Power

Why the security industry can't fix the ransomware problem

Ransomware is one of the most pressing cybersecurity problems, but there's no high-tech fix.

Christopher Krebs

Ransomware is "the scourge of the Internet," said Christopher Krebs, pictured here at the U.S Conference of Mayors 88th Winter Meeting in January.

Photo: Tom Williams/CQ-Roll Call, Inc via Getty Images

Schools shutting down. Hospitals turning patients away. City governments paralyzed. Businesses racking up nine-figure losses.

Ransomware has grown to one of the biggest cybersecurity threats facing organizations, but the security industry might only be able to do so much to help. At the RSA security conference in San Francisco this week, the Department of Homeland Security's top cybersecurity official Christopher Krebs called it "the scourge of the Internet," and CrowdStrike co-founder Dmitri Alperovitch dubbed 2019 "the year of ransomware."

Get what matters in tech, in your inbox every morning. Sign up for Source Code.

But people who came hoping to learn about some high-tech fix for one of cybersecurity's fastest-growing problems are going to be disappointed. Almost none of the conference's hundreds of panels focuses on ransomware, which locks up data and devices until victims pay a demand, typically in bitcoin. Firms that claimed to have sophisticated technology to counter the problem have been exposed for simply paying the ransom demand.

That's because one of the biggest cybersecurity threats pummeling organizations happens to have a pretty boring solution.

Brett Arsenault, Microsoft's chief information security officer, said that it's not a mystery how to protect an organization from ransomware. The first step is not letting it in, which can be accomplished through basic measures such as regularly patching your systems and teaching employees not to fall for phishing emails, he said. The second step is to have backups in place to restore your systems in case they are infected.

"People still underestimate and undervalue the pedestrian part of this job," he said. "Hygiene is still key. I see people spending all this money on widgets that are akin to having a massively awesome alarm system on the front of your house, but it means nothing if you leave your back door open all the time."

Out of more than 500 panels being held throughout the week at the RSA security conference in San Francisco, only one on the agenda was explicitly focused on ransomware (a second, about the city of Atlanta's ransomware recovery efforts, was canceled). The panel, sponsored by network security firm SonicWall, was in a packed 70-seat makeshift briefing room on the expo floor, with dozens of people sitting on the ground. SonicWall Senior Product Marketing Manager Brook Chelmo spent the 30-minute talk sharing insights from his conversations with two ransomware attackers. Their advice to companies trying to protect themselves: Use proper passwords, enable multifactor authentication, hire good cybersecurity employees, and watch out for misconfigured firewalls.

In other words, to protect yourself from one the most dangerous threats, you have to cover the basics.

That explains why so many ransomware victims have been municipal governments, school districts and hospitals, said Ryan Lasalle, North America lead at Accenture Security. These organizations often lack the budget and personnel to keep computer networks up-to-date and protected. In many cases, these organizations don't have a trained employee dedicated to cybersecurity.

That's not to say that large savvy organizations don't need to think about ransomware. The threat is particularly serious because of the massive damage it can cost, both in terms of financial losses and safety risks, Lasalle said. One manufacturer that Accenture works with has determined that a ransomware attack would cost them $1 million an hour in lost revenue, he said. "Even if you're a Fortune 500 company, you don't want to be losing $25 million a day," he said.

Get in touch with us: Share information securely with Protocol via encrypted Signal or WhatsApp message, at 415-214-4715 or through our anonymous SecureDrop.

But for organizations that have the basics covered, there's little else they can do besides plan for the worst-case scenario. The questions then become things like do you pay the demand or ignore it? Do you buy cyber insurance to help cover the costs?

Arsenault said his team at Microsoft went so far as to consider if they should stockpile bitcoin, the preferred ransom currency of attackers. "A thought was should we buy a bunch of bitcoin now, because if we had to pay a ransom in the future, the price of bitcoin is going up. We thought about it and talked to our CFO, and she was like … 'No. You should make sure we have a process and know how to do it and invoke it at the time, but we're not going to hedge,'" he said.

Climate

A pro-China disinformation campaign is targeting rare earth miners

It’s uncommon for cyber criminals to target private industry. But a new operation has cast doubt on miners looking to gain a foothold in the West in an apparent attempt to protect China’s upper hand in a market that has become increasingly vital.

It is very uncommon for coordinated disinformation operations to target private industry, rather than governments or civil society, a cybersecurity expert says.

Photo: Goh Seng Chong/Bloomberg via Getty Images

Just when we thought the renewable energy supply chains couldn’t get more fraught, a sophisticated disinformation campaign has taken to social media to further complicate things.

Known as Dragonbridge, the campaign has existed for at least three years, but in the last few months it has shifted its focus to target several mining companies “with negative messaging in response to potential or planned rare earths production activities.” It was initially uncovered by cybersecurity firm Mandiant and peddles narratives in the Chinese interest via its network of thousands of fake social media accounts.

Keep Reading Show less
Lisa Martine Jenkins

Lisa Martine Jenkins is a senior reporter at Protocol covering climate. Lisa previously wrote for Morning Consult, Chemical Watch and the Associated Press. Lisa is currently based in Brooklyn, and is originally from the Bay Area. Find her on Twitter ( @l_m_j_) or reach out via email (ljenkins@protocol.com).

Some of the most astounding tech-enabled advances of the next decade, from cutting-edge medical research to urban traffic control and factory floor optimization, will be enabled by a device often smaller than a thumbnail: the memory chip.

While vast amounts of data are created, stored and processed every moment — by some estimates, 2.5 quintillion bytes daily — the insights in that code are unlocked by the memory chips that hold it and transfer it. “Memory will propel the next 10 years into the most transformative years in human history,” said Sanjay Mehrotra, president and CEO of Micron Technology.

Keep Reading Show less
James Daly
James Daly has a deep knowledge of creating brand voice identity, including understanding various audiences and targeting messaging accordingly. He enjoys commissioning, editing, writing, and business development, particularly in launching new ventures and building passionate audiences. Daly has led teams large and small to multiple awards and quantifiable success through a strategy built on teamwork, passion, fact-checking, intelligence, analytics, and audience growth while meeting budget goals and production deadlines in fast-paced environments. Daly is the Editorial Director of 2030 Media and a contributor at Wired.
Fintech

Ripple’s CEO threatens to leave the US if it loses SEC case

CEO Brad Garlinghouse said a few countries have reached out to Ripple about relocating.

"There's no doubt that if the SEC doesn't win their case against us that that is good for crypto in the United States,” Brad Garlinghouse told Protocol.

Photo: Stephen McCarthy/Sportsfile for Collision via Getty Images

Ripple CEO Brad Garlinghouse said the crypto company will move to another country if it loses in its legal battle with the SEC.

Garlinghouse said he’s confident that Ripple will prevail against the federal regulator, which accused the company of failing to register roughly $1.4 billion in XRP tokens as securities.

Keep Reading Show less
Benjamin Pimentel

Benjamin Pimentel ( @benpimentel) covers crypto and fintech from San Francisco. He has reported on many of the biggest tech stories over the past 20 years for the San Francisco Chronicle, Dow Jones MarketWatch and Business Insider, from the dot-com crash, the rise of cloud computing, social networking and AI to the impact of the Great Recession and the COVID crisis on Silicon Valley and beyond. He can be reached at bpimentel@protocol.com or via Google Voice at (925) 307-9342.

Policy

The Supreme Court’s EPA ruling is bad news for tech regulation, too

The justices just gave themselves a lot of discretion to smack down agency rules.

The ruling could also endanger work on competition issues by the FTC and net neutrality by the FCC.

Photo: Geoff Livingston/Getty Images

The Supreme Court’s decision last week gutting the Environmental Protection Agency’s ability to regulate greenhouse gas emissions didn’t just signal the conservative justices’ dislike of the Clean Air Act at a moment of climate crisis. It also served as a warning for anyone that would like to see more regulation of Big Tech.

At the heart of Chief Justice John Roberts’ decision in West Virginia v. EPA was a codification of the “major questions doctrine,” which, he wrote, requires “clear congressional authorization” when agencies want to regulate on areas of great “economic and political significance.”

Keep Reading Show less
Ben Brody

Ben Brody (@ BenBrodyDC) is a senior reporter at Protocol focusing on how Congress, courts and agencies affect the online world we live in. He formerly covered tech policy and lobbying (including antitrust, Section 230 and privacy) at Bloomberg News, where he previously reported on the influence industry, government ethics and the 2016 presidential election. Before that, Ben covered business news at CNNMoney and AdAge, and all manner of stories in and around New York. He still loves appearing on the New York news radio he grew up with.

Enterprise

Microsoft and Google are still using emotion AI, but with limits

Microsoft said accessibility goals overrode problems with emotion recognition and Google offers off-the-shelf emotion recognition technology amid growing concern over the controversial AI.

Emotion recognition is a well-established field of computer vision research; however, AI-based technologies used in an attempt to assess people’s emotional states have moved beyond the research phase.

Photo: Microsoft

Microsoft said last month it would no longer provide general use of an AI-based cloud software feature used to infer people’s emotions. However, despite its own admission that emotion recognition technology creates “risks,” it turns out the company will retain its emotion recognition capability in an app used by people with vision loss.

In fact, amid growing concerns over development and use of controversial emotion recognition in everyday software, both Microsoft and Google continue to incorporate the AI-based features in their products.

“The Seeing AI person channel enables you to recognize people and to get a description of them, including an estimate of their age and also their emotion,” said Saqib Shaikh, a software engineering manager and project lead for Seeing AI at Microsoft who helped build the app, in a tutorial about the product in a 2017 Microsoft video.

Keep Reading Show less
Kate Kaye

Kate Kaye is an award-winning multimedia reporter digging deep and telling print, digital and audio stories. She covers AI and data for Protocol. Her reporting on AI and tech ethics issues has been published in OneZero, Fast Company, MIT Technology Review, CityLab, Ad Age and Digiday and heard on NPR. Kate is the creator of RedTailMedia.org and is the author of "Campaign '08: A Turning Point for Digital Media," a book about how the 2008 presidential campaigns used digital media and data.

Latest Stories
Bulletins