7 ms·
Why the ransomware crisis suddenly feels so relentless
- blakesterz 5y agoTo me at least, it doesn't feel relentless, and it's not sudden at all. It has been relentless for years now. I'm glad to see it getting more attention, finally, and more people are suddenly paying attention to the problem. This is a short and sweet look at the problem for people who are just now suddenly noticing the problem. They say it’s the result of inaction, new tactics, criminals having safe harbor and ubiquitous connectivity . I'm surprised they don't call out the "mostly unregulated cryptocurrency" stuff a bit more as a cause as well.
- jordanpg 5y agoIt's hard not to see this as ultimately a good thing for the world. The market will not spend one dime more on security than is needed to maintain lines of business, and that includes things like perception of risk and mitigation. If there is enough pain, whatever level of baseline security is needed to protect most orgs against these attacks will become the new standard. And then this threat will be replaced by a new one.
- splithalf 5y agoCouldn’t disagree more. If that would happen, why hasn’t it happened yet? There are pirates and terrorists too, and they don’t make the world better or safer, quite the opposite.
- panzagl 5y agoI dunno, when I go to Mexico I don't look at the heavily armed guards outside of a bank and go 'gee, it's a good thing there is so much violent crime here otherwise we wouldn't have these armed guards here to protect us from it'.
- throwaway3699 5y agoThe internet isn't like that. You can be attacked from one individual living in a mountain in another hemisphere.
- fireball_blaze 5y agoI think you're hinting at a Broken Window Fallacy [1] here. I disagree that these cybercrimes are a net positive for the world. [1] https://en.wikipedia.org/wiki/Parable_of_the_broken_window https://en.wikipedia.org/wiki/Parable_of_the_broken_window
- notmarkus 5y agoIt's bad when bad things happen, no one will protect against bad things happening unless bad things happen, so it's good when bad things happen.
- Miner49er 5y agoI see it like a vaccine. A ransomware attack is generally not as bad of a damage as a real attack. A vaccine might make you feel kind of bad, but it's not as bad as the thing it protects against. Plus, there's other benefits. Companies might at least think a bit more about storing data about people (their employees, customers, etc) if there's a risk of it being stolen in a ransomware attack. That's a win for privacy overall.
- deleted 5y ago[deleted]
- amackera 5y agoOn the contrary, every media piece I've read about ransomware mentions cryptocurrency in menacing terms (connected to criminals), many implying cryptocurrency is the cause of this new wave of attacks. Of course, lamenting the fact that cryptocurrencies exist isn't getting us any closer to a solution to the problem, but ¯\_(ツ)_/¯ media gonna media.
- eli 5y agoBut cryptocurrency is what led to the scaling up of these attacks.
- user-the-name 5y agoThey "imply" it because it is 100% true. Cryptocurrency is the cause of the rise of ransomware.
- JKCalhoun 5y agoI suspect it was a little harder to demand a ransom when your options were picking up a suitcase of unmarked $20's or a gift card to Home Depot.
- gorbachev 5y agoThe big change from what I've seen is the systemic, business-like approach by the ransomware gangs. It's not script kiddies randomly poking at IP addresses any more, but small businesses running with proper planning both operationally and financially.
- slackfan 5y agoBecause media has a narrative to push.
- king_magic 5y ago… which would be? These are criminals, often state sponsored criminals, that are carrying out literal acts of war against US infrastructure. So what’s the “media’s narrative” here?
- someguydave 5y agofork over more powers to the surveillance state
- JKCalhoun 5y agoI don't see why the media would want that. They are finding out that the previous "surveillance state" secretly scooped their phone records.
- iammisc 5y agoThey're trying to explain away inflation causing high meat and oil price
- emc3 5y agoEnd Bitcoin.
- mikewarot 5y agoI've been writing about the insecurity of Windows, MacOS and Linux since 2005[1], nothing is sudden about this. We still collectively haven't learned the need for Capability Based Security[2]. I give it 5 more years before people finally catch on. [1] - http://mikewarot.blogspot.com/2005/08/secure-computing.html http://mikewarot.blogspot.com/2005/08/secure-computing.html [2] - http://evlan.org/concepts/capabilities/ http://evlan.org/concepts/capabilities/
- bumby 5y agoRegarding your second link, I'm curious about your thoughts of wide implementation in case I'm misunderstanding: For a general user, this may just turn into the equivalent of "Terms and Conditions" acceptance. Most just blindly accept them because we're focused on the end-action. The same seems to go for allowing apps access to much of our phone data. In that sense, it doesn't really mitigate user risk (but does give legal cover). Is there any evidence that general users will "see something fishy was going on" enough to actually change behavior?
- mikewarot 5y agoWallets, the kind that fit in your pocket, containing cash, the folding kind of money, are an example of capabilities that are widely used. People don't just hand over their wallet, they chose the amount to tender in a transaction, which is the most they could lose. If someone asks me to hand over my wallet, I know I'm being robbed. In a capabilities based system, you pick what files to give to an application, instead of the application showing you a dialog and then getting them itself. As far as the user is concerned, the UI doesn't even need to change. It is my long held belief (2005!) that capability based systems are the only way out of this nightmare.
- AnIdiotOnTheNet 5y agoThe big thing I think that needs to happen for this to stick is for the UI to make sense. There has to be some obvious and convenient way for me to provide the things the application needs, without it being a pester-box with an OK button. Some of that already exists on desktop OSs but seems to have been abandoned. Drag and drop file loading is commonly available but applications still seem to insist on file dialog workflows. Drag and drop saving even exists in RiscOS and ROX-Filer. But how do we abstract other resources like cameras, keys, contacts, network ports, or money? Is it as simple as having drag-and-drop-able representations of those things? Do I drag $5 out of my virtual wallet into Steam? My bank password from a virtual keyring? Connect a virtual cable to the application window from an icon representing my camera? Sadly, the desktop metaphor itself is out of fashion as everyone went insane when the iPhone came out, so I expect it will be a lot longer than 5 years before any of this is explored in any depth.
- black_puppydog 5y agoImagine the knowledge of a 0day (and how to fix it) as being the cure for a disease. Picture what withholding it would look like. In this year, if ever, people should realize how crazy dangerous and irresponsible this kind of behavior would seem if it happened to not be done with software. So here's an idea: improve security by stopping the hoarding of 0days. Built a company that buys 0days and doesn't immediately turn around to get them fixed? Too bad, this is a business model that leeches off everyone's insecurity and now deemed unethical like so many other seemingly-genius business plans. If you're that good, go find a different thing to do with your time. Note that this applies to states too: in my book they're welcome to buy/incentivize 0day info, but only to then get stuff fixed ASAP. Any state that keeps a 0day "just in case" is failing to protect (among others) its own citizens.
- knodi123 5y agoare there any companies hoarding 0days? I know the CIA does, but asking for ethical behavior from them seems like such a long-shot that it would make sense to decouple it from more achievable goals.
- gruez 5y agozerodium?
- celticninja 5y agoZerodium is probably the most well known, but many Israeli cyber security firms will also buy them, hacking team out of Italy would. There are plenty of buyers but their customers are government so you don't really hear of them.
- knodi123 5y agowow, I had never heard of them. what a sick business model. I guess in a world of 7 billion people, there's going to be someone willing to fill any niche.
- azemetre 5y ago
- flerchin 5y agoOutlaw crypto. Ransomware would go away overnight, the electricity would no longer be wasted, people could afford to play videogames again. The only downside is the collapse of a no-value asset bubble.
- not_really 5y agoOutlaw torrenting while you're at it
- anikan_vader 5y agoGeneral purpose computing seems to be the real issue here. Might as well ban it while we've got the chance. If people want to compute something, they can use their brains! In seriousness though, banning cryptography would appear to have many more serious consequences than the elimination of Bitcoin. Free speech would take a big hit for starters. If the concern is regarding the waste of electricity, then why not apply a tax on energy equivalent to the associated negative externality? That way everyone who wastes electricity will be charged equivalently, and the government won't have to determine which use cases are "useless." (Personally I think mining gold for jewellery is almost as useless as mining Bitcoin -- both certainly have an aesthetic beauty to them.)
- Tainnor 5y ago> In seriousness though, banning cryptography [...] I think, when they say "ban crypto", they mean "ban cryptocurrencies". I, too, find it deeply unfortunate that some cryptocurrency nerds have suddenly decided that a term that has for a long time been used to refer to cryptography should now suddenly be understood to refer to cryptocurrencies excusively, but it's not the first time I witness this misunderstanding.
- admeyer 5y agoHow much do companies and governments buying back their data and secrets in these attacks push up the prices of the cryptocurrencies used for the ransoms? What % of ransomware attacks are not reported to the media?
- gorpomon 5y agoThe article hits some spot on notes. The other missing piece is just how non-technical organizations can be out of their depth when it comes to the lifecycle of IT hygiene, vulnerability management and training its staff to be security minded. A mid-size school district really has two options to secure itself: get the expertise in house, which could result in easily exploitable gaps, or spend non-trivial amount of budget working with endpoint protection vendors. I can imagine it's hard to explain to a rural school board that you either do this now, or pay majorly later. Luckily for everyone, the endpoint protection market is evolving rapidly, and these solutions do work. Big Game Hunters aren't super humans, they exploit the things that on-the-ball IT teams and endpoint security vendors can easily fix: unpatched vulnerabilities, misconfigured endpoints and mismanaged credentials. Unluckily for everyone, the threat actors, for the reasons laid out in this article, are evolving too. And on top of that there's no shortage of vulnerabilities either. I expect things to get worse before they get better. But do I expect Big Game Hunting to be a major problem in 15 - 20 years? I don't think so, because eventually every IT device in most any organization will have some type of cloud connected security baked into its cost. Do I think there's a likelihood it will be worse in 2-3 years, most likely yes.
- philamonster 5y agohttps://twitter.com/viking_sec/status/1400236266441089025?s=21 https://twitter.com/viking_sec/status/1400236266441089025?s=...
- vmception 5y ago4 popups before you can read the article, new record
- Someone1234 5y agoUntil you hold these companies and their management directly responsible: It will continue. The issue here is the same as it has always been: Cost cutting, poor management, poor oversight, and laziness. We have infrastructure sensitive industries being hit and in the years preceding the hits full of heavily reported ransomware incidents zero audits were conducted that flagged these problems, backups strategies weren't reformed (i.e. they have no offline backups), network onioning wasn't utilized, and other basic 101 security strategies weren't employed. All we hear over and over is "they're CRIMINALS," "they're in [foreign country]!" but ultimately that is a distraction; there will always be criminals, and they will always operate beyond the reach of the law. What matters is mitigating their ability to do damage which we absolutely can and should do. If senior management started being fired and companies heavily fined this problem would magically disappear (or its impacts substantially reduced, like a two-day outage while they restored offline backups instead of multi-week). This isn't because criminals stopped being criminals, it is because this is all just a symptom of a different problem: Corporate responsibility, or lack thereof. Congress should take action, fund mandatory audits on private infrastructure companies and impose large fines on companies & senior executives that cause widespread disruption. Even the threat would be highly effective and the pocket-books would magically open to pay for security professionals and fixes.
- deleted 5y ago[deleted]
- genmud 5y agoI may have an extremely pessimistic view of things, but things aren't going to change until the incentives have changed. This is nothing new, or surprising if you look at human nature. The big issue with security these days is that bad behaviors are not just common practice, in many cases they are incentivized. Many companies have pushed the risk into cyber security insurance policies, or if they haven't they can create massive paper "losses" when a cyber incident happens. Prior to ransomware, if companies were smart, they can actually make money off a cyber incident, versus spending money to prevent an incident. I would say the tipping point for many executives was in that realizing that the Equifax breach (one of the biggest in history up to that time) had literally zero impact to their businesses long term. The company was focused on monitoring credit and many would have assumed the company would have a responsibility to secure its data. Unfortunately this was a light bulb moment for many execs and the light bulb wasn't a good one for their customers or society at large. They basically found out that data breaches don't really matter and if you weather the storm there is very little impact to your business. Yes your customers lose their data, but if you need to minimize overhead costs, why spend a ton of money on a security program that doesn't have a guarantee in stopping it anyway. Fast forward to 2021, with crypto being so ubiquitous and realizing that companies have largely forgot or shut down their Business Continuity Planning (BCP) programs they stood up after 9/11, bad actors are having a field day. Actors were very active stealing DBs and trying to extort people, but they largely found that people just either didn't believe them or didn't care. With ransomware, they basically prevent the business from doing anything and that is something that is just not something that can be ignored like data theft/extortion attempts. If someone steals your customer ACH information from your accounting database, no big deal, but if you can't accept payments from your customers... They are literally not making money. I have worked in information security for ~20 years and I don't believe that there will be any improvements until there are major changes to the incentives that customers have to protect their customer information/data. If anything the ransomware threat is one of the few things actually causing many companies to invest in their security programs.
- Tainnor 5y ago> [...] until the incentives have changed. I think it's not only individual incentives, it's also the incentive structure of whole ecosystems. The way we write software nowadays (or even do other business processes) includes so many complexities and therefore potential attack vectors that I doubt anyone anywhere doesn't have gaping security holes unless they're writing code on airgapped systems where every component is thoroughly vetted or something. Just take a look at the crazy amount of (transitive) dependencies that any average web app (frontend or backend) has nowadays, or all the different infrastructure components.
- musicale 5y agoI'm definitely in favor of blaming Trump and Russia, because we certainly can't blame: - tech companies for selling software and hardware riddled with security flaws - the legal system for absolving said companies from any liability whatsoever - customers who are unwilling to pay more for reliability, security, or recoverable backups - those who pay the ransoms, ensuring steady income for criminal extortionists.
- giantrobot 5y agoI think we're seeing two things: increased reporting because of increased interest and an actual uptick in actual ransomware attacks. The rate of attack isn't necessarily increasing with the rate of increase in reporting but both are up YoY. For increased interest, the Colonial Pipeline shut down had huge far reaching affects beyond the cost to the company. News of the situation reached beyond tech wonks. It also impacted tons of people not directly related to CPC. To the uptick in successful attacks, the increase in working from home probably has a lot to do with it. A virus that wouldn't make it past an enterprise firewall will more easily hit some user at home. They then connect to the corporate VPN for work and bridge past a lot of firewalls and IDSes. Companies they might have decent network security are poking a lot of holes to handle people WFH that never had previously. Joe from Accounting that's a wiz in Excel but falls for every phishing e-mail that hits his inbox is a bigger problem WFH than when at the office. He's a match in a powder mill when he connects to the corporate VPN from his malware riddled home PC. Was he not supposed to install totallylegitzoominstaller.exe from totesthisiszoom.ru?