Live data from Hacker News

Nokia 'paid millions to software blackmailers six years ago'

timminspress.com

31–40 of 49 posts

Re: Nokia 'paid millions to software blackmailers six years ago'

#31
post #10
post #6

Wow, that's rough. Not much you can do against a vulnerability that'll destroy the trust of your entire customer base. A DDOS is one thing but I probably would have paid the millions in this case.

I wonder how much it would have cost to push out an update to all of the Symbian devices in the wild at the time. It wouldn't have been easy, and would have been a PR nightmare, but it could have been done. The question is: would it have been worth it? I don't know, but hiding things rarely goes well. Then again, I don't know of any public instances where this has happened, but I'm sure Nokia aren't the only ones to…

Code signing key compromise has happened at least for Red Hat and Adobe quite publicly. Plenty of malware use code signed windows device drivers with stolen(?) hw manufacturer keys, too.

Re: Nokia 'paid millions to software blackmailers six years ago'

#32
post #19

That's absolutely insane! Even after paying the ransom, how could they be sure noone were still sitting on the keys? Assuming it's code signing keys, it sounds incredibly irresponsible to not (force) update all devices anyways. Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on? ... makes me wonder what else we don't know abo…

In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.

If you or anyone else has any insights: why not airgap energy grid electronics? Companies should two networks, and never let them talk to each other, except perhaps under very controlled and secure conditions. It seems like that would alleviate huge chunks of the security concerns. Now obviously people with physical access could get around that, but if you have physical access, you mostly own computers anyway.

Re: Nokia 'paid millions to software blackmailers six years ago'

#33

I'm trying to imagine this happening to someone like Red Hat. BM: "We have the keys to your software repos give us money or we leak." RH: "Here's a tarball of the sources it make your life easier, knock yourselves out! Maybe we'll even get some new developers!" Obviously there are reason's why companies choose to keep their software closed source, but sometimes I wonder.

I think the analogy is a little off. This would be like someone having the GPG signing key for the Red Hat official repositories. It would give them the ability to insert their own (malicious) software package into the Red Hat update stream without the signature throwing any warnings.

Isn't that why we keep revocation certs around? That doesn't really work for blackmail anyway because it is dependent on preventing the organization from knowing that you have access.

Re: Nokia 'paid millions to software blackmailers six years ago'

#34
post #19

That's absolutely insane! Even after paying the ransom, how could they be sure noone were still sitting on the keys? Assuming it's code signing keys, it sounds incredibly irresponsible to not (force) update all devices anyways. Is really the only thing protecting the safety of those devices the promise of a blackmailer to not abuse the private keys they were sitting on? ... makes me wonder what else we don't know abo…

An explanation could be that Nokia, at the time, did not have the keys anymore. A scenario could be that they kept their top level signing key printed on paper in a vault (not that problematic, as your top level key should be used very rarely), and that paper somehow got stolen.

If that were the case, they didn't buy the promise the evil doers wouldn't use the keys, but the ability to start using it themselves again. They still would have to phase out the compromised master key real soon, but that might be easier to do if one has it in hand.

Disclaimer: I know to little about key management to know whether the above makes sense. In particular, I doubt that having your compromised key makes any difference in the difficulty of phasing it out.

Re: Nokia 'paid millions to software blackmailers six years ago'

#37
> Had it done so anyone could then have written additional code for Symbian including possible malware which would have been indistinguishable from the legitimate part of the software.

Like a rootkit then ? It's a classic case of robbing the mob, as in 'the people who actually own the phone you think you've bought'.

Re: Nokia 'paid millions to software blackmailers six years ago'

#38
post #32

Earlier quoted context omitted.

In 2008, forced updates of mobiles, particularly of the s40 and s60 variety, was not a thing. It turns out that when an operating system is in service for a very long time without updates, bad things happen. Now if you want a real scare, consider for a moment all of the code running on embedded hardware that makes up the entirety of the world energy grid.

If you or anyone else has any insights: why not airgap energy grid electronics? Companies should two networks, and never let them talk to each other, except perhaps under very controlled and secure conditions. It seems like that would alleviate huge chunks of the security concerns. Now obviously people with physical access could get around that, but if you have physical access, you mostly own computers anyway.

http://en.wikipedia.org/wiki/Purdue_Enterprise_Reference_Arc...

Heavily control and packet sniff anything moving between levels.

Re: Nokia 'paid millions to software blackmailers six years ago'

#39
post #4
post #3

Earlier quoted context omitted.

It's almost out of a movie. One of your larger national companies is being extorted and you fail to follow the people doing so? It also had to be a pretty big vulnerability for them to have to pay that much in the first place.

It makes it sound like it was the keys to the castle.

It was. They could have signed any phone application to pretend like it was developed by Nokia, and therefore could have done anything to the phones (hence the malware angle).

Re: Nokia 'paid millions to software blackmailers six years ago'

#40
post #2

'the money was delivered but the police lost track of the culprits' A solid showing by the Helsinki police

A solid showing by the Helsinki police

Or a very well planned getaway. Given that the culprits managed to steal Nokia's signing key, I suspect they knew what they were doing.

Post reply on HN