Live data from Hacker News

How to survive a ransomware attack without paying the ransom

bloomberg.com

41–50 of 168 posts

Re: How to survive a ransomware attack without paying the ransom

#41
post #14

Earlier quoted context omitted.

Probably through Active Directory, which has the ability to deploy software. If a domain controller was compromised, the payload could be pushed out across the board. Endpoints like PCs and servers check in with domain controllers at recurring intervals, so even if all endpoints are behind firewalls and can’t talk to one another, they still reach out to domain controllers periodically to pull down configuration updat…

Pretty much this. Firewalls do absolutely nothing once someone got your weakest link to click something and go to town. From my last penn test it goes, phish, get a click and execute or credentials, use a hack like getting legacy NetBIOS exploit to give up hashes for all your users, crack the hashes and hope someone used a short 12 char password or something dictionary-easy like “Wr3st1ing1!”, then leverage that acce…

> The only thing that “saves” you from paying the ransom is good backups. But if a group is fairly competent, they’ll encrypt your backups too. So it needs to be offline.

This is the part I’ve never understood. Surely you should be backing up in an append only fashion initiated from the backup server?

My best guess is that this gets managed from AD as well, so they find it and take over?

Re: How to survive a ransomware attack without paying the ransom

#42
post #38

Earlier quoted context omitted.

It is surprisingly difficult to make synchronisation work between two devices that might run different hard- and firmware and even potentially software versions. Cloud based APIs as middleware is soo much easier in comparison. I am completely with you conceptually, but from experience I can tell you that even if there is a commercial incentive to allow for local communication it takes a few days to get it working wit…

What makes it so difficult? What are some concrete problems you encountered?

It is not intrinsically difficult, it's made difficult by the fact that the companies themselves specifically want to have their infrastructure in the mix to have access to valuable user data. There's no particularly difficult challenge to sync the phone and watch directly, offline. A good chunk of revenue comes from services which rely on the data being in the cloud.

Re: How to survive a ransomware attack without paying the ransom

#43

Earlier quoted context omitted.

Offline backups have been a thing for decades. Why is this not standard practice? Especially for a technology company like Garmin. It can't be about cost savings, businesses still pay for insurance and security systems. For that matter, offsite backups should also be saved in case of fires, floods, tornadoes, theft, etc...

Offline backups are not a complete solution. What if your backups are infected with the virus? Even if the backups are uninfected, your IT department has to manually scrap and rebuild all your computers from data centers to the warehouse to the receptionist. And in the meantime, like the article described, you have to pay your employees and suppliers and continue to ship products to customers.

An important part of any backup strategy is testing your backups on a regular basis. Perhaps it could even be automated...

Re: How to survive a ransomware attack without paying the ransom

#44
post #31
post #5

Garmin CEO at al must be reading this impatiently, looking for some clever-magic clue, which is not gonna arrive, I am afraid. Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. I can understand that some parts like "social" stuff might depend on some central…

Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. You really wonder that? I'm sorry, how stupid are you? It's obviously to harvest data and control users. We've been warning and educating people about this for decades. When are you guys starting to wake up a…

This reply strikes me as an uncharitable interpretation of OP’s statement. It’s also rude.

Re: How to survive a ransomware attack without paying the ransom

#45
post #14

Earlier quoted context omitted.

Probably through Active Directory, which has the ability to deploy software. If a domain controller was compromised, the payload could be pushed out across the board. Endpoints like PCs and servers check in with domain controllers at recurring intervals, so even if all endpoints are behind firewalls and can’t talk to one another, they still reach out to domain controllers periodically to pull down configuration updat…

Pretty much this. Firewalls do absolutely nothing once someone got your weakest link to click something and go to town. From my last penn test it goes, phish, get a click and execute or credentials, use a hack like getting legacy NetBIOS exploit to give up hashes for all your users, crack the hashes and hope someone used a short 12 char password or something dictionary-easy like “Wr3st1ing1!”, then leverage that acce…

Your backups will contain all the backdoors that the attackers managed to deploy - so even ignoring the normal massive effort of restoring all your computers, you can't simply restore backups, you need to carefully audit everything that you're restoring to clean hardware, and you need everyone to change their credentials (and not just by appending "2" at the end) otherwise you'll be owned again immediately afterwards.

Re: How to survive a ransomware attack without paying the ransom

#46
post #5

Garmin CEO at al must be reading this impatiently, looking for some clever-magic clue, which is not gonna arrive, I am afraid. Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. I can understand that some parts like "social" stuff might depend on some central…

Wait until this happens to your car...

Re: How to survive a ransomware attack without paying the ransom

#47

Earlier quoted context omitted.

Offline backups have been a thing for decades. Why is this not standard practice? Especially for a technology company like Garmin. It can't be about cost savings, businesses still pay for insurance and security systems. For that matter, offsite backups should also be saved in case of fires, floods, tornadoes, theft, etc...

Offline backups are not a complete solution. What if your backups are infected with the virus? Even if the backups are uninfected, your IT department has to manually scrap and rebuild all your computers from data centers to the warehouse to the receptionist. And in the meantime, like the article described, you have to pay your employees and suppliers and continue to ship products to customers.

Wired did a phenomenal article on the Maersk attack https://www.wired.com/story/notpetya-cyberattack-ukraine-rus... company I worked for was affected as we had shipping containers on the water at the time and it was chaos but they recovered.

Re: How to survive a ransomware attack without paying the ransom

#48
post #46
post #5

Garmin CEO at al must be reading this impatiently, looking for some clever-magic clue, which is not gonna arrive, I am afraid. Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. I can understand that some parts like "social" stuff might depend on some central…

Wait until this happens to your car...

Or your pacemaker...

Re: How to survive a ransomware attack without paying the ransom

#49
post #31
post #5

Garmin CEO at al must be reading this impatiently, looking for some clever-magic clue, which is not gonna arrive, I am afraid. Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. I can understand that some parts like "social" stuff might depend on some central…

Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. You really wonder that? I'm sorry, how stupid are you? It's obviously to harvest data and control users. We've been warning and educating people about this for decades. When are you guys starting to wake up a…

the garmin data actually is in an open format. i've written software to decode it using publicly available documentation. the software is free to use. you can copy the (.FIT) file off the watch over USB.

Re: How to survive a ransomware attack without paying the ransom

#50
post #5

Garmin CEO at al must be reading this impatiently, looking for some clever-magic clue, which is not gonna arrive, I am afraid. Meanwhile Garmin watches users (like me) are wondering how it is that syncing my watch that I have bought with an application on my smartphone that I have bought requires presence of some distant online service. I can understand that some parts like "social" stuff might depend on some central…

It is surprisingly difficult to make synchronisation work between two devices that might run different hard- and firmware and even potentially software versions. Cloud based APIs as middleware is soo much easier in comparison. I am completely with you conceptually, but from experience I can tell you that even if there is a commercial incentive to allow for local communication it takes a few days to get it working wit…

>It is surprisingly difficult to make synchronisation work between two devices

No it isn't. We were doing it for years before "the cloud" or even the modern Internet even existed using Bluetooth, RF, IR, and cables. Have you ever looked at a .fit file on a Garmin watch? It's a binary format, but is straightforward to convert to CSV, and doesn't contain much beyond timestamp, latitude, longitude, altitude, heart rate, cadence, and a few other fields. Calculating distance, duration, training effect, calories burned, etc. is simple summarization and arithmetic, plotting course on a map just requires an offline map and a plotting library. It already does all of this ON THE WATCH itself without needing any connection to anything else, so there's nothing stopping an app from doing the same thing locally on a much more powerful iPhone or Android phone. The Garmin cloud is only inserted in the process here so they can monetize your data.

Post reply on HN