Live data from Hacker News

Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

nbcboston.com

231–240 of 267 posts

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#231
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

The Risky Business podcast #624 talks about pretty much all your questions if your want to listen to it. But here's some relevant info: Hardening can help, but we'll always have new exploits and some of the time the intrusion comes from standard fishing rather than automation, so tech can't solve it. Crypto coins enable payment at scale, but Russia enables the operation to not worry about consequences (a lot of ranso…

Risky Business #624: Ransomware farce continues (19 May 2021)

Show: https://www.risky.biz/RB624/

Media: https://chtbl.com/track/383384/media3.risky.biz/RB624.mp3

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#232

Earlier quoted context omitted.

Presumably one has rolling backups. Something line N backup drives, and every day you back up to the next one in line. Then there are rolling monthly backups, etc. The idea is hopefully you notice the problem before all are corrupted. With the way I understand ransomware works, merely connecting a backup to the system will corrupt it. This is where a write-enable switch really comes into play, it cannot corrupt the b…

First, adding manual steps to backups is a terrible idea. People already don't do them (which, since you missed it, you should know is actually the problem), and you're suggesting making them error-prone and manual. Second, where is this idea coming from that corrupted backups are the issue? You're solving a problem that doesn't exist and creating a real one.

> Second, where is this idea coming from that corrupted backups are the issue?

When I read about how ransomware encrypted every drive attached to it, and encrypted the backup drives when they were attached. This was why the ransomware waited some length of time before shutting off access to the user - they wanted to get the backup drives encrypted, too.

> You're solving a problem that doesn't exist

Now you know!

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#233
Interesting how everybody focuses on the things that they know about: technical solutions, legal solutions aiming at the victims, payment options and so on.

When the real failure is somewhere else: bringing these perps to justice. The fact that they can get away with this over and over again hiding behind anonymity is what enables these crimes.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#234

Earlier quoted context omitted.

This is a system I put together at my first IT job. Backups get pushed from devices between 1AM and 3AM each day, so the primary backup server enables it's network card at 1 and disables it at 3. Primary backup server also has a second network card, that in turn is attached to a small subnet containing it and the secondary backup server only. The secondary backup server pulls a copy from the primary on a weekly basis…

The odds of hitting the secondary are zero if you've got a hardware write enable switch! One thing you could do is get one of those mechanical lamp timer clocks from the hardware store, and have it turn the power on/off the network card on schedule.

I am now seeing a grandma style light timer device used to turn off and on a cheep switch.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#235
Well, I’ve been shouting this from the rooftops for a while now, and finally they got my lifeline.

Ransomware in cryptocurrency could be easy to stop naturally. Miners just need to know that there is a nonzero chance of their blocks being forked off if they help them. It’s a technical problem of out-of-band governance protocols among miners, not unlike what is already being done for positive gain (MEV) by FlashBots. That’s the incredible possibility of cryptocurrency. It’s designed to turn selfishness into a public good, with no coercion, recognition, or good will. And sure, they could include a massive reward to convince miners to include the block, but then that also goes for every coinbase and transaction afterward, until there is nothing left, and no incentive at all for ransomware.

The present reality, of course, is that miners are just not that sophisticated. For the most part they’re just aping the repos that are released by the foundations. But the foundations certainly should understand that it’s in their interest to protect their currency by at least giving the miners information about transactions in the mempool or utxos, and perhaps some kind of out-of-band signaling mechanism to indicate unwillingness to accept blocks that include them. Perhaps better yet, a price for inclusion demanded in the form of an MEV burn added to the next block, which would of course fetch its own price. There is some criticism of the foundations here, as there is also some criticism of some PoS implementations that do not allow fork selection, but ultimately I think that they can solve it.

So that takes care of economic hackers. I’m far more concerned with non-economic or peri-economic agents. There is a doctrine of “unrestricted warfare” that everybody should know about. It explains many things about how and why things do not make sense. It is because we are under attack, and it’s a truly brilliant offensive, for which all of our defenses only work in their favor. I don’t have the answers for this. But it does give a warning. The effect they seek is not the damage they’ve done, but our reaction to it. Our reaction, by regulation that cripples our competitiveness, by restricting our own freedoms, could be disastrous to our country and our way of life, which is exactly what they want. And these attacks, although they may be carried out by economic agents, almost certainly find their roots in exploits created by long-standing programs of infiltration. Nature too, has learned this trick; SARS kills by turning the immune system against the host.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#236

Earlier quoted context omitted.

How do you know that we’re not less secure? It wouldn’t surprise me at all if our systems are on average far less secure simply because so much more is online now, to speak nothing of increases in the complexity of and opportunities for errors and misconfigurations in today’s systems.

Because twenty years ago computer security was an absolute and utter shambles. Exploiting a vulnerability today is orders of magnitude harder than it was twenty years ago. Massive strides have been made.

Vulnerabilities may have been easier but the scope for damage was reduced. Certainly in my organisation (local government housing) the impact even just five years ago of all our systems being unavailable was a lot less than it would be now (mainly because we've spent the last five to ten years getting people to abandon paper processes). More than this, we used to have various "systems" which weren't really connected together in a way that could be usefully exploited. We had hundreds of dialup modems in sites which were probably terribly insecure but all they were connected to was a single building component. Now, there's a management console (and related database) which gives you access to hundreds of sites over the internet.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#237

Interesting how everybody focuses on the things that they know about: technical solutions, legal solutions aiming at the victims, payment options and so on. When the real failure is somewhere else: bringing these perps to justice. The fact that they can get away with this over and over again hiding behind anonymity is what enables these crimes.

I think a big factor here is IT people jumping at the chance to say "I told you so! Triple my budget!"

I agree the problem is that these criminals are sheltered from prosecution.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#238

Earlier quoted context omitted.

Banning crypto currencies would have no negative impact on the real economy and end ransom payments overnight.

Ban them how? Ban the on-ramps in the US so that companies can't legally purchase cryptocurrency with which to pay the ransom? Is that fundamentally different than making it illegal to pay the ransom in any currency? It seems that in either case, what you've done is push a company into breaking the law if they want to pay the ransom, which would probably deter most of them from doing it. Or do you mean banning both t…

Laws can be made very broad and can generally lay out a ban and leave it up to those impacted to figure out how to comply with the law. A hypothetical law could criminalize possession of all cryptocurrency wallet keys for all US citizens and all corporations that operate in the United States, with a regulatory agency tasked with adding to the list of “cryptocurrencies” each time someone launches a new one. There’s no reason in principle that a law couldn’t treat cryptocurrency wallet keys the same way that the law currently treats child porn, i.e. destroy all of your keys by X date or go to jail if you are discovered to still be in possession of them after the date the law goes into effect.

This would immediately destroy the entire cryptocurrency industry, and mining power in most or all networks would collapse to the point that the networks would essentially be defunct. Transaction volume and coin price on surviving networks could collapse to the point that it would be infeasible to pay an $XX million ransom, and ransomware developers would be back to where they were circa 8 years ago, with no real mechanism to untraceably receive millions of dollars.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#239

Interesting how everybody focuses on the things that they know about: technical solutions, legal solutions aiming at the victims, payment options and so on. When the real failure is somewhere else: bringing these perps to justice. The fact that they can get away with this over and over again hiding behind anonymity is what enables these crimes.

Unfortunately this is significantly harder than you might think. The perps tend to be citizens of countries who happily turn a blind eye to their activities so long as they aren't infecting their domestic systems. What interest do Russia or post-Soviet states have in prosecuting cybergangs that destabilize Western business and infrastructure? I mean, maybe we can create such interests/motivations, but now we are talking about a major geopolitical issue.

If major infrastructure continues to be hit I think we will eventually see this happen, but we absolutely cannot count on foreign states to 'do the right thing.'

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#240

Interesting how everybody focuses on the things that they know about: technical solutions, legal solutions aiming at the victims, payment options and so on. When the real failure is somewhere else: bringing these perps to justice. The fact that they can get away with this over and over again hiding behind anonymity is what enables these crimes.

The internet is global and ransomware developers operation out of jurisdictions that will not prosecute them. Unless you’re proposing Mossad-style unsanctioned kidnappings and assassinations, any approach that requires apprehending or prosecuting the people responsible is not a real option.
Post reply on HN