News: 1655967428

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

If you didn't store valuable data, ransomware would become impotent

(2022/06/23)


Column Sixteen years ago, British mathematician [1]Clive Humby came up with the aphorism "data is the new oil".

Rather than something that needed to be managed, Humby argued data could be prospected, mined, refined, productized, and on-sold – essentially the core activities of 21st century IT. Yet while data has become a source of endless bounty, its intrinsic value remains difficult to define.

That's a problem, because what cannot be valued cannot be insured. A decade ago, insurers started looking at offering policies to insure data against loss. But in the absence of any methodology for valuing that data, the idea quickly landed in the "too hard" basket.

[2]

Or, more accurately, landed on the to-do lists of IT departments who valued data by asking the business how long they could live without it. That calculus led to determining objectives for recovery point and recovery time, then paying what it took to build (and regularly test) backups that achieve those deadlines to restore access to data and the systems that wield it.

[3]

[4]

That strategy, while sound, did not anticipate ransomware.

Cyber criminals have learned how to exploit every available attack surface to make firms' hard-to-value-but-oh-so-vital data impossible to use. Ransomware [5]transforms data in situ into cryptographic noise – the equivalent of a kidnapper displaying their hostage, while laughing at the powerlessness of the authorities.

[6]

Businesses now face not just data loss but [7]data theft . The data is not only gone – it's been "liberated" by a threat actor who chooses to share exactly the parts of that data most damaging to your business, your customers, and your brand.

Do you still have a business? If so, how many lawsuits have been launched by clients who have themselves been damaged by your inability to keep private data private? Who will want to do business with you in the future? And can you ever again trust any of your systems – or your staff?

Sony [8]barely survived the reputational damage of the serious attack it endured in 2014 – and it's not clear that any other business would do significantly better in similar circumstances.

[9]Inverse Finance stung for $1.2 million via flash loan attack

[10]Bank for International Settlements calls for reform of data governance

[11]Atlassian comes clean on what data-deleting script behind outage actually did

[12]GitHub saved plaintext passwords of npm users in log files, post mortem reveals

Arguably the best strategy to avoid ruinous reparation costs is to avoid storing any sensitive data at all. Let your customers hold their own data, and ask them for (limited) permission to use it. Those techniques exist – but they're rarely used, because such an approach directly interferes with the profits to be made from endless data analytics. Short-term gains open the door to long-term losses.

We'll be caught on the horns of this dilemma until we learn – the hard way – how to collect, keep and use data without getting burned. ®

Get our [13]Tech Resources



[1] https://en.wikipedia.org/wiki/Clive_Humby

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrQ5xbBbJrMXR5nggQqphgAAAE0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrQ5xbBbJrMXR5nggQqphgAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrQ5xbBbJrMXR5nggQqphgAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/06/13/helloxd-ransomware-evolving/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrQ5xbBbJrMXR5nggQqphgAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/06/21/flagstar_bank_breached_ssn/

[8] https://www.theregister.com/2014/11/28/sony_staff_reduced_to_pencil_and_paper_as_computers_still_crippled_by_hackers/

[9] https://www.theregister.com/2022/06/17/inverse_finance_heist/

[10] https://www.theregister.com/2022/05/06/bis_data_governance_design/

[11] https://www.theregister.com/2022/04/14/atlassian_ongoing_outage/

[12] https://www.theregister.com/2022/05/27/github_publishes_a_post_mortem/

[13] https://whitepapers.theregister.com/



Doctor Syntax

If data is to be sold valuing it shouldn't present any problem at all. It's based on what customers* are prepared to pay for it. Ironically the data that's hard to value is that held by businesses who are more ethical and don't sell it on.

* That's the data customers, not the customers who are mere data subjects

Prst. V.Jeltz

Let your customers hold their own data, and ask them for (limited) permission to use it

who is this article aimed at exactly?

Me.

Josco

I think it was aimed at me, I found it interesting.

Anonymous Coward

I tend to agree. Felt like a bit of a non-article. Would have been better with some thoughts on a foward strategy rather then just tapering off..

So instead of...

2+2=5

So instead of holding all your customer's data centrally the idea is to store it de-centrally and somehow this protects from ransomeware attacks?

1) Ransomeware will evolve to encrypt the remotely held data.

2) The author assumes that the only valuable data a business has is its customer database. What about payroll, tax payments, bank information, product designs, supplier contacts and details etc.? There's plenty of data that a business needs to survive which is not linked to customers.

If Dr. Seuss Were a Technical Writer.....

Here's an easy game to play.
Here's an easy thing to say:

If a packet hits a pocket on a socket on a port,
And the bus is interrupted as a very last resort,
And the address of the memory makes your floppy disk abort,
Then the socket packet pocket has an error to report!

If your cursor finds a menu item followed by a dash,
And the double-clicking icon puts your window in the trash,
And your data is corrupted 'cause the index doesn't hash,
then your situation's hopeless, and your system's gonna crash!

You can't say this? What a shame, sir!
We'll find you another game, sir.

If the label on the cable on the table at your house,
Says the network is connected to the button on your mouse,
But your packets want to tunnel on another protocol,
That's repeatedly rejected by the printer down the hall,
And your screen is all distorted by the side effects of gauss,
So your icons in the window are as wavy as a souse,
Then you may as well reboot and go out with a bang,
'Cause as sure as I'm a poet, the sucker's gonna hang!

When the copy of your floppy's getting sloppy on the disk,
And the microcode instructions cause unnecessary risc,
Then you have to flash your memory and you'll want to ram your rom.
Quickly turn off the computer and be sure to tell your mom!

-- DementDJ@ccip.perkin-elmer.com (DementDJ) [rec.humor.funny]