15 ms·
A Modest Proposal About Ransomware
- _wldu 5y agoCompanies could also stop creating monoculture networks that are easy to manage and also easy to compromise. When every device is a domain joined Windows 10 machine running some low level, 3rd-party centralized remote management system, it's just a matter of time before you are completely owned. This is the "Encryption Backdoor" problem in Computer Science (aka "Exceptional Access System"). It is impossible to build an exceptional access system and then ensure it is only used by good people to do good things.
- lima 5y agoSome of this monoculture and attack surface is necessary (line-of-business software, standard productivity tooling, the OS itself...) for the company to function. At least with remote management, you can respond at scale if one of those gets compromised.
- _wldu 5y agoThe problem is the entire thing will be compromised. Exchange, SharePoint, clients, servers, domain controllers, etc. That's what happens to monocultures. You must have diversity at every level (OS, DB, network, apps, etc.) Yes, it is more difficult to manage a diverse environment, but when you survive the next big ransomware attack you'll see why it's so important (while your competition struggles to recover). This holds true for crops, people, animals, financial investing and everything else. Diversity makes us strong and resilient. Monocultures make us weak. Monocultures are easier to manage, audit and predict, but their weaknesses outweigh those benefits IMPO.
- TheDong 5y agoWe have finite energy and knowledge. I know how to configure a firewall on linux. I don't know how to on plan9 and windows. Should I run Windows, Plan9, Solaris, FreeBSD, NetBSD, and Linux on my 5 servers to ensure I have diversity? To me, that makes it seem 5x as likely that I make a configuration error that leads to a critical vulnerability if I have to figure out 5 different ways to setup a firewall and sandbox. What about using software that historically has been shown to have vulnerabilities? For example, wordpress has had a lot of vulns in the past, so should I host one of my blogs on ghost, one using jekyll, one using wordpress, or should I only use a static site made with jekyll because I know static sites are more secure? If I'm allowed to eliminate wordpress there, why can't I eliminate diversity at other layers? I know linux is more secure than windows IME, so can't I just not run any windows hosts by the same argument that I won't use wordpress? You mentioned "diversity at every level (network)". Do you mean I should run wireguard VPN for some of my networks, cisco for others, unencrypted for others, just so I have more diversity? I'm genuinely curious because the model I've heard advocated so far is that a monoculture is more secure because you can eliminate less secure things (use wireguard instead of unencrypted traffic), and gain mastery of a small surface area to ensure it is harder to attack. Adding diversity just for the sake of it, by its nature, adds more attack surface and requires more expertise to secure, so it seems to fly in the face of the common advice I normally hear.
- throw0101a 5y ago> Should I run Windows, Plan9, Solaris, FreeBSD, NetBSD, and Linux on my 5 servers to ensure I have diversity? Running Windows and Linux would be a good start. Plenty of business-y software runs on POSIX systems: perhaps your business processes don't have to run the same operating system as your desktops? Having a file share appliance (e.g., TrueNAS, NetApp) would be a good step after that (if things get encrypted just revert to the last snapshot).
- TheDong 5y agoYou may have missed the point of the question. All my machines (business and servers) are currently linux because I know how to update and secure linux. The parent poster is arguing for diversity for the sake of it. To me, moving from my linux monoculture to a linux+windows diaspora seems less secure. I'm talking specifically about the idea of security through diversity, not about this specific incident, so backup recommendations aren't really related to this thread.
- webmaven 5y ago> Should I run Windows, Plan9, Solaris, FreeBSD, NetBSD, and Linux on my 5 servers to ensure I have diversity? No. At the scale of five servers, a monoculture is acceptable risk, and as long as other businesses at that scale are choosing different monocultures, the systemic risk is limited as well. But in analogy to agricultural monocultures, larger fields make monocultures more dangerous, and many adjacent fields with the same monoculture increase the risk even more. But geographic continuity isn't necessary in our networked world, so the analogy is of limited use, and any vendor with enough customers, no matter how spread out, makes an attractive target.
- fsflover 5y agoYou can run Qubes OS instead and enjoy security through isolation and diversity it provides by default.
- dllthomas 5y agoRansomware in particular requires the attacker to be able to make your data inaccessible; in order to do that they need a certain level of control over every system on which that data is replicated, and as you say avoiding a monoculture makes that (substantially?) more difficult. On the other hand, a leak or breach of user privacy requires exploiting any single system containing the data. Putting the same data on a diversity of systems makes that easier, and you won't even know what's happened if you've made it too difficult to "manage, audit and predict." Avoiding a monoculture isn't the security magic bullet you pretend it is.
- DougN7 5y agoDiversity just leads to more attack surfaces that have to be locked down. Doesn’t sound like a good idea. And even if you had it (33% of desktop OSes each on Linux, Windows and Mac), having 1/3 of your company neutralized is still a huge problem.
- ozim 5y agoUnfortunately companies cannot afford to build messy environments. Fixing small issues, on-boarding new people, explaining existing setups to already employed, adding new servers. That is nontrivial amount of money burned there "day in and day out" when networks are monoculture with centralized access. Making it a little bit of this flavor a little bit of other, will make those costs grow 100x in no time. This way you have 100x operational costs to prevent something that may or may not happen. Having messy environment also brings other risks like some operator might mess up easier because of being tired fighting that mess.
- majormajor 5y agoNon-computer-experts were sold computers and the internet as tools that would help them run their business. I find it hard to blame them too much for unexpected unadvertised technical problems. I propose something simpler: disconnect most computers from the internet, and don't put them places strangers can access them. Then build out the tools that work in that environment. I don't actually think it would work in practice, though, because it's a race to the bottom. The company continuing to do all their shit over the public internet with commodity PCs is going to be doing things more quickly and more cheaply initially, and may thoroughly beat the competition before getting hit by an attack.
- eikenberry 5y agoI believe the terminology for what you'd like to see is the zero-trust security model, and it is gaining acceptance as the new standard. https://www.nist.gov/publications/zero-trust-architecture https://www.nist.gov/publications/zero-trust-architecture
- easterncalculus 5y ago"The US always claims to have the best cyber-warfare capability on the planet, so presumably they could do ransomware better and faster than gangs like REvil. The US should use this capability to mount ransomware attacks against US companies as fast as they can." This is totally ridiculous. If anything, the US government needs to hack people less, stop dropping broken DLLs[1] and focus on defense. Security needs to be built up and incentivized, not punitively broken down. Practically all of the organizations hit by these huge attacks were not doing basic measures. Many of them not by CVEs from this year as this post implies. It also isn't even "ransomware" in this case since there's no ransom. It's just the government hacking your computer because the military-industrial complex (MITRE) doesn't like you. No hate towards them or CVE, but that's not a good look or policy. --- [1] https://blog.malwarebytes.com/threat-analysis/2021/01/cleaning-up-after-emotet-the-law-enforcement-file/ https://blog.malwarebytes.com/threat-analysis/2021/01/cleani...
- redler 5y agoThe article is attempting to follow in the satirical tradition of Jonathan Swift's "A Modest Proposal", which suggested feeding children to the poor in 18th century Ireland.
- f38zf5vdt 5y agoIndeed. :) This is as much about encouraging US ransomware attacks as much as A Modest Proposal was about eating babies.
- easterncalculus 5y agoI've read it, but I find the line hard to see with this article. There are several, maybe most, of the other claims that are actually true. Governments in general really do breach systems and drop malware like this, and most ransomware attacks aren't being performed with big zero day exploits. Jonathan Swift didn't cite his previous articles or actual newspapers, as I remember at least. After a couple more reads I should have picked up on them "shortening the grace period", that seems obvious. I got burned by this one.
- cjensen 5y agoSure, we could fix the flaws in every accessible software on the planet. Or we could outlaw non-traceable payment methods like Bitcoins so that there is no profit in ransomware. What are they going to do? Ask for payment of a million dollars in iTunes gift cards?
- kyleee 5y agoBitcoin is quite traceable; but I take your point. To flesh out your position, are there any circumstances in which you believe two parties should be able to transact securely and privately?
- bin_bash 5y agoIt's trivial to make Bitcoin untraceable. See tumblers. I think people also have this strange idea that the bitcoin ledger must represent all bitcoin transactions. But think for a minute that I can just email you a wallet and the coins just changed hands without putting anything on the ledger.
- rspeele 5y ago> But think for a minute that I can just email you a wallet and the coins just changed hands without putting anything on the ledger. I won't trust that you destroyed your own copies of the keys, so I'll want to transfer the coins to another wallet first thing with a real transaction recorded on the ledger. Otherwise I'm risking that at any time you could take the coins back from me.
- user-the-name 5y agoDoesn't matter much if it is traceable, as long as it can be converted into actual money. And it can, thanks to dodgy exchanges turning a blind eye or being actively complicit.
- f38zf5vdt 5y agoThat solves ransomware, which is bottom of the barrel in the hacker world. The reason talk about this is so much about _defense_ lately is because if people as untalented as ransomware operators can make it into US corporate and government infrastructure, imagine how deep in state-employed hackers must be. In the past decade US government infrastructure has been deeply penetrated multiple times, with catastrophic consequences. https://en.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach https://en.wikipedia.org/wiki/Office_of_Personnel_Management... https://www.wired.com/story/the-full-story-of-the-stunning-rsa-hack-can-finally-be-told/ https://www.wired.com/story/the-full-story-of-the-stunning-r... https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach https://en.wikipedia.org/wiki/2020_United_States_federal_gov...
- everdrive 5y ago>"The US always claims to have the best cyber-warfare capability on the planet, so presumably they could do ransomware better and faster than gangs like REvil. The US should use this capability to mount ransomware attacks against US companies as fast as they can." I wonder why it is presumed that the US has the best cyber-warfare capability? Why do we think this is true?
- karaterobot 5y agoIt isn't presumed, it's claimed by the U.S., and the presumption the author is making comes from granting that claim for the sake of his(facetious) argument. Whether it's true or not doesn't matter. I don't think you'll find many countries making claims of weakness on defense-related topics. In the same way that no country would just announce that they have the 11th or 12th greatest military in the world, they'd never say they have the 2nd best cyber-warfare capability either.
- cookie_monsta 5y agoHere in Australia I think most people would agree that our capabilities are are, ahh... y'know... not too shabby. But then we like to walk softly and carry big sticks :)
- ralfd 5y agoWhat is the proposal?
- only_as_i_fall 5y agoI assume this proposal is at least somewhat tongue in cheek based on the title, but if the US really wanted to nip this in the bud could they not instead make it a crime punishable by jail to pay the ransom?
- wmf 5y agoThat may or may not help. If a company has a choice between going out of business or some probability of the CIO going to jail you know what they're going to choose.
- only_as_i_fall 5y agoBut the choice is really between a personal risk of going to jail or a personal risk of finding a new job. As long as the individual risk outweighs the collective reward the incentive to lie should be small. Besides, unless 2 or 3 execs can also implement the recovery procedure without any of their engineers catching wind I don't think it's likely that the secret would remain well kept.
- ithkuil 5y agoThe CIO can resign instead of going to jail. It all depends on how strictly the law gets e forced. If only a few get caught, then it becomes a dishonor to not have "the balls" of just risking it, and you'd not get a new job as CIO if you didn't want to play it out. But if it's guaranteed to get caught, nobody would do it.
- webmaven 5y ago> The CIO can resign instead of going to jail. It all depends on how strictly the law gets e forced. If only a few get caught, then it becomes a dishonor to not have "the balls" of just risking it, and you'd not get a new job as CIO if you didn't want to play it out. But if it's guaranteed to get caught, nobody would do it. Right. Humans don't strictly adjust their behavior according to the game theoretic adjusted risk (penalty × probability). Raising the odds of getting caught tends to work much better than increasing the penalty. That said, one of the outgrowths from this observation has been Broken Window Theory (that credits a drop in larger crimes to increasing enforcement and speedy mitigation of other - highly visible - minor infractions), which turns out to be more of a just-so story. You mostly have to increase the odds of getting caught for the crimes you are most interested in deterring rather than something else.
- mdoms 5y agoCrypto "currency" is the worst thing that has happened to the internet. Without crypto "currency" there's no ransomware.
- irq-1 5y ago> The US always claims to have the best cyber-warfare capability on the planet, so presumably they could do ransomware better and faster than gangs like REvil. The US should use this capability to mount ransomware attacks against US companies as fast as they can. As ridiculous as this sounds, a private sector version could work. Imagine 'hacking' companies that audit municipal services and private companies. The hackers would have to be motivated to win, by payment, not just go through a security checklist. Insurance and law could demand this sort of active and ongoing security check. This would also create diversity in hacking systems instead of one governmental set of tools and strategies.
- oh_sigh 5y agoThe US wouldn't maintain their capabilities for long if they were burning all of their zero-days on defensive posturing.
- tedunangst 5y agoVulnerabilities Equities Process!
- muricula 5y agoThis exists: https://en.wikipedia.org/wiki/Penetration_test https://en.wikipedia.org/wiki/Penetration_test
- hoppyhoppy2 5y agoRight, but I think they're talking about a marketplace of friendly hackers that are motivated by big winnings if they successfully penetrate a system. As opposed to a security consultant who gets paid to test a company's security and write a report, regardless of the findings. This does already exist, to a limited extent, as the security bug bounty programs that some companies have on public offer. For example, Amazon says they'll offer you $15,000 if you find a "critical" security bug in one of their services; Google offers up to $31,337 for discovering a remote code-execution bug. https://hackerone.com/bug-bounty-programs https://hackerone.com/bug-bounty-programs
- imglorp 5y ago> The NSA routinely hoards 0-days, preferring to use them to attack foreigners rather than disclose them to protect US citizens (and others). This short-sighted policy has led to several disasters, [...] Unless they are immediately required for a specific operation, the NSA should disclose 0-days it discovers or purchases The author too charitably positions NSA here. When one considers the hoarding of 0-days, weakening of encryption standards, wrecking trust in US businesses by forcing compliance, failing to intervene in years of breaches, and many other malicious activities, it soundly refutes any claim of concern for protecting the country. How many billions has this cost in business terms, on top of the billions they're paid for the privilege? So if defense isn't their actual mission, maybe it's actually population control. https://reason.com/2014/07/11/total-population-control-is-nsas-goal-sa/ https://reason.com/2014/07/11/total-population-control-is-ns...
- kovacs_x 5y ago.. or maybe there should be a small "system service" that looks particularly for such a "mass encryption pattern"?
- dakial1 5y agoOR the US could fund hacker groups that only target Russian companies, in a quid-pro-quo mode. For every ransomware attack to US companies there would be a retaliation asking the same ramson value to a Russian Company (or oligarch) That would get the Russian government working.
- rosege 5y agoI wonder how hard it would be to spoof that your computers are using Russian as the default language so that the code wont execute in your environment?
- jl2718 5y agoBLUF: government should attack vulnerabilities first, disabling systems until they are patched. Very creative. It might also be done better with an open market where companies set the price there’re willing to pay for red hats. This also requires some understanding of how zero-days come to exist. Briefly, insiders, many of them foreign assets developed from their earliest education and helped along the way to get to their target. There are some ‘in the wild’ discoveries, but the sophisticated attack chains do not rely on luck. Given that, here’s another viewpoint: $70m in ransom might be a far better deal than exploitation by a nation state. It’s quite possible that these guys are actually defectors doing us a favor. So, we should consider that security is something we’ll have to pay for one way or another, and we should seek to establish markets that make that cost predictable and minimize disruption. And yes, I do understand the moral hazard this would create, and I don’t have any good ideas to fix that right now.