While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…
Nothing will change until they make it a felony to pay a ransom.
US travel firm $4.5M ransom negotiation open chat
431–440 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#432For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…
Re: US travel firm $4.5M ransom negotiation open chat
#433Earlier quoted context omitted.
> To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. I see your point but this is flat-out organized crime, extortion to be precise. How long will it be before we're all making protection payments to ransomware groups?
What makes crime "organised"? There's no indication that this involved more than one thief.
Re: US travel firm $4.5M ransom negotiation open chat
#434Earlier quoted context omitted.
> It's easy-mode for security because it offloads the cost of security to employees. Yeah, absolutely. But I consider this to be, when done right, a good thing. A single security team is going to drown trying to scale your company's security asymmetrically with your company's growth. For every 1000 developers you might have 5-50 security engineers depending on how serious the company is about it. Spreading out securi…
We're trying to do much of what you mention here. It ain't easy. Here's some of my thoughts, as one of the people in Development trying to achieve it. The app whitelist impairs my efficiency, and honestly takes a fair amount of fun out of work. I can no longer use many of the tools that help me , and instead am confined into the corporate-approved structure. This is both a productivity issue and a job satisfaction is…
Out of curiosity, like what?
> Trying to separate
Yeah, like I said, starting early is going to make things much easier. If you're trying to get to this place later on, it's just wayyyyyy harder and most orgs can't get there. This is often the case with security - if you build your code, infra, policy, etc, with security in mind from day 1 it's 1000s of times simpler than doing it even just a few years later.
> Coming up with the right mix of apps, and convincing our Risk team, is very difficult.
Oh yeah, a risk team can be the real killer. That's why upvote is nice - security only gets involved if something is flagged. But if your risk team isn't willing to work with you that's a problem, and it sounds like yours isn't doing the work consistently.
To me, approval should be easy. Even if a malicious app is approved that's often still a huge win - the attacker can't use many of the tools and techniques they're used to. Obviously you want to avoid that compromise too, but it isn't the whole entire goal.
We whitelist some vendors entirely. Our app whitelist request form is:
* What risks are there with this extension/ app?
* Is there another approved app that can do this, and if so, why do we need this one?
* How will this app help you? What is it for?
That first question is really important because people usually have a decent understanding of what the app should/ shouldn't be doing, or if the risk should be trivial. It's all about spreading the assessment out.
Re: US travel firm $4.5M ransom negotiation open chat
#435Earlier quoted context omitted.
I think this is a step in the right direction, but I'd expand this to be a tax on all organizations that maintain large enough systems to become targets because: 1. Taxing only the victims is adding salt to a wound: these companies are already hurting from being attacked, lost money to the ransomer, and are likely to lose more shortly thereafter due to bad PR. They'll need this money to fix things and hire/consult ap…
It's almost like there should be some national security agency whose sole purpose would be to uncover this kind of activity and help those impacted. I wonder what I'd call it?
Jokes aside, I absolutely agree that this is a failure of the US federal government and congress. We should have answers for these things for now, or at least the beginnings of a national security program to combat cyber crime. The FBI is seriously overwhelmed and the other three letter agencies can't be bothered to play the blue team as far as I'm aware.
Re: US travel firm $4.5M ransom negotiation open chat
#436Earlier quoted context omitted.
Yeah, let's just equate criminal behavior with doing people a service, that's going to reflect well on people in IT.
No worse than us being unable to take an extremely obvious joke as a joke, and feeling the need to respond to it as if it wasn't meant completely in jest.
Re: US travel firm $4.5M ransom negotiation open chat
#437Earlier quoted context omitted.
I would assume one address with 377k transactions that has seen over 131 million BTC move through it strongly implies it's some sort of tumbler address. I'm not sure why reusing one address like this would make any sense though...
It is more difficult to trace funds through a single node with gazillion transactions. This is part of the laundering scheme. Of course, all such addresses are immediately suspect, but if they pay out to innocent addresses too... It's difficult to distinguish between signal and noise.
Re: US travel firm $4.5M ransom negotiation open chat
#438Earlier quoted context omitted.
The main one I know of is international money transfers (remittances). Usually these have to go through an oligopoly that sets the fees and exchange rates to be favorable to itself. This is the kind of market that's pretty big on the international scale, but it's completely boring and non-sensational to read about a bunch of people who are sending $400 to their moms on a regular basis.
As far as I know, nearly everyone uses Western Union (Transferwise etc. etc.) for that. Bitcoin is too costly* and complicated for most people. * Two set of fees to exchange crypto to fiat + transfer fee compared to one set of fiat currency exchange + transfer fee.
Re: US travel firm $4.5M ransom negotiation open chat
#439Earlier quoted context omitted.
We need to make laws in western countries that paying off these kinds of ransoms is illegal. It gives money to criminal elements and only encourages this. I also thought it would be possible for powerful law enforcement groups to follow the bitcoins even through exchanges. Why does this not run into the worldwide hunt for the perpetrators?
> We need to make laws in western countries that paying off these kinds of ransoms is illegal. That'd be the sort of counter-productive legislation we see too often. The only result would be to push this underground and to keep authorities in the dark. It might end up helping criminals. A similar case has been made about corruption: If you're asked for a bribe by, say, a corrupt official you usually have no choice bu…
You may be able to clearly document the attempted bribery, and report it to the relevant authority—which may be a central agency of some form, or may be just going up the chain within the same organisation. Success will vary by country, authority and magnitude of offence. But even threatening to do this (politely) normally achieves the desired result, though it does nothing to actually uproot the corruption.
Alternatively, just indicate clearly that you’re not willing to play along with this illegal behaviour.
The zero rupee note (https://en.wikipedia.org/wiki/Zero_rupee_note) is a fairly successful example of doing this, and bear in mind that India corruption problem is much larger than any western country’s—although it’s illegal, it’s still par for the course in a great many areas. Yet standing up to this bribery is quite possible if only you have any inclination to do so.
I am currently in India, residing with another Australian who has lived in India for forty-odd years and operated business locally, and bribes were solicited from time to time, but he would not play ball, typically by either pretend nothing had happened (that is, ignoring any “hints” that you could pay for such-and-such) or by actively declining. Flunkies that try to take bribes personally are generally quite ready to backtrack once they see which way the wind is blowing (they could get in trouble with their boss), and more institutional bribery can generally be waited out, at the least. Even if it’s occasionally a long wait (like, months instead of days, or years instead of weeks).
A large part of the fight on these sorts of issues is changing cultural norms. Consider seatbelts over time in Australia (and much of the world): fifty years ago seatbelts were uncommon, but legislation was paired with a big marketing push to normalise wearing seatbelts had the effect that before terribly long society would look down with severe displeasure on anyone that didn’t wear a seatbelt while driving, so that now most people (well over 99% of the driving population, at a guess) wouldn’t dream of driving without wearing a seatbelt. The same is possible here, and will be far easier than selling ice to proverbial eskimos, because it’s easy to take the moral high ground in advertising (and moral high ground is almost as powerful as safety and “think of the children”): we will not parley with criminals.
Re: US travel firm $4.5M ransom negotiation open chat
#440Earlier quoted context omitted.
Even just hiring one guy whose only job is to take backups would solve ransomware for much cheaper.
There was a post on here a few days back about why it's not that simple. Basically, by the time your stuff is ransomed, they've potentially been in your network for a long time. There's no telling how far you have to go in your backups to make sure they are gone. Who knows, maybe they wait on your computers for several months just so restoring from backups isn't a realistic option, and punish you for trying.
If your backup process "isn't that simple", then you should make it that simple. Otherwise failure looms.