Why the Colonial Pipeline ransomware attack is a sign of things to come

Ransomware has grown fouler than ever, but it’s also grown up. The practice of using malware to encrypt files on a victim’s devices and then demanding a ransom payment for unlocking them has advanced far beyond its origins as a nuisance for individual users. These days, it’s a massively profitable business that has spawned its own ecosystem of partner and affiliate firms. And as a succession of security experts made clear at the RSA Conference last week, we remain nowhere near developing an equivalent of a vaccine for this online plague. “It’s professionalized more than it’s ever been,” said Raj Samani, chief scientist at McAfee, in an RSA panel . “Criminals are starting to make more money,” said Jen Miller-Osborn, deputy director of threat intelligence at Palo Alto Networks’ Unit 42, in another session . She added that the average ransomware payout now exceeds $300,000, fueled by such tactics as the “double extortion” method of exfiltrating sensitive data from targeted systems and then threatening to post it. That method figured in recent ransomware attacks against Colonial Pipeline and Washington, D.C.’s Metropolitan Police Department . “It’s such a lucrative business now for the criminals, it is going to take a full court press to change that business model,” agreed Michael Daniel, president and CEO of the Cyber Threat Alliance, in that panel. (Just five years ago, the $17,000 ransom reportedly paid by a compromised hospital was a newsworthy figure.) Having this much money sloshing around has given rise to networks of affiliates and brokers. Samani’s colleague John Fokker, head of cyber investigations at McAfee, explained the rise of “ransomware as a service” (“RaaS”), in which you can buy or rent exploit kits or back doors into companies. He showed one ad from an “access broker” that listed a price of $7,500 for compromised Virtual Private Network accounts at an unspecified Canadian firm. The ad vaguely described this target company as a “Consumer Goods (manufacturing, retailing, food etc…)” enterprise with about 9,000 employees and $3 billion in revenue. “The commoditization of these capabilities for the criminals makes it so easy,” said Phil Reiner, CEO of the Institute for Security and Technology, during one of the RSA panels. RSA speakers noted how often ransomware attacks start with exploitations of known, avoidable vulnerabilities. Samani called Microsoft’s Remote Desktop Protocol “the number-one most common entry vector for corporate networks related to ransomware attacks.” Fokker added that companies that use RDP often make this remote-access tool too easy to compromise, joking that RDP also means “really dumb passwords.” The pandemic has helped grease the skids further for ransomware attacks—both by requiring companies to rush into remote work and by making people a little more tempted to respond to COVID-themed phishing lures. As Samani put it, phishing is “still there, still works, people still click on links.” Two other factors make ransomware especially resistant to any suppression attempts. One is cryptocurrency enabling hard-to-trace online funds transfers. Bitcoin and other digital currencies may not be too useful for everyday transactions , but they suit the business of ransomware well Read More …

New iPad Pro: Amazing hardware in search of equally amazing software

There’s a long-standing urban myth that Apple designs products with planned obsolescence in mind—intentionally engineering them so that you’ll grow dissatisfied over time and want to replace them with something newer and shinier. Don’t you believe it. The company actually has a pretty impressive track record of building products that remain useful for the long haul, even well after they’ve been discontinued and replaced. One of the best recent examples is the iPad Pro that arrived back in November 2018 . Now theoretically two generations out of date, it belies its age by feeling just about as fast, fresh, stylish, and capable as it did on day one. It’s even compatible with Apple’s Magic Keyboard, which shipped 16 months later and took the iPad Pro to new heights as a laptop replacement. That 2018 iPad Pro was so good, in fact, that it hasn’t cried out for reinvention. Last year’s iPad Pro  acknowledged that by focusing on improvements to the rear camera system, including some aimed at making augmented-reality apps work better. For most iPad Pro users, it was the kind of update you could sensibly skip, biding your time to see what came next. That time has arrived. Apple is about to release  another new iPad Pro that, like last year’s model, retains the industrial design and basic feature set of the 2018 version. (It officially arrives in stores on Friday, though it’s already in enough demand that Apple is quoting availability dates for new preorders in late June and July.) I’ve spent more than a week with a prerelease 12.9-inch unit provided by Apple, along with a Magic Keyboard case and Pencil stylus. (The keyboard is the new white version , which looks mighty sharp—and, unlike any previous iPad keyboard, is color-coordinated with the Pencil.) Finally, an iPad keyboard case that matches Apple’s Pencil. [Photo: Harry McCracken] In terms of sheer technical excellence, this new iPad Pro is a good-size leap beyond its 2018 and 2020 predecessors. Read More …

AT&T’s WarnerMedia merger with Discovery could mean higher prices for you

Here we go again. Another two media companies have decided that they can’t live with being less successful than Netflix, and so they’re merging together in hopes of creating a larger competitor. This time, the jealous parties are AT&T and Discovery, which announced plans for a $43 billion merger on Monday morning. If regulators approve, the deal would effectively undo AT&T’s previous mega-merger with Time Warner in 2018, creating a new standalone company that pools WarnerMedia’s entertainment assets—including HBO Max and cable channels like CNN—with those of Discovery. AT&T CEO John Stankey said the goal is to create “one of the leading global direct-to-consumer streaming platforms.” Never mind that Discovery’s existing streaming efforts have been going pretty well, racking up 15 million subscribers since Discovery+ launched in early January with favorites like Deadliest Catch and Diners, Drive-Ins, and Dives . And never mind that HBO Max has been enjoying a growth spurt as well, with a combined 63.9 million HBO and HBO Max subscribers in the United States, up from 53.8 million a year ago. If you really want to compete with Netflix, these companies seem to say, you’ve got to be even bigger. Unfortunately for us, that probably translates more bloated TV services at higher prices. We’ve been down this road before, and it always ends the same way. TV mergers and price hikes: A brief history For an example of how big media company mergers lead to higher prices, we need only look to Viacom’s merger with CBS in 2019 Read More …

The CDC’s new masking rules don’t mean you can unmask just yet

On Thursday, the Centers for Disease Control and Prevention issued huge news: If you’ve been fully vaccinated, you can stop wearing a mask. Now, health experts are expressing concern about the new rule and telling Americans to proceed with caution. The CDC’s new guidelines come with a few caveats. Americans must follow the rules of local businesses and mask up on planes, trains, buses, and other transit. But for the most part, vaccinated people can go back to the way they lived life before the pandemic. What these broad recommendations don’t account for, health experts say, is how much COVID-19 is spreading in a given community versus how many people are vaccinated. I remain concerned that we will see summer surges in states with low vaccine rates… but again, those states were largely unmasked to begin with. ????‍♀️????‍♀️????‍♀️ But – at some point, people can do unsafe things ***as long as*** it doesn’t endanger the rest of us. — Megan Ranney MD MPH ???? (@meganranney) May 14, 2021 The problem is the way the recommendation bifurcates Americans into two health statuses: vaccinated and unvaccinated. There are people who do not want to get vaccinated and the new guideline may alienate unvaccinated Americans. The hope is that the recommendation will incentivize unvaccinated Americans to get vaccinated. But that may not be the way it works out. “These guidelines rely on unvaccinated people to keep masking, and to be forthcoming about that status,” writes pediatrician Daniel Summers, in an opinion piece for The Daily Beast . “If you believe the same people who think Naomi Wolf is making good sense about the vaccines are going to cough up the truth to a maître d’ before taking their seat at a restaurant, please see me about a hot new purchase opportunity for shares in a diamond mine.” Doctors and health experts are worried there may be COVID-19 case spikes in areas with low vaccine rates and higher case numbers Read More …

It’s time to take videos of Black Americans dying offline

Since 2013, when Black Lives Matter erupted on the scene to challenge the acquittal of Florida resident George Zimmerman for killing 17-year old Trayvon Martin, images of Black Americans dying on-screen have become as constant as air. In the last week, videos pertaining to at least four instances of police violence against Black Americans have circulated online. At the same time, a Minnesota jury found former police officer Derek Chauvin guilty for the murder of George Floyd. The video of Chauvin kneeling on Floyd’s neck while Floyd gasped for breath sparked a movement for police accountability that led to Chauvin’s conviction on all charges. But that video, which has continued to circulate, is also deeply traumatizing. Now Allissa V. Richardson, an author and journalism professor at the University of Southern California, is calling for more guardrails around publishing visual accounts of violence against Black people Read More …