10 ms·
Oakland declares state of emergency due to ransomware attack
- unxdfa 4y agoThis sort of stuff doesn’t surprise me any more. I’ve been on a number of “desktop support” sessions over the last few years and seen some shit. The common denominator seems to be entirely unpatched obsolete stuff (stock RTM windows 7 with stock IE in 2021 was my favourite) where either someone turned the updates off because they knew better or stopped paying their MSP for service immediately after they had been set up and assumed it’d just work forever. People like that and the associated competence level are rolling out the red carpet.
- qikInNdOutReply 4y agoIf its really important. Airgap. Or VM-Wrapped with restore points. I completely understand that somebody does not want to upgrade into the warp-abyss-abomination of modern windows, especially if huge expenses software was written once, that needs backwards compatability or contains sensitive data. You can not use windows if you work for anything with sensitive data. In todays world the legacy is the good stuff. Just needs protection.
- pjc50 4y agoAn airgapped system is one that's basically unusable because you can't communicate with other systems.
- AlexandrB 4y agoCan't help but think back to my youth where nearly every system was airgapped, but were plenty usable regardless.
- deleted 4y ago[deleted]
- mycall 4y agoA system can be more than one computer, i.e. mainframe. Airgapped systems can include multiple computers that are disconnected from external networks. They can be very useful for specialized applications.
- PeterisP 4y agoIt doesn't look like Oakland would have the IT people, time and skills to deploy and maintain a VM-wrapped infrastructure - which has all the same issues with needing to keep it up to date; e.g. I know people for whom this VMWare ESXi attack https://www.crn.com/news/security/vmware-esxi-ransomware-attacks-5-things-to-know/1 https://www.crn.com/news/security/vmware-esxi-ransomware-att... managed to ransom-encrypt both their main virtualization environment and also the backup one.
- CWuestefeld 4y agoI witnessed a ransomware attack where somebody in operations had a SMB share on their desktop to the backend storage for the VMWare ESXi cluster. So the ransomware was able to encrypt many of the vdisks.
- hanselot 4y agoI love people that believe there exists a version of windows that could be deemed secure. I was there once. Install the latest update to fix the security problems. Don't worry, our software becomes 300mb larger due to 500 other security problems we are rolling out today, but we managed to close off this one tiny hole over here. Why does it matter anyways. With both Intel and AMD running processors independent of your machine, there's really no way to keep anything secure unless you use a machine that's over 20 years old.
- jmpz 4y agoBut, isn't that backwards? 20 year old systems have been thoroughly exploited and usually do not benefit from more recent updates. It's true you can't patch every single vulnerability, but probability is a huge factor in risk. If many of the common exploits have been patched, it's simply harder for your average hacker, the difficulty and opportunity cost just go up.
- maccard 4y agoMicrosoft have 122k employees. Assuming that every one of them takes the upgrade, it uses an extra 61TB of storage. I can buy 61TB of NVMe storage from a high street retailer for under $5000. It's less than half that for a normal SSD. It costs more than that for the electricity to install the updates to 120k people I would bet. > there's really no way to keep anything secure unless you use a machine that's over 20 years old. This is nonsense. Security isnt a binary thing, and even if it was, you're still vulnerable to wrench-ops. If your threat model is that you suspect your procedure manufacture have backdoored your CPU, you better be running your own fab, air gapping your machines, and desoldering input ports. Meanwhile for probably 95% of people and businesses out there, keeping windows up to date, 2FA required, encryption in transit and at rest, and regular tested backups is enough.
- hulitu 4y agoWindows 1.0 was pretty secure by todays standards. /s
- bee_rider 4y ago
- santiagobasulto 4y agoWhat crypto are Ransomware asking for these days? After all the Bitcoin mixers seem to be taken offline (have they?). Sorry, I'm kinda out of the loop and was wondering how these thugs were cashing their attacks.
- Maxious 4y agoMonero https://cointelegraph.com/news/monero-crypto-of-choice-as-ransomware-double-extortion-attacks-increase-500 https://cointelegraph.com/news/monero-crypto-of-choice-as-ra...
- santiagobasulto 4y agoThanks! That is from 2021; is that still the case?
- tough 4y agonew mixers come around. there where some news about one called sinbad for btc recently which is being used to launder money by the NK hackers
- latchkey 4y agoYou don't need a mixer. There are plenty of ways to sell large amounts of BTC 'over the counter' in other countries.
- latchkey 4y agoSEC says that Do Kwon sold 10000 BTC to a Swiss Bank. https://news.bloomberglaw.com/securities-law/do-kwon-tapped-hoard-of-10-000-bitcoin-via-swiss-bank-sec-says https://news.bloomberglaw.com/securities-law/do-kwon-tapped-...
- midasuni 4y agoI don’t get why any user has the ability to cause so much damage. Sure they can lock their own files out and need to restore from backup, but how can that knock out other departments, let alone things like email.
- jmpz 4y agoIt's not any user, it's a ransomware attack. So it was intentionally done to limit their ability to work. Also, don't assume they had backups, or that these backups weren't also targeted.
- hulitu 4y agoSecurity is expensive.
- Lacerda69 4y agosurely less expensive than the fallout from this
- xvilka 4y agoTrue, but not always. Also, until something happens nobody would approve budget anyway. Exceptions from this rule are rare.
- tromp 4y agoPrevention is orders of magnitude less expensive than dealing with the fallout from an eventually inevitable atack. The tragedy is that in the absence of attacks, local governments don't always allocate the necessary funds to employing competent admins who take a proactive approach to security. Even more importantly, these admins need to be given authority to block attempts at lowering defenses in the name of convenience or "money-saving".
- deleted 4y ago[deleted]
- 4y ago
- Keyframe 4y agoAre there no agencies that can help out? CISA is, I guess, more of an advisory agency than operative? Or maybe there are but on federal level?
- bee_rider 4y agoI don’t think there’s much to be done retroactively. I’m sure there’s an option for proactive help (trainings, advice) but it is a big country, some attacks will slip through.
- pjc50 4y agoHardly anyone is interested in defensive security because if you do it well your job looks unnecessary. This goes both at the national security level and the individual organisation.
- PeterisP 4y agoAt this point it's too late, and before that they didn't really need advice or some fancy technology, they needed to dedicate enough resources/people/effort to simply do proper maintenance of their IT infrastructure. It's also plausible they simply couldn't afford the required resources, but that's not something fixable by CISA or other federal agencies.
- prox 4y agoIt’s really easy to cut back on your IT infrastructure until stuff like this happens, and suddenly everyone is up in arms about why something isn’t working. But it makes great budget headlines, “I slashed the IT budget in half!”
- alephnerd 4y agoWhen an extremely high profile attack like this happens, CISA ends up taking over the organization and revamping the entire organization's IT team. This happened to Atlanta back in 2018-19. It doesn't mitigate the current incident, but helps prevent the next one.
- 2Gkashmiri 4y agohow many of these systems will be safe if they had linux running? just saying because the linux is a smaller target and it would be a long time till it reaches the "year of linux desktop"
- alephnerd 4y agoThe same amount as would be if they were using MacOS or Windows 11. This isn't an OS issue, this is a "I didn't manage and configure my ACLs and RBAC correctly to minimize lateral movement in my environment" problem. Linux isn't anymore secure than Windows in that regard, as can be seen with ransomware such as Elbie. I can also say with extremely high confidence that in a number of orgs that are ransomware victim are running Linux seployments for their servers (usually Centos 6.x-7.x or RHEL6-7)
- throwaway14356 4y agoimho we have to look at what limited set of tools and functionality we really use. The days where we didn't know what computers were used for are long gone and the justification for doing everything in software along with it. You want to exchange strings of text with video and images. Not much more than morse code offered. Direction of dataflow can be easily enforced in hardware. The backup drive takes input that you can't read, you break off part of the print and it becomes read only permanently. It can easily be made an insane amount of work to regain write ability. A completely finished os can be stored on a read only device. We just have to start from scratch :) that is all it takes :)
- mdaniel 4y ago> A completely finished os can be stored on a read only device. ChromeOS has entered the chat Seriously, if it's good enough for school children, it surely is good enough for government. I love my Chromebook, and while I cannot yet do my day-job on it, I did interview at a crypto company that did do their day jobs on it, so I believe it's possible
- alephnerd 4y agoSo I work in this space and I am honestly quite surprised by the users here who think a Linux deployment would do any better. They won't. This isn't a Windows vs Linux vs Solaris vs BSD issue, this is a "did I manage and configure ACLs, RBAC, GPO, and other security features correctly" issue. For example, I've had customers have had RHEL 6.x enviromments that still got hit because they wrote a security group that allows all traffic from all ports from 0.0.0.0/0 (aka everywhere). Security issues always come down to misconfigurations and the lack of best practices in my experience. In that regard, the MS suite is actually superior to Linux because if you need a Security Solution Partner, Microsoft Professional Services is infinitely more competent than the largest Linux solution partner righ now (IBM).
- taeric 4y agoI'm with you right up to the "infinitely more competent" line. The big thing that Microsoft and Windows have against them, is the crapshow that is all that they include on a standard installation. That said, from what I'm seeing, this is not really unique to Windows anymore. Seems everyone wants everything on the machine. So, yes, it is theoretically possible to setup all access rules correctly. But it is essentially a lines of code problem, at this point. Given a mountain of things to setup, you will make a mistake somewhere.
- nradov 4y agoWhat specifically does a modern Windows installation include that is inappropriate or insecure in terms of default services or access rules?
- taeric 4y agoCertainly a fair question, but a big part of the problem is I don't know the specifics of what is on a new installation anymore. Worse, I'm not sure where to find such a list. Just scanning on the things they are proud to list at https://learn.microsoft.com/en-us/windows/whats-new/windows-11-overview https://learn.microsoft.com/en-us/windows/whats-new/windows-..., I'd be worried about Teams, Windows 365, and Widgets. I'd also be worried about all trial software that is on the machine. I could not find a list of that, though. And again, this is not unique to Windows. It used to be OEM bloat that was added to all things. In linux land, it would have been all of the "power tools" included by default.
- nradov 4y agoIn the modern threat environment it's no longer viable for small and medium enterprises to maintain their own IT infrastructure. This includes city governments. They should outsource infrastructure to one of the major cloud vendors with the scale and technical competence necessary to counter advanced persistent threats. It's a shame that we all have to pay this "tax" and give more control to a few big tech companies, but that is our reality.
- alephnerd 4y agoThey already have for at least 15 years.
- foepys 4y agoThis doesn't help. You still need people to configure the group policies and firewalls. You will also need a local installation on various PCs running on-prem to connect a lot of hardware. You might get away with Azure AD instead of a local domain controller and exchange but you won't get much farther than that. And if there isn't a backup strategy in place already, this won't change with cloud.
- chriscjcj 4y agoIt's been quite a few years since I did this kind of stuff for a living, so this may be an antiquated notion... "In my day," desktop computers saved their files to a server. That server would get backed up daily. The backup tapes/drives would be stored offline and rotated to an offsite location. (Back then you were more concerned about the building burning down than a ransomware attack.) The same would be true for any apps running on servers; their data/databases would be backed up daily and the tapes/drives used for backup would be stored elsewhere. What is this old guy missing? If a process like this were in place, nearly all of their data would be intact. Yes, it will take some time to do a full restore and you will be missing some amount of data that was created since the last backup. But it's survivable in many cases. And you're not negotiating with criminals.
- PeterisP 4y agoThe big change is that many places now send data to an offsite location (or cloud!) through a network instead of physically moving tapes, and the attacker can often use the same network connection to destroy backups.
- deleted 4y ago[deleted]
- scarmig 4y agoI think most backup providers (e.g. rsync.net) allow and encourage read-only backups. The bigger issue is that nowadays organizations have lots of interdependent systems, and if you seize the data of one, you basically cripple the entire organization. So for each system you need to institutionally require both backups and backup testing procedures, which is easier said than done.
- alephnerd 4y agoA lot of organizations also don't have the money or processes in place to manage backups. It's a huge cost outlay and in cash strapped SLGs, it simply ain't happening - especially when any half decent talent can make way more money working remotely for companies that respect Engineering.
- anigbrowl 4y agoThe emergency declaration will assist with equipment and materials and the activation of emergency workers as the city seeks to safely restore its systems. It's important to remember that 'state of emergency' is less of a 'everybody stop and listen to this' than a legal circuit breaker that allows the signing of checks and assignment of tasks without being bound by the normal web of procedure and contractual obligation. We tend to imagine (in popular culture) the executive aspects of government as being somewhat by fiat, but much of the time it's more like incremental product development, with most of the job being workarounds, excuse-making, bullshitting, and tedious social obligations.
- qwertyuiop_ 4y agohttps://www.oaklandca.gov/departments/information-technology#page-leadership https://www.oaklandca.gov/departments/information-technology... Are they ever going to hold the leadership accountable for sleeping on the job ?
- ChewFarceSkunk 4y ago[dead]