Live data from Hacker News

Maersk, Me and NotPetya

gvnshtn.com

41–50 of 59 posts

Re: Maersk, Me and NotPetya

#41
post #37
post #32

Earlier quoted context omitted.

> Does anybody here think that even adopting and correctly practicing all practically deployed recommendations of the security industry that a system could resist such an attack? There are multiple examples of organizations successfully thwarting advanced attacks by following (and exceeding) industry best practices. Most of that stuff isn't disclosed to the public unfortunately. Coinbase incident from the last year i…

Thank you for your response. Unfortunately, that example is about 2 orders of magnitude (100x) cheaper to do at market rates than the standard I proposed before the questions of $30M. I arrived at the number of the thwarted attack by looking at Zerodium payouts https://zerodium.com/program.html where a Firefox RCE+LPE goes for up to $100K, so even if we say both such exploits were a RCE+LPE (they are not, the pair am…

You're right, that wasn't a 30M attack. But that's because there aren't any 30M attacks that we know of (coming from economically-motivated attackers). NotPetya as a whole would have cost So, your math just does not represent real life. Criminals that have 30M lying around are looking for a way to get out and would rather invest their money into legitimate(ish) businesses with lower ROI, criminals that don't have 30M would rather invest into multiple smaller campaigns with higher ROI rather than putting all their eggs into one basket, developers that can attract valley level salary on black market can also find positions in the valley or at defense contractors.

On the other hand just because company faces X damages does not mean they are willing to pay anywhere near to X to avoid them. Ethical issues aside, Maersk would have faced impressive damages even if they decided to pay out ransom. Their operations would have been disrupted regardless, they would need to carry out the massive data restoration anyway. Their networks where compromised and there were no guarantees about consistency/integrity of restored data or that paying out ransom wouldn't make them even bigger targets and that hackers (possibly some other crew) wouldn't return next week through the same or different vulnerabilities. So they would need to plan extremely fast migration to win10 in any case, as well as fixing their network architecture, permission systems, putting in place mitigations, buying new defensive solutions and requiring various consulting services. It is hard to say how much money would they be able to save if they would have chosen to pay ransom (and if NotPetya was a ransomware), but it wouldn't be anywhere close to 300M, maybe just > If I want to be even more pedantic

That's ignorant not pedantic. Attackers spent month on spearphishing attacks targeting Coinbase engineers specifically which included making verifyable fake identities and compromising Cambridge web & mail systems. That's exact opposite of a large-scale opportunistic attack.

Re: Maersk, Me and NotPetya

#42
post #40
post #35

Earlier quoted context omitted.

You are wrong to focus on 300M. That's the cost of dealing with consequences of an attack, not the cost of measures that would have prevented it. So, you're right to say that attacking some businesses leads to >10 ROI for an attacker (actually much higher ROI are quite common although with lower thresholds), but that's only assuming that these businesses do not invest into proper protections ahead of the attack. The…

I agree with your statement on the point of infosec. I disagree that any particular infosec organization is equipped to deal with problems of this class in any meaningful way. In fact, it is so far off as to be mind-boggling and probably criminally irresponsible. To this end, I will clarify what I meant. I believe that an attack funded on the order of $30M would be able to do $300M in damages to Maersk even if Maersk…

> I disagree that any particular infosec organization is equipped to deal with problems of this class in any meaningful way.

FAANGs are bigger targets and yet none of them suffered anything remotely similar.

> An attack, able to do $300M in damages that Maersk can not prevent after we have assumed it already did the best it possibly can, should be able to support a $100M extortion payment.

That's incorrect. I already mentioned it in another reply, but in short it does not matter that attack caused 300M in damages. What matters is how much Maersk could possibly save by paying out ransom. And that's a fraction of those 300M not even including secondary effects such as potential problems with tax office, reputational damage or having to deal with becoming a target #1 for every other ransomware crew out there - as they just proved that they are ok with paying out for such "unsolicited penetration tests". It also misses that even if Maersk payed out 100M, criminals wouldn't have any way to actually benefit from all of that, as laundering such amount of BTC isn't trivial and historically that's exactly the step with highest risk for the criminals.

> How much do you think it would cost for a targeted attack to breach and cause significant damage to the best system you have every personally observed?

That's a non-answerable question as it does not mention other resources that are available to attacker besides pew-pew internet weapons, restrictions that they potentially face, the risk they are comfortable with, and basically all of these questions applied to the defensive side as well (i.e. on a furthest side of the spectrum there are certain systems, attacking which would put you above ISIS leaders on a to-be-droned-soon list).

Re: Maersk, Me and NotPetya

#43
post #41
post #37

Earlier quoted context omitted.

Thank you for your response. Unfortunately, that example is about 2 orders of magnitude (100x) cheaper to do at market rates than the standard I proposed before the questions of $30M. I arrived at the number of the thwarted attack by looking at Zerodium payouts https://zerodium.com/program.html where a Firefox RCE+LPE goes for up to $100K, so even if we say both such exploits were a RCE+LPE (they are not, the pair am…

You're right, that wasn't a 30M attack. But that's because there aren't any 30M attacks that we know of (coming from economically-motivated attackers). NotPetya as a whole would have cost So, your math just does not represent real life. Criminals that have 30M lying around are looking for a way to get out and would rather invest their money into legitimate(ish) businesses with lower ROI, criminals that don't have 30M…

Before I get onto the main topic, the timeline seems to indicate that non-Coinbase engineers were also targeted by the attack given that, to paraphrase, it says: "Early June: people click link" and in a separate block "June 17: Coinbase employee clicks link". Using that reading, which may be mistaken, I concluded that it is non-targeted. If it is non-targeted then the fake Cambridge identities were presumably used on all targets which would then make it purely opportunistic as well. Luckily, even if my reading is incorrect, it does not affect the conclusion I wrote since it assumed the strongest possible interpretation of a targeted attack.

Onto the other topic, yes I agree there are probably no $30M attacks in the wild. This means that every attack that hits and breaches a company is less than the standard that I proposed. Given that essentially every major company using every combination security solution has been successfully attacked and the situation of continuous hacks has only gotten worse over the years, this supports my position. The lack of $30M attacks is most likely an indication of the immaturity of the attacker market. The fact that an entity can accidentally do $250M in damages to a company, get away with it, and nobody is trying to do that themselves all the time is plain incompetence in the criminal industry. To further support my point that the attacker market is immature, the number and size of economically-motivated attacks has been rapidly increasing over the years. 30 years ago, it was all pranks. 20 years ago it was all data loss. 10 years ago it was all cheesy $200/computer ransoms from consumers. Now we are seeing hospitals being ransomed for $1M. Given the cost of these attacks it is massively profitable at this stage to continue upping the ante.

I computed $30M by back-calculating from the damages with an extortion payment of $100M from an extortion damages of $300M. I think this is a reasonable analysis, but you are free to substitute your own numbers on those. If I wanted to give a forward-calculated number based on my knowledge of attack difficulty, I would say that a targeted attack by a competent adversary whose primary goal was to extort Maersk and researched how to actually do damage would be able to allocate ~$10M and cause ~$10B in damages. As for how they might do such damage, they could hack every ship in their fleet and crash them into each other or land. They hack the ships while they are at sea and crash them into cruise ships. They could take over the shipping cranes and drop containers incorrectly onto ships destroying them. They could make the shipping cranes operate in unsafe parameters destroying all of them. They could use the shipping cranes to drop containers on the employees. They could reorganize the shipping manifests subtly over a few weeks to violate shipping agreements that Maersk made. They could sit on every computer until backups are made and then take over the backup systems and destroy them then destroy all the existing systems and servers and wipe the shipping manifests. The list goes on.

If you want cases for other companies that might be desirable to attack with high extortion value:

An attacker could take over every 2019 Camry then wait until rush hour to engage the ABS so the brakes do not work, engage the cruise control to 120 MPH, then engage autosteer to turn slightly left (or right depending on your country). They would kills tens of thousands in 3 minutes which would completely irrevocably destroy Toyota.

An attacker could take over every internet connected GE stove with remote turn-on capabilities (they make these, seriously) and engage the gas at 3:00 AM then wait 30 minutes then ignite blowing up every house with the stove killing everybody inside while they are asleep and at least thousands worldwide which would completely irrevocably destroy GE.

An attacker could hit Merck (also hit by NotPetya for apparently ~$1.3B or more) by targeting one of their pharmaceutical plants to either vent and over-pressurize all of the chemicals so they explode into the nearby community or you could re-tune the chemistry to increase toxicity while preventing the automated QA systems from rejecting them which would both completely irrevocably destroy Merck. The list goes on.

Given the continuous failure to protect against attacks less than $10M by every company in every industry for decades I see no reason to give the benefit of the doubt to any of these companies, so I assert that not a single one of these companies can protect against an attack funded on the order of $10M where as the extortion value is in the tens to hundreds of billions and thousands of lives. I further assert that there is not a single well known company in the world that can do so and is willing to make that statement in a legally binding manner. And, even if they did so, that is still only minimally sufficient for unimportant industries. A thousand lives should not be subject to the whim of someone with $10M, that is criminally irresponsible in the actual sense where you should go to jail if you do that. For the cases I gave above, you probably need a number on the order of ~$100B on the low end.

Re: Maersk, Me and NotPetya

#44
post #42
post #40

Earlier quoted context omitted.

I agree with your statement on the point of infosec. I disagree that any particular infosec organization is equipped to deal with problems of this class in any meaningful way. In fact, it is so far off as to be mind-boggling and probably criminally irresponsible. To this end, I will clarify what I meant. I believe that an attack funded on the order of $30M would be able to do $300M in damages to Maersk even if Maersk…

> I disagree that any particular infosec organization is equipped to deal with problems of this class in any meaningful way. FAANGs are bigger targets and yet none of them suffered anything remotely similar. > An attack, able to do $300M in damages that Maersk can not prevent after we have assumed it already did the best it possibly can, should be able to support a $100M extortion payment. That's incorrect. I already…

That is not an unanswerable question at all. To clarify, I am literally asking for a simplified threat model. Take an existing threat model, reduce it to cost of doing those actions, done. Order of magnitude is fine. If there are parameters, pick a set of parameters within the non-totally-stupid range and state them. Estimate when reasonable. The question is just me looking for broad strokes anecdotes.

Re: Maersk, Me and NotPetya

#45
post #38
post #11

As someone with very limited Microsoft/Windows background, I would be curious to somehow better understand how these lessons would apply to the Linux world. What are the Linux equivalents of pass-the-hash, TAM/PAM/PAWs etc?

Other answers are good, but no one mentioned *nix equivalent of PTH. Admittedly it's not exactly the same, but from an attacker's perspective it can be used with similar effect. This equivalent (which works on Windows as well, btw!) is pass-the-password. There are two requirements for this to work, both much more common in the wild then hip HN DevOps crowd would like you to believe: 1. root or other privileged accoun…

> The attacker gains superuser access on one system, then tricks admin to log in and gain root privileges, disclosing their password during that process (by swapping binaries, process injection, reading memory, rootkits, etc).

Just gaining access to the admin's login account (ie. one from which the admin runs SSH) is enough - alias sudo=/home/admin/.trustmeimadolphin.sh in .bashrc and wait.

Re: Maersk, Me and NotPetya

#46
post #29

Earlier quoted context omitted.

How would that have helped? The finance software that started the breach was legitimately needed and would have been whitelisted.

One of two things: Either the malware modifies the finance software, and is executed as part of the finance software, but the checksum for the software is now different and can't run. Or: The executable malware code is separate and only triggered by the finance software, which will fail to execute it, because the malware isn't a whitelisted application. At any rate, the malware would never be able to escape beyond th…

NotPetya authors penetrated the accounting software vendor and planted their attack code in a regular update.

Re: Maersk, Me and NotPetya

#47
post #43
post #41

Earlier quoted context omitted.

You're right, that wasn't a 30M attack. But that's because there aren't any 30M attacks that we know of (coming from economically-motivated attackers). NotPetya as a whole would have cost So, your math just does not represent real life. Criminals that have 30M lying around are looking for a way to get out and would rather invest their money into legitimate(ish) businesses with lower ROI, criminals that don't have 30M…

Before I get onto the main topic, the timeline seems to indicate that non-Coinbase engineers were also targeted by the attack given that, to paraphrase, it says: "Early June: people click link" and in a separate block "June 17: Coinbase employee clicks link". Using that reading, which may be mistaken, I concluded that it is non-targeted. If it is non-targeted then the fake Cambridge identities were presumably used on…

> Using that reading, which may be mistaken, I concluded that it is non-targeted.

That's a wrong reading. The attackers were specifically targeting Coinbase employees although there were some instances where people with the same name and working in the same field (but not for Coinbase) got emails as well. The reason they say engineers clicked on a phishing link only on June 17 is precisely because it was a quality attack. The emails where personalized, written by literate English speaker and didn't contain any attachments or links at all initially. They only sent a link to an exploit after exchanging a few emails, confirming target's identity and establishing trusted relationship.

> Given the cost of these attacks it is massively profitable at this stage to continue upping the ante.

Sure, that's the general trend. But cost of the attacks also rises due to software becoming more security-aware. Just the fact that all major browsers and Windows 10 have auto-updates enabled by default (and hard to disable) has basically killed exploit kits, although that was a booming market less than a decade ago. Legitimate security job openings have exploded as well (including remote positions) with the HR focus shifting from costly certifications to practical skills, which gives would-be-hackers more possibilities to choose lighter hat to wear. Bug bounties are a thing now meaning people have new monetization opportunities for the vulns they discover. Twitter community has matured and there are more than 365 security conferences a year held globally, meaning angsty teens have so many more ways to establish their street creds besides dark corners of IRC and anonymous imageboards.

Your simplistic analysis ignores all these factors. It's like completely ignoring logistics, supply chain and risk management in real world, if you are one of these MBA types.

> allocate ~$10M and cause ~$10B in damages

Sure. Just like you can cause massive damages by causing forest fire in dry season with just a box of matches. In the context of our discussion such estimations are non-productive as 1) they ignore other costs and risks that attackers need to account for; and 2) ability to cause massive damage does not necessarily translate into ability to extract similarly massive profits from the situation.

> they could hack every ship (...)

The examples that follow are laughable. You clearly know nothing about these systems. That's like being afraid that someone will hack your laptop and give you cancer by manipulating display refresh rate. There certainly are problems with industrial control systems and critical infrastructure, but they are much more nuanced than the Hollywood-type hacking you predict. And no exploit is worth more than ~1M$ (apart from military thingies), because 1) there are always multiple ways to enter and as a result is the same attackers usually choose the path of the lowest resistance); 2) at that price you can buy an insider that will just run your stuff directly or plug an LTE-enabled rPI into the network. And for the vast majority of modern real-world attacks exploit is the most trivial/easiest/cheapest part. So well protected systems are designed in such a way that even malicious sysadmin would be able to do only so much damage before getting noticed and expelled from the network.

Re: Maersk, Me and NotPetya

#48
post #11

As someone with very limited Microsoft/Windows background, I would be curious to somehow better understand how these lessons would apply to the Linux world. What are the Linux equivalents of pass-the-hash, TAM/PAM/PAWs etc?

SSH Agent Hijacking comes to mind. Technically not the same, but outcome of self propagating malware is same.

Re: Maersk, Me and NotPetya

#49
post #44
post #42

Earlier quoted context omitted.

> I disagree that any particular infosec organization is equipped to deal with problems of this class in any meaningful way. FAANGs are bigger targets and yet none of them suffered anything remotely similar. > An attack, able to do $300M in damages that Maersk can not prevent after we have assumed it already did the best it possibly can, should be able to support a $100M extortion payment. That's incorrect. I already…

That is not an unanswerable question at all. To clarify, I am literally asking for a simplified threat model. Take an existing threat model, reduce it to cost of doing those actions, done. Order of magnitude is fine. If there are parameters, pick a set of parameters within the non-totally-stupid range and state them. Estimate when reasonable. The question is just me looking for broad strokes anecdotes.

> To clarify, I am literally asking for a simplified threat model.

That's a simplification beyond any usefulness. You wouldn't be able to do as much damage with $100k budget in a few months as a well-staffed national agency in a week.

> The question is just me looking for broad strokes anecdotes.

Even Jeff Bezos wouldn't be able to orchestrate a cyberattack that crashes International Space Station with astronauts aboard.

Re: Maersk, Me and NotPetya

#50
post #31
post #28

Earlier quoted context omitted.

This is ridiculous. You're basically saying that having any security at all is pointless because someone will always still be able to break into your system in some way. Nothing could be further from the truth. Only ignorant amateurs believe that security is an all-or-nothing game. By making your system more difficult to break into, you: * increase the effort and thus cost for the attacker, thereby reducing the numbe…

No. I made a very specific statement about the cost of attack relative to the benefit of attack for this class of attack. The cost of attack is so far from the benefit of attack that there is no meaningful defense being offered. To use an analogy, making a tank from paper provides more defense than tissue paper. That does not, however, mean that there is any meaningful defense against credible threats. To provide a t…

You're still thinking all-or-nothing, talking about "exploits" or "vulnerabilities" where finding one lets you take over the whole ystem at once.

That is not how these attacks happen, that is not what happened at Maersk, and that is not what the article is about.

The breach happend via compromised third-party software installed on a small number of regular workplace PCs. The big damages happened largely because sloppy privilege managment allowed the attackers to hop between systems and gradually acquire more credentials and more privileges via weak or reused passwords and accounts shared across systems and functions, until the attackers controlled thousands of PCs and servers across the entire international company.

This kind of thing is a process, and the amount of damages depends mostly on how fast the attackers can gain more privileges vs. how soon they are noticed and countermeasures taken.

Better privilege management, as suggested by the article, can easily slow down that process to a point where it won't cause significant damage.

And your whole extortion argument hinges on the idea that an attacker can demonstrate the ability to cause X amount of damage without actually doing it or giving the victim information that can be used to prevent the attack. That is not how it works in reality, except in the case of DDOS attacks, which are an infrastructure rather than a security issue.

In reality, the amount of damage an extortionist hacker can put a price on is only the amount they can undo or provably refrain from doing in the future. Specific examples of this are mass-encrypting data and threatening to publish trade secrets. And those are things we see happening in reality, but the amounts are much smaller because they cannot include the large-scale disruption of operations that Maersk experienced.

By your logic, the form of extortion you describe should already be happening, constantly, to every large company on the planet. It should be the most profitable form of organized crime ever.

But that is not happening in reality. Because in reality, security and security breaches don't work like you seem to think they do.

Post reply on HN