Live data from Hacker News

Nokia 'paid millions to software blackmailers six years ago'

timminspress.com

11–20 of 49 posts

Re: Nokia 'paid millions to software blackmailers six years ago'

#11

I always wondered how you do paperwork for something like this. It must be a nightmare from an accountant perspective. What is the bill code for "blackmail" when you file the income tax and you write a 6 figure expense. In the end your cash has to balance out, you cannot not declare it. Anybody with experience in something like this?

At least for the IRS, you can deduct money paid out for ransom, blackmail, or other forms of theft.

http://www.irs.gov/publications/p17/ch25.html#en_US_2011_pub...

Re: Nokia 'paid millions to software blackmailers six years ago'

#14
post #10
post #6

Wow, that's rough. Not much you can do against a vulnerability that'll destroy the trust of your entire customer base. A DDOS is one thing but I probably would have paid the millions in this case.

I wonder how much it would have cost to push out an update to all of the Symbian devices in the wild at the time. It wouldn't have been easy, and would have been a PR nightmare, but it could have been done. The question is: would it have been worth it? I don't know, but hiding things rarely goes well. Then again, I don't know of any public instances where this has happened, but I'm sure Nokia aren't the only ones to…

Assuming you could even reflash the firmware key.

Re: Nokia 'paid millions to software blackmailers six years ago'

#15
post #3
post #2

'the money was delivered but the police lost track of the culprits' A solid showing by the Helsinki police

It's almost out of a movie. One of your larger national companies is being extorted and you fail to follow the people doing so? It also had to be a pretty big vulnerability for them to have to pay that much in the first place.

And at the time Nokia was a major part of the entire finish economy - sounds like gross incompetence on the finish authorities.

Re: Nokia 'paid millions to software blackmailers six years ago'

#16
I'm trying to imagine this happening to someone like Red Hat.

BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!"

Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.

Re: Nokia 'paid millions to software blackmailers six years ago'

#17

I'm trying to imagine this happening to someone like Red Hat. BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!" Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.

I think the analogy is a little off.

This would be like someone having the GPG signing key for the Red Hat official repositories. It would give them the ability to insert their own (malicious) software package into the Red Hat update stream without the signature throwing any warnings.

Re: Nokia 'paid millions to software blackmailers six years ago'

#18

I'm trying to imagine this happening to someone like Red Hat. BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!" Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.

The article is a bit unclear, but it appears that what the blackmailers got were the signing keys for the software.

Losing signing keys would be pretty bad for Red Hat, too.

Re: Nokia 'paid millions to software blackmailers six years ago'

#19
That's absolutely insane! Even after paying the ransom, how could they be sure noone were still sitting on the keys? Assuming it's code signing keys, it sounds incredibly irresponsible to not (force) update all devices anyways.

Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on?

... makes me wonder what else we don't know about all the other vendors...

Post reply on HN