Live data from Hacker News

Garmin received decryptor for WastedLocker ransomware

bleepingcomputer.com

21–27 of 27 posts

Re: Garmin received decryptor for WastedLocker ransomware

#21

I bet they’ll start investing in backup solutions right about now.

How would restoring from backups also not risk restoring whatever it was that broke their world at the same time?

Proper backup does data independently from code, and proper devops is to always do an install from trusted source.

It is unfortunately very rare to find this in practice - everyone seems to be happy with just snapshotting live systems as a backup these days; and it works well enough as long as there is no lingering systemic corruption of data.

(And .... Excel, by mixing data with potentially malicious code, is beyond redemption. But good luck quarantining that in a modern suit controlled company)

Re: Garmin received decryptor for WastedLocker ransomware

#24

Since GARMIN is a publicly traded company, couldn’t an investor demand to know if the money was paid, and if they don’t get an answer, they could go to the SEC? Could they sue?

There is the Matt Levine answer to this which is 'Everything is Securities Fraud' [0]. He claims this is partially because securities law is broad and relatively functional, violations of other laws end up being pursued under securities law.

[0] https://www.bloomberg.com/opinion/articles/2019-06-26/everyt...

Re: Garmin received decryptor for WastedLocker ransomware

#25
post #6

To me the fascinating part is that with the ransom payment they received the decrypt key as well as the security system patches needed to protect the system. However I would be very nervous that the hacker didn’t leave something behind but perhaps they would rather a good reputation and not risk losing payment for the next attack.

have to keep them on a subscription model. provide the antidote to the manufactured problem. oh wait...

Re: Garmin received decryptor for WastedLocker ransomware

#26
post #4
post #3

Is Evil Corp their actual name, or just what the US law enforcement called them? https://home.treasury.gov/news/press-releases/sm845

It looks like that's just the name of a group - like anonymous, lulzsec, equation, shadow brokers, etc. It's likely a nod to Mr. Robot, where the company that the hackers are infiltrating is called Evil Corp.

Its E Corp, Elliot call's them Evil Corp (He says in episode 1 iirc, that he basically replaced E Corp with Evil Corp in his own internal dialogue)

Re: Garmin received decryptor for WastedLocker ransomware

#27
post #19

I'm still hopeful that Garmin is prosecuted for paying the random. The us is actually sanctioning evil Corp. https://slate.com/technology/2020/07/garmin-cyberattack-rans... I even have a Garmin device affected by this. I still want ransomware stopped.

Ransomware that is a result of users clicking on update notices they should not click is very hard to protect against. Even Stuxnet was successful in crossing over to a separate network through the use of USB sticks. Source: https://en.m.wikipedia.org/wiki/Stuxnet I get the sentiment that Garmin should suffer due to paying the ransom, but I bet a lot of american companies would act the same way if it was their compan…

Those companies should have backups. If this was say a mafia type org that was going to kill people if they didn't pay up, it would be clearly wrong. If someone said they'd cut your internet links if you don't pay, it might be more obvious this extortion payment is wrong. And this can be defeated by having backups.
Post reply on HN