Live data from Hacker News

Nokia 'paid millions to software blackmailers six years ago'

timminspress.com

41–49 of 49 posts

Re: Nokia 'paid millions to software blackmailers six years ago'

#41
post #28

Earlier quoted context omitted.

In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.

Maybe not forced, but I did update several s60 devices as they had new firmware published. So they should at least have made the updates public and explained that everyone must upgrade. Imagine, for example, openssl being told about the heartbleed vulnerability, then being pressured into paying big money to prevent disclosure, and then keeping their mouths shut about it for six years. Except this is even worse becaus…

The difference is that OpenSSL updating was the responsibility of the admins maintaining the server, not general public. The general public did have to act, but it wasn't something technical like updating firmware on a phone is.

Back in the day, I had an S60 phone but no way to even connect it to a computer to get the firmware.

Re: Nokia 'paid millions to software blackmailers six years ago'

#42
post #2

'the money was delivered but the police lost track of the culprits' A solid showing by the Helsinki police

You can't exactly arrest them without one of their partners releasing the key. Following them might not end well either.

I think blackmail would be enough to arrest them.

Re: Nokia 'paid millions to software blackmailers six years ago'

#43
post #8

I can fully see how this could happen. Too many companies don't understand the value of keys like this, and won't until they have a similar situation. I wonder how exactly the criminals came to have them in the first place, but would be willing to bet it was ultimately incompetence by someone at Nokia.

Having done a few code signings physically at Nokia Tampere back in the Symbian days, I would say they were pretty serious about these codes. Not that the security was 100% tight, but it did involve having to go to a single locked up computer with someone looking at you, keys to the safe in different places, required two separate persons from the signing to be there etc. Impressed myself at least.

Re: Nokia 'paid millions to software blackmailers six years ago'

#44
post #28

Earlier quoted context omitted.

In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.

Maybe not forced, but I did update several s60 devices as they had new firmware published. So they should at least have made the updates public and explained that everyone must upgrade. Imagine, for example, openssl being told about the heartbleed vulnerability, then being pressured into paying big money to prevent disclosure, and then keeping their mouths shut about it for six years. Except this is even worse becaus…

Nobody but the nerdiest of phone users bothered to ever connect their phones to a PC and over-the-air updates were not supported. The risk of malware signed with the key showing up was probably weighted against the hassle updating everything would have caused.

Re: Nokia 'paid millions to software blackmailers six years ago'

#45

Earlier quoted context omitted.

Exactly this. Also, for those that still remember Heartbleed, read again the above comment and think what embedded hardware is running around you. It is a bit scary.

To be fair, you can't exactly "force" an android or an iOS device to update either. It's easier to coach users to update but goddamn would it have been impossible to get s40/60 users to move even one version up. I recall doing an s60 software upgrade and having it crash halfway through, which somehow bricked the baseband and the operating system of the device. Go figure.

On S60 there was no separate baseband chip to my understanding, the Symbian kernel was responsible of driving the radio as well. This was said to give Nokia a competitive advantage, as most of the competing smartphone OSes required separate baseband chip with a firmware of its own, which drove costs up back then. Such chips are inside SoCs of course these days and cost next to nothing anyway.

Re: Nokia 'paid millions to software blackmailers six years ago'

#46

I'm trying to imagine this happening to someone like Red Hat. BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!" Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.

I was going to make a similar post suggesting Google/Android. It's one class of business risk avoided.

Re: Nokia 'paid millions to software blackmailers six years ago'

#48
post #7

I always wondered how you do paperwork for something like this. It must be a nightmare from an accountant perspective. What is the bill code for "blackmail" when you file the income tax and you write a 6 figure expense. In the end your cash has to balance out, you cannot not declare it. Anybody with experience in something like this?

isn't there something fringe like 'theft' or miscellaneous losses?

Having a code for theft is definitely a thing. For many businesses, having a small amount of theft is just an unavoidable cost of doing business.

Re: Nokia 'paid millions to software blackmailers six years ago'

#49
post #8

I can fully see how this could happen. Too many companies don't understand the value of keys like this, and won't until they have a similar situation. I wonder how exactly the criminals came to have them in the first place, but would be willing to bet it was ultimately incompetence by someone at Nokia.

The Helsinki Times article[1 english] says they suspect it was an ex employee.

"Information obtained by Helsingin Sanomat from two different sources indicates that Nokia believes the blackmailer to be a Finnish citizen who participated in the development of the user interface. The suspect was able to obtain the highly-classified encryption key due to a data security vulnerability."

[1] http://www.helsinkitimes.fi/finland/finland-news/domestic/10...

Post reply on HN