10 ms·
I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these
by uses 5y ago
I'd really like to see/hear/read a breakdown of some of related issues from some experts.
Even on HN it's the same knee-jerk reactions every time one of these stories hit.
This is one of the most pressing technology issues of this moment and the discourse just sucks.
* Does banning ransom payments do anything? Good idea/bad idea? Historical analogues?
* Do we need to pay rewards to cyber privateers to take down cyber criminals?
* Is this an issue that can only be solved at the geopolitical level because of the role states play in enabling this activity?
* Will the hardening brought about by this eventually outpace the crappy attacker software?
* Is this a phase or the new reality?
* How much of this is enabled by technology vs the geopolitical situation?
- mannerheim 5y ago> Historical analogues? 'Don't negotiate with terrorists' or: > It is wrong to put temptation in the path of any nation, > For fear they should succumb and go astray; > So when you are requested to pay up or be molested, > You will find it better policy to say:— > "We never pay any-one Dane-geld, > No matter how trifling the cost; > For the end of that game is oppression and shame, > And the nation that plays it is lost!"'
- alksjdalkj 5y agoAnother issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.
- xkyf 5y agoThat gets discussed every time, hackers were using prepaid cash services. Ransomware predates cryptocurrencies by decades.
- viraptor 5y agoIt's a bit of the "we have X at home" meme situation. Sure, ransomware existed before, but the scale was not even close to that. You can't move hundreds of millions in gift / prepaid cards without getting found. It's a completely different level of comfort for the operators.
- anonymousDan 5y agoDo you have evidence for this claim? I'm almost certain it's no longer true.
- mandelbrotwurst 5y agoHow do you know that we’re not less secure? It wouldn’t surprise me at all if our systems are on average far less secure simply because so much more is online now, to speak nothing of increases in the complexity of and opportunities for errors and misconfigurations in today’s systems.
- user-the-name 5y agoBecause twenty years ago computer security was an absolute and utter shambles. Exploiting a vulnerability today is orders of magnitude harder than it was twenty years ago. Massive strides have been made.
- mannerheim 5y agoJust a couple years ago, the largest botnet in history infected IOT devices using default passwords in order to DDOS Minecraft servers, so perhaps these strides haven't been so massive.
- Grimm1 5y agoIOT isn't datacenter server technology. IOT is basically in the state of software security from 20 years ago. Often running crappy proprietary stuff. Your average server running a recent Linux kernel is Fort Knox comparatively. There have been massive strides in many places in software security but IOT and embedded security in general is very lacking unless your talking things going into space or military.
- dopidopHN 5y agoThe S in IOT stands for security, after all.
- rurban 5y agoThe S in Linux ditto. Linux has a far wider attack surface than my baremetal embedded firmware. Like 10^6 wider. There's a single mqtts service mostly, or just passive senders (sensors, controllers). Zero attack surface. Linux is way too big, with thousands of drivers, services and patches.
- karaterobot 5y agoGranting your premise, but: what is there to discuss about it? Cryptocurrencies are good for this, yes. I am inferring (perhaps incorrectly) that you're saying this is an argument against cryptocurrencies. I think that's beside the the point: even outright outlawing cryptocurrencies wouldn't stop the technology from existing, and wouldn't discourage extortionists from using it to anonymously receive payments. It would make it harder to pay, since you'd have to go outside of safe, legal channels to get money into the system. If the best strategy when being extorted is to never pay or negotiate, then I suppose that could be a benefit. But, in that case it would be more efficient to just make it illegal to cooperate with extortion in the first place. For all I know, this is already true. If not, let's try that first. If it is, it doesn't seem to matter, since people are paying ransomware hackers. Still, if paying at all is illegal, but people still do it, then making paying less convenient probably won't make much of a difference: they'll still ask for payment in crypto, and leave the logistics up to the victim.
- lvs 5y agoBut the genie is out of the bottle now. It's not going back in.
- dopidopHN 5y agoI always wondered if it’s was possible. Without looking. Now, I know?
- f38zf5vdt 5y agoThis level of corporate hacking existed prior to cryptocurrencies, the difference is that it was used for stock market manipulation and profiting on short or long positions. It appears that this is even more profitable than ransomware, in the hundreds of millions or possibly even billions of dollars. [1][2] [1] https://www.wired.com/2010/03/manipulated-stock-prices/ https://www.wired.com/2010/03/manipulated-stock-prices/ [2] https://www.reuters.com/article/us-cybercybersecurity-hacking-stocks-arr-idUSKCN0QG1EY20150811 https://www.reuters.com/article/us-cybercybersecurity-hackin...
- goatsi 5y agoYour comment makes it sound like stock markets were manipulated by hacking the companies that issued the stock. In one of your stories brokerage accounts were compromised and used to pump penny stocks. In the other someone hacked a few companies that distributed press releases to get early access to them and traded on the information. Stocks weren't even manipulated in that case, they simply placed trades based on how they thought the market would react to the news. That was a targeted attempt to get information, not a destructive attack on the entire company network.
- f38zf5vdt 5y agoYes, so both manipulation and put/calls were leveraged by hacking as I specified. I think there is a disconnect in my communications. In these cases the penetration (hacking) was the same but there was no data destruction. Ransomware appears to be a less profitable and less clever use of hacking.
- lmm 5y agoFrom my memory the profits from such attacks were remarkably low. In particular it's very striking that the hackers who compromised JP Morgan couldn't find anything more profitable to do with that access than send basic scam emails to their client lists.
- MattGaiser 5y agoAs an alternative question, how much is this worth stopping? As how much is being spent on these payments overall each year? How would that compare to the massive IT fortification project people are demanding? We don't meaningfully fight bike theft for this reason. The cost of doing so relative to the benefits is just too high. We can debate whether that is reasonable, but that is essentially what has been decided as a society. Most low level crime is not meaningfully investigated.
- nitrogen 5y agoWe don't meaningfully fight bike theft for this reason. And this erodes trust in society and rule of law, and gradually leads to vigilantism, privatization of security, and segregation due to middle-class flight from high-crime areas.
- mrhyyyyde 5y agoSource to support your statement?
- nitrogen 5y agoHistorical precedent (e.g. white flight), personal experience with losses of thousands of dollars of my former startup's equipment to theft, and forward-looking projections from other HN threads about people who chose to leave the Bay Area.
- MattGaiser 5y agoAs I said, we can dislike it, but as a society we have basically decided that anything short of reasonably straightforward violent crime/extreme violent crime and high value property crime and easy to prosecute drug crime is not worth the effort. I don't disagree, but I hear very little discussion about low solve rates for smaller crimes.
- rsj_hn 5y ago> As I said, we can dislike it, but as a society we have basically decided that anything short of reasonably straightforward violent crime/extreme violent crime and high value property crime and easy to prosecute drug crime is not worth the effort. No, I would say that a few counties have decided this, but the majority of counties have not. In most places, you do get arrested for property crimes, you still serve prison time for this, police still do things like use bait cars and exert resources to catch those who steal, and the idea that property crime should not result in jail time is not widely accepted by the majority of the population.
- viraptor 5y agoThe Risky Business podcast #624 talks about pretty much all your questions if your want to listen to it. But here's some relevant info: Hardening can help, but we'll always have new exploits and some of the time the intrusion comes from standard fishing rather than automation, so tech can't solve it. Crypto coins enable payment at scale, but Russia enables the operation to not worry about consequences (a lot of ransomware will disable itself on Russian computers to avoid local prosecution). And in my opinion it's only a matter of time till something so crucial will be affected that the big guns will be rolled out. (I.e. targeted 3 letter agencies efforts) The podcast argued that touching the energy delivery / pipeline was already it - Fox asking daily how the current administration fails to deal with securing energy may be the point when some real action happens.
- wmf 5y agoGood 2FA (e.g. U2F) can solve most phishing. https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/ https://krebsonsecurity.com/2018/07/google-security-keys-neu...
- tgsovlerkhgsel 5y agoIn this context, "phishing" often means "random other forms of social engineering that people started calling phishing almost a decade ago". The attackers no longer steal a password and log in with it, they kindly ask someone to please run their malware.
- rudedogg 5y agoThis mentality of "there will always be new exploits" bothers me. Yes, there will always be exploits, but we can do a hell of a lot better at preventing them than we are. We know how to design systems that are really hard to get into – we just don't do that. Blaming a lack of IT funding is misguided in my opinion too.
- viraptor 5y agoSure, there are ways that would pretty much nuke most of the ransomware business. For example application whitelisting. I wish it was more popular.
- xenadu02 5y agoMany ransomware attacks are not sophisticated. They may be targeted but the procedure is fairly simple: blast targets with phishing emails/texts, get them to click, done. It seems that zero-days are often not required because targets lag behind in applying patches. Many (if not most) companies have file shares with fairly wide-open access and/or a complete lack of backups so peer-to-peer spreading within the company is enough to cause a lot of trouble. At its root these are technological problems that we could choose to solve: 1. The program is not the user. Code running as a user shouldn't necessarily have permission to access everything the user can access. 2. New code is not treated with suspicion when it should be. New code should have its file access throttled in proportion to how many files it accesses. 3. Our systems do a terrible job of spotting unusual behavior. How many processes actually need to rewrite every file the user has access to? Almost none... rewriting 10% of the user's files should trigger an automatic throttle/stop and raise red flags. 4. As a variation on #3, most OSes these days ship parsers for a lot of common file formats... if the OS sees lots of user documents being rewritten and the parsers can no longer parse them stop allowing new rewrites and alert the user. If the user is encrypting their content on purpose they can approve it. If not you can at least limit the damage. 5. Similarly a network user that usually accesses a limited set of files should not be able to suddenly start rewriting thousands of files without some kind of intervention. 6. Our systems completely fail to take advantage of ancient technology called "file versions" (see VMS). Excess disk space should store old versions of files in a way that cannot be deleted (or the ransomware would just call that API or generate random writes to consume the space). Combine with 2/3: when there is suspicious activity on the system move into CoW mode and preserve previous versions of all files or an entire system snapshot and don't allow purging the snapshot without special intervention (eg rebooting into a special mode). 7. To go along with all of the above code should be tagged with its provenance in a system-tracked way. If a process writes a new binary to disk track that responsibility. Track it all the way back to the URL or email it came from. This entire audit trail should be attached to any of the mechanisms listed above. It should also be attached to any sort of activity monitoring program that shows you disk accesses, including historical accesses. If I see 50GB of disk reads/writes from a process group "JGjthjsfgl.exe, downloaded from p0wnme.example.farts" that is a huge red flag. Let me suspend that entire process group with a single click. I'm sure smarter people could come up with even better ideas... but ransomware is absolutely something we can and should make nearly impossible. We could engineer operating systems to be resilient and limit the damage (eg: macOS prompting you to approve access to Desktop/Documents/Downloads) but it means giving up some sacred beliefs about how desktop operating systems should work that tends to make a subset of the HN audience extremely angry.
- joe_the_user 5y agoThe answer to your (somewhat leading) questions is just no. War analogies are inapplicable, privateer analogies are inapplicable. Create the incentives, organizational and software structure required to stop this or it will continue. Holding single companies accountable shifts the burden without solving the problem. Have standards, standards bodies, defensive organizations.
- dopidopHN 5y agoExactly. Nothing some good old boring gouvernering to raise the bar of standards. Like for foods, hostels, stuffs on the roads. There is some analogies.
- WalterBright 5y agoAn easy way to blunt such attacks is to have physical write-enable switches on drives used for backups. Then, when restoring from backup, it cannot get corrupted. Of course, even better would be a physical switch for incremental backups, so a disk drive works like tape - it can physically only be appended to if that switch is "off". Come on, security professionals. None of this has any technical or cost barriers. Demand it from drive vendors. My older drives have such a switch.
- WalterBright 5y agoAnticipate a problem with your IT staff leaving the write-enable switch on? Have the drive maker add a (again, physical) clock circuit (could just be an RC delay) to turn it off again automatically. (Even if you don't anticipate a problem with your IT staff, it's just good engineering to automatically turn off the write-enable. Nobody's perfect. I've gone to the airport without my passport once. It really sux when you do that.)
- willcipriano 5y agoThis is a system I put together at my first IT job. Backups get pushed from devices between 1AM and 3AM each day, so the primary backup server enables it's network card at 1 and disables it at 3. Primary backup server also has a second network card, that in turn is attached to a small subnet containing it and the secondary backup server only. The secondary backup server pulls a copy from the primary on a weekly basis in a similar manner as the primary, disabling it's network card once it has finished. Maybe they can hit the primary if the infection takes place overnight, but the odds of getting the secondary are pretty low.
- WalterBright 5y agoThe odds of hitting the secondary are zero if you've got a hardware write enable switch! One thing you could do is get one of those mechanical lamp timer clocks from the hardware store, and have it turn the power on/off the network card on schedule.
- deleted 5y ago[deleted]
- colechristensen 5y agoPaying ransoms can be illegal if it is happening with a sanctioned entity. We need to start holding companies criminally liable having security vulnerabilities that get breached. It is true that there will always be exploits but the issues are usually much more wildly irresponsible security practices and not “didn’t know about the latest 0day” There needs to be a statutory liability to customers and required insurance. Let the insurance company figure out the regulations instead of bureaucrats and politicians, insurance company rules are optional and noncompliance is just more expensive. It is an increasing trend but the current uptick in awareness is mostly media coverage. This stuff has been going on forever, a few particularly newsworthy things happened now everyone is going out of their way to report each new instance. Trends in reporting instead of trends in exploits (to a degree)
- rsj_hn 5y agoCurious, how do you know that you are paying ransom to a sanctioned entity? Do they publish lists of bitcoin addresses of sanctioned entities that you can check? If not, how do you check the identity of the payee?
- tacosaretasty 5y agoYou can create a Bitcoin address simply with random data, and since you can transfer Bitcoin without an intermediary it’s trivial to bypass any list of suspect addresses. Further, you don’t throw a party with a list of people not invited. It’s super ineffective to try to globally block an infinite list of bad. Fungibility of a currency is actually important for it to be effective as a store of value. If my 1 USD is somehow worth more at the supermarket because it previously was owned by Elon Musk. That said it’s not entirely impossible to track the source of origin of a Bitcoin transaction. It’s just computationally very expensive. Since you can programmatically create wallets and transactions that can obfuscate the origin of transactions. So by the time the funds reach any exchange the money has changed hands too many times for them to reasonably be able know if the origins of digital coin came from illegal activity. Then, by the time they do know it was stolen the funds are gone. Here’s the punchline though, since most exchanges do in fact keep records and the blockchain is an immutable list it’s only a matter of time till the software/computing resources adapt.
- an_opabinia 5y agoBanning crypto currencies would have no negative impact on the real economy and end ransom payments overnight.
- sanderjd 5y agoBan them how? Ban the on-ramps in the US so that companies can't legally purchase cryptocurrency with which to pay the ransom? Is that fundamentally different than making it illegal to pay the ransom in any currency? It seems that in either case, what you've done is push a company into breaking the law if they want to pay the ransom, which would probably deter most of them from doing it. Or do you mean banning both the US on-ramps and the foreign off-ramps? Are you optimistic that the US could get, for instance Russia, to enforce such a ban? I'm not necessarily opposed to this "just ban cryptocurrency" talking point, but I'm never sure I understand what people mean by it in practice.
- dodobirdlord 5y agoLaws can be made very broad and can generally lay out a ban and leave it up to those impacted to figure out how to comply with the law. A hypothetical law could criminalize possession of all cryptocurrency wallet keys for all US citizens and all corporations that operate in the United States, with a regulatory agency tasked with adding to the list of “cryptocurrencies” each time someone launches a new one. There’s no reason in principle that a law couldn’t treat cryptocurrency wallet keys the same way that the law currently treats child porn, i.e. destroy all of your keys by X date or go to jail if you are discovered to still be in possession of them after the date the law goes into effect. This would immediately destroy the entire cryptocurrency industry, and mining power in most or all networks would collapse to the point that the networks would essentially be defunct. Transaction volume and coin price on surviving networks could collapse to the point that it would be infeasible to pay an $XX million ransom, and ransomware developers would be back to where they were circa 8 years ago, with no real mechanism to untraceably receive millions of dollars.
- greyface- 5y ago
- deleted 5y ago[deleted]