Garmin, now this, in one week. I beleive it is much easier to pull a trick like this with the help from the inside. If so, with malicious insider's incentives in a ballpark of hundreds of thousands we are doomed :(
US travel firm $4.5M ransom negotiation open chat
361–370 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#362Re: US travel firm $4.5M ransom negotiation open chat
#363It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
Re: US travel firm $4.5M ransom negotiation open chat
#364Earlier quoted context omitted.
Do you want a solution that makes such an attack unprofitable to execute (i.e. it raises the cost of doing a similar attack above $4.5M)? Buy insurance and pray. There is not a single readily available enterprise solution that would even dare to put that in writing, let alone deliver. If there is one that does dare, ask to test their claim by having the deal conditional on them putting out an open $4.5M bug bounty an…
Not a good test. If they expect a decent ROI, the attack can't cost any amount up to $4.5M to execute. The $4.5M isn't a guaranteed outcome from such an attack. Some targets may not be willing to pay, or may only be willing to pay a substantially smaller amount. Also, part of the execution cost is the non-monetary "breaking the law" factor. For instance, would you rather make a legal $1M or an illegal $2M?
If you are not, I am not sure what you are arguing since all of your statements show how the test overestimates the difficulty. The test is designed to identify, with reasonably high confidence, whether any attack is profitable given a specific upside. Therefore it should be as easy as possible for a legitimate bug that could result in at least a $4.5M upside to be paid.
A 100% guaranteed legal payout clearly minimizes the risk and thus allows more attacks below a $4.5M cost to execute to be profitable. Any other form of payout means the cost to execute must be lower to be profitable. Put another way, if it is unprofitable to do it totally legally for some amount of money, it is probably even more unprofitable to do it illegally for the same amount of money (obviously this excludes cases where you might be able to gain a higher upside, but then we are not talking about mitigating attacks with a certain upside), therefore this estimate should be no lower than the true cost to execute (on average).
To use your examples:
If they want a decent ROI, the cost of attack must be significantly less than $4.5M to execute to be a good investment. ROI of illegal actions usually needs to be higher to make up for the risk since you would almost always choose a legal action with the same ROI.
If the probability of payout is less than 100%, then the cost of attack must be less than $4.5M to make up for the reduced probability of success. The probability of payout for a bug bounty is usually higher than the highly variable payout of an attack. Also since the buyer is using this to make a quality decision and has authority to force the vendor to pay out with the stated scheme, it is in the buyers best interest to pay out credible attacks.
If the non-legal nature is a serious cost, then the cost of attack must be less than $4.5M for the illegal case to make up for the extra risk and cost. Non-legal actions usually come with extra costs compared to legal actions and thus have to be even more profitable to be worth doing.
Therefore, if a $4.5M bug bounty (where payout is decided by the product buyer) is not claimed after some reasonable amount of time we can conclude, with some reasonable amount of confidence, that the lowest risk option is likely unprofitable. Therefore, higher risk illegal options with the same upside are even less likely to be profitable. Thus, the test is a relatively good lower-bound for identifying if attacks with a $4.5M upside are actually being mitigated. If you can not even institute this lower bound, then you are nowhere near the necessary level.
Re: US travel firm $4.5M ransom negotiation open chat
#365It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.
Re: US travel firm $4.5M ransom negotiation open chat
#366Earlier quoted context omitted.
Don’t be surprised if companies would rather roll the dice than pay whatever it costs to prevent the problem. $4 million once times the risk of getting hit vs. the up-front and ongoing costs of dealing with an overly paranoid IT guy. Tough call.
How many times would you need to do a security audit before this paid for itself?
Re: US travel firm $4.5M ransom negotiation open chat
#367While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…
Meanwhile in the real world, a company I develop for implemented the most draconian security measures to "prevent ransomware".
Development environment is a virtual machine at the other end of the world, with disabled copy-pasting from and to the local system. A complete separation between safe internal network and unsafe development environment. No copy pasting from and to email, etc. Horrible environment to work in.
Re: US travel firm $4.5M ransom negotiation open chat
#368Earlier quoted context omitted.
The ransom payment isn't really a theft or robbery, they didn't have to give it.
At the bottom of the thread the ransomers gave them security advice. Therefore this is an "unplanned penetration test" and gets filed as "consulting" on the expenses side of the accounts. Almost all money going out of a business can be deducted from money coming for purposes of counting taxable profit. I'm having a hard time thinking of one that isn't.
Re: US travel firm $4.5M ransom negotiation open chat
#369Earlier quoted context omitted.
Isn’t stuff stolen in a theft/robbery deductible generally?
The ransom payment isn't really a theft or robbery, they didn't have to give it.
Yet, regardless of how much you pay Bill, his wages are tax-deductible.
Re: US travel firm $4.5M ransom negotiation open chat
#370Earlier quoted context omitted.
When I started my career I'd always hear old greybeards talk about "oh this one time.. some certain thing happened, and everyone learnt a lesson" and I feel like I just witnessed one of those come into existence
Don’t be surprised if companies would rather roll the dice than pay whatever it costs to prevent the problem. $4 million once times the risk of getting hit vs. the up-front and ongoing costs of dealing with an overly paranoid IT guy. Tough call.