Live data from Hacker News

Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

nbcboston.com

141–150 of 267 posts

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#141
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

The answer to your (somewhat leading) questions is just no.

War analogies are inapplicable, privateer analogies are inapplicable. Create the incentives, organizational and software structure required to stop this or it will continue. Holding single companies accountable shifts the burden without solving the problem.

Have standards, standards bodies, defensive organizations.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#142

Earlier quoted context omitted.

Would this result in not paying or them hiring consultants who pay on their behalf and just invoice them for "resolution services"?

I wonder where this pop-understanding of the law that seems prevalent on HN comes from. Loopholes exist, but in general the government is not terrible at figuring out basic schemes like this and adapt administration of the law.

Libertarians have substantial, though I think not majority, representation on HN. Certain themes always seem to repeat that seem related to this. For instance, likening any form of prohibition to the failed prohibition of alcohol to suggest that all forms of prohibition are similarly doomed. This argument relies on the reader neglecting to consider the myriad of prohibitions that are going well, like CFC bans or the prohibition on building unsafe firetrap buildings. They point out one failure and ask us to extrapolate from only that datapoint, ignoring the rest.

As in this case, pointing out a hypothetical way a law could fail, to insinuate that all laws would fail.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#143

This isn't news anymore, its weather. If your company does not have a full time cybersecurity team, they soon will, even if they say they don't need it.

In a lot of situations we've heard about, the cybersecurity team could consist of one person with a bullhorn walking around shouting "don't connect critical infrastructure to the Internet".

Whether they'd listen to them still is another matter but that's the same with a regular cybersecurity team.

And that is to say we have institutional standards where unsafe practices are considered OK and will be followed because they save X dollars and time now.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#144
There are threats which emerge when a viability threshold is crossed and realised.

For cities, recurring plauges began occurring during Roman times and limited maximum city populations to about 1 million until the advent of modern sanitation, hygiene, public health, waste removal, and food quality. (Actual medical care and treatment had little to do with this, though vaccines and antibiotics helped.)

Industrial pollution lagged industrial development by about 50--100 years, with air and water quality and material contamination (heavy metals, asbestos, organic solvents, synthetic hormone disruptors and other bio-active contaminants, etc.).

Increases in travel, transport, and communications almost always directly facilitate fraud. The Greek/Roman gods Hermes/Mercury represented communication, messages, travel, transportation, commerce, trickery, and theives. The term "Confidence Man" arose from Herman Melville's novel of the same name, set on the first great highway of the United States, the steamboat-plied Mississippi.

Mail begat mail fraud. Telegraph and telephones begat wire fraud. Cheap broadcast radio and television, payola and game-show fraus. Email begat spam and phishing.

The 1990s and 2000s computerised business practices employed computers with shitty security, but those systems were saved by the general lack of networking, the relatively small size of global computer networks, limited disk storage, limited network bandwidth, and the effectual air-gapping of paper-driven steps in processing. Billing might be submitted or computed electronically, but a paper check still had to be cut and signed. Draining accounts or data simply wasn't possibly without running up against the inherent limitations of computer infrastructure at the time even had a payment mechanism similar to today's cryptocurrencies been available.

If my assessment is correct, we'll be seeing much more of this.

Attackers have low costs. Victims have highly-interconnected, but poorly-defended systems, comprised of multiple components, each complex on its own, and lacking any effective overall security accountability. End-to-end automation exists, facilitating both productive work and effective attacks. A viable and tracking-resistant payment mechanism exists. Regions from which attacks can be made with impunity exist, and are well-connected to global data networks.

Backups alsone are not an effective defence as these protect against data loss but not data disclosure. Full defence will require radically different thinking, protection, risk assessment, and law-enforcement capabilities.

Until then, get used to more of this, at both large and small scales.

There are some potential bright lights.

- I suspect attackers aren't targeting specific facilities but are instead conducting automated and scripted attacks against vulnerable facilities.

- For data-encryption ransom attacks, this means that the decryption key is all but certainly derivable from information on the attacked system, perhaps encoded as filenames or contents. Determining this mechanism may at least allow for data recovery. (It of course does nothing against data disclosure, long-term surveillance, or access denial attacks.) The likelihood that attackers have some database of victims + passwords seems low.

- Attackers are themselves subject to trust and suspicion attacks, and turning members or safe-harbours against attackers is probably a useful countermeasure.

- State-level sanctions, flling short of military attacks, may also prove effective.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#146
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

The Risky Business podcast #624 talks about pretty much all your questions if your want to listen to it. But here's some relevant info: Hardening can help, but we'll always have new exploits and some of the time the intrusion comes from standard fishing rather than automation, so tech can't solve it. Crypto coins enable payment at scale, but Russia enables the operation to not worry about consequences (a lot of ranso…

Good 2FA (e.g. U2F) can solve most phishing. https://krebsonsecurity.com/2018/07/google-security-keys-neu...

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#147

Clearly they are messing with the wrong people from Martha's Vineyard :).

Most of Worcester county and Bristol county would probably disagree.

Just like when they hit the vehicle inspection system in March, the wealthy hemmed and hawed about how nobody should get away with thumbing their nose at state authority but the little guys were just happy it wasn't them getting the shaft for once.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#148
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

Many ransomware attacks are not sophisticated. They may be targeted but the procedure is fairly simple: blast targets with phishing emails/texts, get them to click, done. It seems that zero-days are often not required because targets lag behind in applying patches. Many (if not most) companies have file shares with fairly wide-open access and/or a complete lack of backups so peer-to-peer spreading within the company…

The sophistication of the major ransomware attacks happens at the "done" step of your "blast targets with phishing emails/texts, get them to click, done" description. The initial foothold is often done randomly by various attackers, but the execution after that takes some skill and effort and often is done by a limited number somewhat sophisticated groups who buy the initial footholds from a larger number of random attackers. The lateral movement is not generally done through "file shares with fairly wide-open access", but the attackers often (at least in most of the major attacks) manage to obtain full domain administration privileges to the whole network, so if the backups can be easily disabled or destroyed by your administrators, attackers can do the same.

Zero days are indeed often not required, however, IMHO the initial attack is less preventable than that lateral movement and further exploitation - if attackers are in your systems for a week while they spread everywhere and kill your backups preparing to pull the switch to "ransomcrypt" everything at once, then that was your opportunity to detect it and kick them out, but the victim organizations obviously were not capable of that. This needs to be fixed, perhaps by methods similar as you describe.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#149
post #117

Earlier quoted context omitted.

Various providers of "cyber insurance" are right now busy getting rid of ransomware coverage because it turns out offering that isn't working for them. and yes, they do require companies to have cyber security infrastructure and audits.

That would imply that cyber security isn't effective in mitigating these attacks then, no?

It suggests it is a difficult problem to stop. As I understand it, attackers now frequently perform an initial compromise and then manually escalate privileges before launching a ransomware attack for greater impact. Alternatively, the attacker will sell privileged access to a ransomware group. This isn't someone from HR opening a malicious attachment and getting the whole company owned via eternal blue.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#150
post #117

Earlier quoted context omitted.

Various providers of "cyber insurance" are right now busy getting rid of ransomware coverage because it turns out offering that isn't working for them. and yes, they do require companies to have cyber security infrastructure and audits.

That would imply that cyber security isn't effective in mitigating these attacks then, no?

At least it suggests that the current standards and auditing practices are not sufficient, and apparently formulating testable requirements is difficult.
Post reply on HN