario, the bear is the ransomware attackers, and Colonial Pipeline is one of the runners. There are hundreds or thousands or tens of thousands more runners that the bear can go after. You don't need to have perfect security over every aspect of your operation (though you should of course aspire to that). In particular you don't need to give up because in theory someone could infiltrate your offsite backups. You just need to make things hard enough that the ransomware guys will go after an easier target.
- Veserv 5y agoExcept that is totally wrong. You are assuming that there is one bear, that you can escape the bear forever, that the bear is not hungry enough to eat everybody, and that the bears are not multiplying ferociously due to nearly unlimited supply of delicious food. No, reality is more like the story of the dodo. A vast quantity of delicious prey that nobody was eating because nobody knew about them. Then they were discovered and some predators showed up but there were not enough to eat all of them. But then more and more predators showed up to exploit the vast untapped resource until they were all eaten. We are still in the middle of that process which is borne out by the fact that the frequency of attacks has been increasing on the order of >100% per year and average demands per attack have been doing something similar. That is an utterly ferocious rate of growth that will soon be enough to attack not just the juiciest targets, but every profitable target in a few years. Being slightly faster or slightly less delicious will not help when there are finally enough bears to eat everybody.
- cutemonster 5y ago> If it is in hardware you just infiltrate then silently encrypt any new data until it would be painful to revert that far back in time What does "infiltrate" mean here? An insider? > painfulthey regularly test their backups you just silently decrypt the data on restore until it is time to strike. Interesting, I was just going to ask