Earlier quoted context omitted.
> But giving the keys to the castle to some mid-tier company is just a recipe for disaster It sucks, because I know my company is quite small but we take security extremely seriously (we have 9 people, 4 are security engineers, and the other 5 have varying degrees of experience in security). I think people might worry that, because of our size, we won't be as secure as a larger company. But the irony is that larger c…
Much easier to do it Ina small company, very hard to get it right in a company "100x your size".
US companies hit by 'colossal' cyber-attack
451–460 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#452Earlier quoted context omitted.
> But giving the keys to the castle to some mid-tier company is just a recipe for disaster It sucks, because I know my company is quite small but we take security extremely seriously (we have 9 people, 4 are security engineers, and the other 5 have varying degrees of experience in security). I think people might worry that, because of our size, we won't be as secure as a larger company. But the irony is that larger c…
> We plan to give talks and blog about how companies at our stage can do things that would make companies 100x our size jealous Sounds interesting and rather extraordinary, would be great to read more on your thoughts on that. Do you refer to the Grapl blog?
Re: US companies hit by 'colossal' cyber-attack
#453Earlier quoted context omitted.
Yes but how does the cashier know what the price is? How does the cashier open the safety box to reach the money? Or open the cash registry? I don't even think it is legal to accept money without a working cash registry for tax registration reasons.
> Yes but how does the cashier know what the price is? My understanding was that it was just payment processing that was affected, not the point of sale systems. The scanners and things probably work fine, and I think they could accept cash payments without issue. It’s just not worth it when almost no customer pays with cash.
Re: US companies hit by 'colossal' cyber-attack
#454Earlier quoted context omitted.
Subscription based Ransom ware.
RWaaS. It should come with indemnity against other ransomware hackers where your RWaaS provider will either provide you with backups &/or go after (negotiate, hack, or physically assault) the other hackers.
The delicate ecosystem of the unwatched computer.
Re: US companies hit by 'colossal' cyber-attack
#455Earlier quoted context omitted.
Toothpaste's out of the tube. Banning the exchanges won't stop the ransomware.
It would. Ban the exchanges and make sure there are no such thing as anonymous payment channels. That's not hard.
Re: US companies hit by 'colossal' cyber-attack
#456Earlier quoted context omitted.
Holy hell... no wonder they snuffed it out in the media. I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin. The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!" I sometime find wisdom in the approach from olden times…
> Holy hell... no wonder they snuffed it out in the media. The OPM hack wasn’t ‘snuffed out’ by any means - it was fairly well covered for a cyber attack of it’s era. Perhaps it wasn’t covered much in your part of Eastern Europe, but it was definitely not covered up. The fact that some people have forgotten about it is a completely different issue.
But it's true that I don't remember it at all, even though I worked in a field parallel to CompuSec and usually notice those events.
Re: US companies hit by 'colossal' cyber-attack
#457Earlier quoted context omitted.
Holy hell... no wonder they snuffed it out in the media. I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin. The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!" I sometime find wisdom in the approach from olden times…
They should also have the old wisdom of not connecting critical systems to Internet.
Major mission critical systems are managed by the country's Ministry of the Interior, and haven't had a major hack (yet), as far as is publicly known.
And besides, how are those poor souls gonna connect to Facebook during their mandatory 10 o'clock coffee pause ?
Re: US companies hit by 'colossal' cyber-attack
#458Earlier quoted context omitted.
Give it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack. No worries though, the ransom from this round should serve nicely as a…
Unsure why everyone is acting like this is a new phenomena. These organizations have been getting multi-million payments for the better part of a decade, it is just only being covered by the media now. Why couldn't they have bootstrapped years ago? I suspect the real reason is they actually want to avoid extensive media coverage.
1) Scale of the attacks. Taking large portions of a country's petro-chemical/energy pipeline is far above the threat level presented by most prior hacks. The same goes for shutting down ~20% of the nation's pork & beef food supply. And now hundreds of companies impacted as a result of a single breach. Ransomware isn't new, but it is in hockey-stick growth mode.
2) Increased market for crypto currencies. Criminal activity may not, by far, be the dominant activity, but the more legitimate transactions there are, the easier it is to hide criminal transaction.
3) Bootstrapping this type of thing takes time because it's not just about capital in this case. It's also about accumulating vulnerabilities and compromising systems long enough that backups-- for example a week or month old-- are still useless (also encrypted). And going back to earlier backups will lose the company too much essential data.
4) And as you said, avoiding media coverage that will bring too much attention, and with it the potential for a crackdown. The slow burn on increasing ransomware over the years has acclimate people to it in a way that makes even the most recent massive attacks a little more normalized, especially when they pay the ransom & get back up & running in a few days. That limits the amount of public pressure to fight this head on with mandated increased security and massive resources thrown at pro-actively going after these hackers.
5) In 2016 ransomware wasn't quite as mature. 2020 is different, and the political landscape is different: I'm not making a partisan comment here. I'm not saying the previous US administration prevented these things better or the current administration dropped the ball. What I'm saying is that when there's any new administration, there are threat actors that will test the waters, see how far they can go. I definitely thing that's a factor here, especially so close after the Biden administration delivered its list of 16 untouchable sectors to Russia & Putin. There's going to be a lot of adversarial interest in just how firm those limits are, and what the response will be.
Otherwise, from a national awareness standpoint, you do approach an important point: It may not be a new phenomena, but for the vast majority of Americans that don't follow tech news, this is new and, given the scale of recent attacks, somewhat scary.
Re: US companies hit by 'colossal' cyber-attack
#459Earlier quoted context omitted.
This is a tiresome, meaningless religious mantra nowadays. Yes there is corruption. No not everybody is corrupt. No it does not only exist in USA nor is USA anywhere near the worst. No you can't blame anything and everything you don't like on corruption and greed.
Perhaps, but of all the leading developed nations on Earth, the US has a particularly corrupt government that sells itself to the highest bidder thanks to Citizens United and armies of lobbyists. Our healthcare, prison, and student loan systems, for example, prey on US citizens without repercussions at lengths that don’t fly in most developed countries. I think it’s safe to say that corruption and greed are at the ro…
Re: US companies hit by 'colossal' cyber-attack
#460Earlier quoted context omitted.
RWaaS. It should come with indemnity against other ransomware hackers where your RWaaS provider will either provide you with backups &/or go after (negotiate, hack, or physically assault) the other hackers.
A few years back didn't bitcoin botnets patch/fix their nodes so that other ransomware/malware operators didn't take over their valuable mining stock? The delicate ecosystem of the unwatched computer.
But if REvil etc. are going to branch out like that, they really need to follow the traditional protection racket and engage in, let's say, aggressive counter measures with the potential for rapid bodily disassembly of any competitors that come along.