Nations should lessen the penalties for white-hat and even grey-hat hackers who report their findings. They should have strong protections; they are helping all of society and national security. Instead, we have politicians and executives who make legal threats to cover their mistakes and everyone suffers for it. I have this view because I have personally walked away from security problems I've discovered simply by p…
> Nations should lessen the penalties for white-hat and even grey-hat hackers who report their findings. you mean increase the rewards?
Illinois college, hit by ransomware attack, to shut down
31–40 of 89 posts
Re: Illinois college, hit by ransomware attack, to shut down
#32It sounds like they weren't in a great financial situation to begin with. Definitely a tragedy to have everything down for three months and to find out afterwards that you're not going to have enough money to stick around next year. I wonder what the ransom was and if they paid it. Side note: Planet Money had an interesting segment on insurance claims for things like cyber attacks last week, it's worth giving a liste…
Cyber insurance premiums are skyrocketing YoY due to ransomware attacks based on conversations with clients. Overall, it’s still a challenge to demonstrate the value of defending against them (reducing attack surface, real backups and data recovery plans, phishing exercises to see who is click happy and what their privileges have access to, etc) to folks who don’t understand the risk this poses. Like driving without…
A year ago they would just send a laptop with Nessus on it and then sign off on a risk sheet full of the usual llmnr/nebios/kerberoast/smb1 vulns because they didn't know what it meant. Now they will pop your domain administrator and refuse your renewal or jack your rates until you get a followup pentest demonstrating that those vulns have been resolved.
Re: Illinois college, hit by ransomware attack, to shut down
#33A tragedy That needs to happen The humanizing done about how its was something like an HBCU and weathered other calamities is sad, should also be a wakeup call to other organizations
I don't know why this was down voted, but I agree, that this tragic shutdown makes it clear that Ransomeware affects the real world.
The "we need more victims to change everyone's minds" is a strawman.
Re: Illinois college, hit by ransomware attack, to shut down
#34Hey, I actually have experience with that school! I did some consulting with them about a decade ago. The ransomware attack certainly didn't help, but it is wildly misleading to say, or even imply that caused them to shut down. The actual reasons: (a) They filled a niche that didn't need to be filled anymore. They used to absorb students from other local universities (ISU, UIS, UIUC). Those schools have realized the…
> enrollment management What would be a comparable industry perspective to the way colleges fight over tuition generators (students)? Oil companies fighting over oil fields?
Re: Illinois college, hit by ransomware attack, to shut down
#35How did we end up at a point where we are this reliant on the internet? Any truly critical system should not be connected to the public internet. Computers with internet connections are for sending email and reading Wikipedia. Any data critical to your organization should be accessed from separate terminals connected via LAN. No VPN, that's still the internet. Do that, and unless you're the CIA you will never be hack…
Another helper technology that's underused is data diodes, which prevent two-way connections but allow one-directional data flows, such as security updates for a lab full of workstations, or in the other direction, allowing internet monitoring of a source-of-truth or sensor while preventing internet tampering.
Unfortunately, distributed orgs can't as easily benefit from air gaps and data diodes, but they're effective tools when your physical boundaries align with your security boundaries such as in a lab or around a campus.
Re: Illinois college, hit by ransomware attack, to shut down
#36"Fortunately, no personal identifying information was exposed." How can they know this?
Re: Illinois college, hit by ransomware attack, to shut down
#37Hey, I actually have experience with that school! I did some consulting with them about a decade ago. The ransomware attack certainly didn't help, but it is wildly misleading to say, or even imply that caused them to shut down. The actual reasons: (a) They filled a niche that didn't need to be filled anymore. They used to absorb students from other local universities (ISU, UIS, UIUC). Those schools have realized the…
> enrollment management What would be a comparable industry perspective to the way colleges fight over tuition generators (students)? Oil companies fighting over oil fields?
Residential solar or real estate agents?
The crazy thing to me about higher ed is that there's large loans and everybody qualifies. We'd probably get a better skills/job match by including the major in interest rate calculations.
Re: Illinois college, hit by ransomware attack, to shut down
#38Earlier quoted context omitted.
> enrollment management What would be a comparable industry perspective to the way colleges fight over tuition generators (students)? Oil companies fighting over oil fields?
Any industry which has clients that pay for a service, I guess.
Re: Illinois college, hit by ransomware attack, to shut down
#39Nations should lessen the penalties for white-hat and even grey-hat hackers who report their findings. They should have strong protections; they are helping all of society and national security. Instead, we have politicians and executives who make legal threats to cover their mistakes and everyone suffers for it. I have this view because I have personally walked away from security problems I've discovered simply by p…
Way back in college, I talked myself into doing a white-hat hack of a service another student was running that I valued highly. He had used software with a rather nasty CERT advisory outstanding. My attempts failed, which meant he had patched his system, probably at the firewall. I shrugged and went on with life.
Or at least I tried to, because the next day I got an email from him telling me that he saw what I did and if I ever pulled shit like that again he'd report me to the Dean's Office. For the time, the university had some pretty sophisticated auditing tools to backtrack problems including shenanigans of this sort and because I was doing something 'good' I had just accessed his system straight from my dorm room (I found out shortly after that even if I had attempted to remote in he still would have been able to send that email).
I offered an "apology" that was about what you'd expect from a 20 year old white male: all excuses and rationalization. It hadn't quite sunk in yet that this distinction between black and white hat existed solely in my brain. I don't even think I bothered to tell my roommate what I was planning to do. I had zero alibi because I was impulsive. I never did anything like that again. If memory serves, I told him I'd never do something like that again (which means it was sinking in a little bit), and that has been largely true.
In hindsight, I was such an earnest kid that any decent lawyer could have would have been able to get me off with a warning, that would have saddled me with debts that would have fucked up my 20's, even if we had gotten a good rate through a family friend. I'd probably have still failed a background check on the piece of software that I worked on in my 30's that is and probably will remain one of the mantelpieces of my career.
The Venn diagram of people with a suspicious enough mind to think of trying what I did and the personality that would keep them out of big trouble is very narrow. But to your point, the circles for aptitude, desire, and history are pretty small. As it turns out, I didn't enjoy being a low-bus-number person responsible for the security of the system, so I now fall outside of the 'desire' circle. These days I'm content to help people sort out/select auth libraries, configure CA certs, and occasionally talk trash about cryptocurrency. I have enough other interests that I'm probably booked out until after retirement.
Re: Illinois college, hit by ransomware attack, to shut down
#40Earlier quoted context omitted.
Cyber insurance premiums are skyrocketing YoY due to ransomware attacks based on conversations with clients. Overall, it’s still a challenge to demonstrate the value of defending against them (reducing attack surface, real backups and data recovery plans, phishing exercises to see who is click happy and what their privileges have access to, etc) to folks who don’t understand the risk this poses. Like driving without…
Cyber providers are becoming much more savvy and are starting to decide that self-service 'yeah we are totally doing this' self-assessment checklists aren't sufficient. I have around 20 financial institutions on my client list and 11 of them have had their first hands-on penetration test in the past year. A year ago they would just send a laptop with Nessus on it and then sign off on a risk sheet full of the usual ll…