Live data from Hacker News

How to survive a ransomware attack without paying the ransom

bloomberg.com

21–30 of 168 posts

Re: How to survive a ransomware attack without paying the ransom

#21

This is not really surviving. What do you need to do is prepare and to have off line backups

Offline backups have been a thing for decades. Why is this not standard practice? Especially for a technology company like Garmin. It can't be about cost savings, businesses still pay for insurance and security systems. For that matter, offsite backups should also be saved in case of fires, floods, tornadoes, theft, etc...

Backup price for 8TB is cheap enough. Backup price for 8PT does not scale well.

I don’t know how much data Garmin has company wide. But it’s a lot different for me to consider offline backups as a simple service than a company this size and complexity.

Re: How to survive a ransomware attack without paying the ransom

#22
post #6

How is ransomware able to spread to all the PCs in a company? (Especially PCs at different locations around the globe) The malware needs to execute itself on each computer. But I would think this would be thwarted by hardware firewalls as well as apps like Windows Firewall. If my PC at work gets infected, somehow it can magically infect the guy down the hall's PC too? I thought that was made impossible years ago.

Apart from some special cases like Wannacry/NotPetya, ransomware crews do only as much lateral movement as is required for privilege escalation. Once they have DA, they can just disable protections and push malware centrally through AD.

Re: How to survive a ransomware attack without paying the ransom

#23
post #14

Earlier quoted context omitted.

Probably through Active Directory, which has the ability to deploy software. If a domain controller was compromised, the payload could be pushed out across the board. Endpoints like PCs and servers check in with domain controllers at recurring intervals, so even if all endpoints are behind firewalls and can’t talk to one another, they still reach out to domain controllers periodically to pull down configuration updat…

Pretty much this. Firewalls do absolutely nothing once someone got your weakest link to click something and go to town. From my last penn test it goes, phish, get a click and execute or credentials, use a hack like getting legacy NetBIOS exploit to give up hashes for all your users, crack the hashes and hope someone used a short 12 char password or something dictionary-easy like “Wr3st1ing1!”, then leverage that acce…

> Firewalls do absolutely nothing once someone got your weakest link to click something and go to town.

Well, fw would be effective if organizations used network segmentation effectively, but of course close to no one does that in practice (e.g. usually IT/support have access to everything).

Re: How to survive a ransomware attack without paying the ransom

#24
post #5

Garmin CEO at al must be reading this impatiently, looking for some clever-magic clue, which is not gonna arrive, I am afraid. Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. I can understand that some parts like "social" stuff might depend on some central…

It is surprisingly difficult to make synchronisation work between two devices that might run different hard- and firmware and even potentially software versions. Cloud based APIs as middleware is soo much easier in comparison. I am completely with you conceptually, but from experience I can tell you that even if there is a commercial incentive to allow for local communication it takes a few days to get it working wit…

And yet everything from Palm Pilots to iPaqs were able to do it a quarter of a century ago with just a beam of light.

Re: How to survive a ransomware attack without paying the ransom

#25

Earlier quoted context omitted.

Offline backups have been a thing for decades. Why is this not standard practice? Especially for a technology company like Garmin. It can't be about cost savings, businesses still pay for insurance and security systems. For that matter, offsite backups should also be saved in case of fires, floods, tornadoes, theft, etc...

Backup price for 8TB is cheap enough. Backup price for 8PT does not scale well. I don’t know how much data Garmin has company wide. But it’s a lot different for me to consider offline backups as a simple service than a company this size and complexity.

There are plenty of companies that can backup 8PB of data from a wide variety of sources for you, and make it a relatively staitforward task to interegrate with them.

There is complexity, yes, but it's mostly a solved problem.

Disclaimer: I work for one.

Re: How to survive a ransomware attack without paying the ransom

#26
post #5

Garmin CEO at al must be reading this impatiently, looking for some clever-magic clue, which is not gonna arrive, I am afraid. Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. I can understand that some parts like "social" stuff might depend on some central…

“A distributed system is one that prevents you from working because of the failure of a machine that you had never heard of.”

Leslie Lamport

Re: How to survive a ransomware attack without paying the ransom

#29
post #6

How is ransomware able to spread to all the PCs in a company? (Especially PCs at different locations around the globe) The malware needs to execute itself on each computer. But I would think this would be thwarted by hardware firewalls as well as apps like Windows Firewall. If my PC at work gets infected, somehow it can magically infect the guy down the hall's PC too? I thought that was made impossible years ago.

Here is the diagram

https://www.bleepingcomputer.com/news/security/evil-corp-blo...

Re: How to survive a ransomware attack without paying the ransom

#30
post #5

Garmin CEO at al must be reading this impatiently, looking for some clever-magic clue, which is not gonna arrive, I am afraid. Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. I can understand that some parts like "social" stuff might depend on some central…

Over two days now, and almost radio silence from Garmin. I can sympathize with their issues, but not keeping us informed at all about what's going on is quickly leading people to become angry on various fitness forums I frequent. Not a good way to treat us customers.
Post reply on HN