Live data from Hacker News

Nokia 'paid millions to software blackmailers six years ago'

timminspress.com

21–30 of 49 posts

Re: Nokia 'paid millions to software blackmailers six years ago'

#23
post #2

'the money was delivered but the police lost track of the culprits' A solid showing by the Helsinki police

Where did you read that it had something to do with Helsinki police?

At least the money exchange took place in Tampere.

In Finnish: http://www.aamulehti.fi/Kotimaa/1194907965691/artikkeli/mtv+...

Re: Nokia 'paid millions to software blackmailers six years ago'

#24

I'm trying to imagine this happening to someone like Red Hat. BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!" Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.

Well, RH isn't the best example. IIRC they do some shenanigans around kernel updates to hide the actual patches. And only paying customers get it.

Re: Nokia 'paid millions to software blackmailers six years ago'

#26
post #19

That's absolutely insane! Even after paying the ransom, how could they be sure noone were still sitting on the keys? Assuming it's code signing keys, it sounds incredibly irresponsible to not (force) update all devices anyways. Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on? ... makes me wonder what else we don't know abo…

In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing.

It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.

Re: Nokia 'paid millions to software blackmailers six years ago'

#27
post #19

That's absolutely insane! Even after paying the ransom, how could they be sure noone were still sitting on the keys? Assuming it's code signing keys, it sounds incredibly irresponsible to not (force) update all devices anyways. Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on? ... makes me wonder what else we don't know abo…

In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.

Exactly this.

Also, for those that still remember Heartbleed, read again the above comment and think what embedded hardware is running around you. It is a bit scary.

Re: Nokia 'paid millions to software blackmailers six years ago'

#28
post #19

That's absolutely insane! Even after paying the ransom, how could they be sure noone were still sitting on the keys? Assuming it's code signing keys, it sounds incredibly irresponsible to not (force) update all devices anyways. Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on? ... makes me wonder what else we don't know abo…

In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.

Maybe not forced, but I did update several s60 devices as they had new firmware published. So they should at least have made the updates public and explained that everyone must upgrade.

Imagine, for example, openssl being told about the heartbleed vulnerability, then being pressured into paying big money to prevent disclosure, and then keeping their mouths shut about it for six years. Except this is even worse because at least then someone could look at diffs. I can't even think of a proper analogy here.

Re: Nokia 'paid millions to software blackmailers six years ago'

#29

Earlier quoted context omitted.

In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.

Exactly this. Also, for those that still remember Heartbleed, read again the above comment and think what embedded hardware is running around you. It is a bit scary.

To be fair, you can't exactly "force" an android or an iOS device to update either. It's easier to coach users to update but goddamn would it have been impossible to get s40/60 users to move even one version up.

I recall doing an s60 software upgrade and having it crash halfway through, which somehow bricked the baseband and the operating system of the device. Go figure.

Re: Nokia 'paid millions to software blackmailers six years ago'

#30
post #18

I'm trying to imagine this happening to someone like Red Hat. BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!" Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.

The article is a bit unclear, but it appears that what the blackmailers got were the signing keys for the software. Losing signing keys would be pretty bad for Red Hat, too.

That happened! And that was also 6 years ago. http://linux.slashdot.org/story/08/08/22/1341247/red-hat-fed...
Post reply on HN