Wow, that's rough. Not much you can do against a vulnerability that'll destroy the trust of your entire customer base. A DDOS is one thing but I probably would have paid the millions in this case.
I wonder how much it would have cost to push out an update to all of the Symbian devices in the wild at the time. It wouldn't have been easy, and would have been a PR nightmare, but it could have been done. The question is: would it have been worth it? I don't know, but hiding things rarely goes well. Then again, I don't know of any public instances where this has happened, but I'm sure Nokia aren't the only ones to…
Nokia 'paid millions to software blackmailers six years ago'
31–40 of 49 posts
Re: Nokia 'paid millions to software blackmailers six years ago'
#32That's absolutely insane! Even after paying the ransom, how could they be sure noone were still sitting on the keys? Assuming it's code signing keys, it sounds incredibly irresponsible to not (force) update all devices anyways. Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on? ... makes me wonder what else we don't know abo…
In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.
Re: Nokia 'paid millions to software blackmailers six years ago'
#33I'm trying to imagine this happening to someone like Red Hat. BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!" Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.
I think the analogy is a little off. This would be like someone having the GPG signing key for the Red Hat official repositories. It would give them the ability to insert their own (malicious) software package into the Red Hat update stream without the signature throwing any warnings.
Re: Nokia 'paid millions to software blackmailers six years ago'
#34That's absolutely insane! Even after paying the ransom, how could they be sure noone were still sitting on the keys? Assuming it's code signing keys, it sounds incredibly irresponsible to not (force) update all devices anyways. Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on? ... makes me wonder what else we don't know abo…
If that were the case, they didn't buy the promise the evil doers wouldn't use the keys, but the ability to start using it themselves again. They still would have to phase out the compromised master key real soon, but that might be easier to do if one has it in hand.
Disclaimer: I know to little about key management to know whether the above makes sense. In particular, I doubt that having your compromised key makes any difference in the difficulty of phasing it out.
Re: Nokia 'paid millions to software blackmailers six years ago'
#35Re: Nokia 'paid millions to software blackmailers six years ago'
#36Re: Nokia 'paid millions to software blackmailers six years ago'
#37Like a rootkit then ? It's a classic case of robbing the mob, as in 'the people who actually own the phone you think you've bought'.
Re: Nokia 'paid millions to software blackmailers six years ago'
#38Earlier quoted context omitted.
In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.
If you or anyone else has any insights: why not airgap energy grid electronics? Companies should two networks, and never let them talk to each other, except perhaps under very controlled and secure conditions. It seems like that would alleviate huge chunks of the security concerns. Now obviously people with physical access could get around that, but if you have physical access, you mostly own computers anyway.
Heavily control and packet sniff anything moving between levels.
Re: Nokia 'paid millions to software blackmailers six years ago'
#39Earlier quoted context omitted.
It's almost out of a movie. One of your larger national companies is being extorted and you fail to follow the people doing so? It also had to be a pretty big vulnerability for them to have to pay that much in the first place.
It makes it sound like it was the keys to the castle.
Re: Nokia 'paid millions to software blackmailers six years ago'
#40'the money was delivered but the police lost track of the culprits' A solid showing by the Helsinki police
Or a very well planned getaway. Given that the culprits managed to steal Nokia's signing key, I suspect they knew what they were doing.