I’m starting to feel very sorry for the employees caught up in this, they must be under massive pressure and stress.
If this happened in my place of work we’d be taking sleeping bags in with us.
I’m starting to feel very sorry for the employees caught up in this, they must be under massive pressure and stress.
If this happened in my place of work we’d be taking sleeping bags in with us.
If its wastedlocker, that is unlikely as it only appears to encrypt data rather than mine it.
That might well be true, but they may have no idea how long the attackers were inside the network. In a lot of cases they won’t start encrypting until they have taken what they want. In a lot of attacks nowadays they will have taken the data, prove to Garmin they have it and say pay up or we will release it.
A different attack, but in this case the gang were happy to turn down $780,000. Nice work if you can get it.
How hackers extorted $1.14m from University of California, San Francisco
I work for a security company and help our customer install and run our product properly. It is scary how many don’t even login to see what is going on inside there network. Alerts are ignored from month previously and then the attack is dropped. The gang has been inside for months.
Nothing wrong with being a Data Proction nerd
. More companies need them! If they have lost data these fines will not be pretty. I doubt they will be kind to them like they have been to others in the past.
Exactly, the encryption is them locking the door as they leave, fridge already emptied…
This is the sort of thing that must keep @Nate_Pearson up at night. If it can happen to Garmin it can happen to anyone, and to be honest, the size of brand is not important when it comes to security.
Once your servers are in the cloud you have to hope the cloud service provider is doing there job. It is no longer about how good you run your systems, the provider has to do their part as well.
You’re working too hard if your goal is to steal bikes. Just break into a bike shop
. They aren’t banks with high security.
Yes but I’m not worried about the bike shops bikes, just mine … but your right, bike theft from private property isn’t a thing
And imagine if/when it happens to Strava. The world will literally explode.
I’m sure this has been asked 10 times but I can’t find it, without Garmin Connect can I put my Strava course on my 530 so it will give me turn by turn instructions
Export GPX from Strava and save as file. Copy manually to Garmin.
I never realized my dependence on Garmin/Strava. How did anyone verify their existence before fitness tracking aps?
I think you’re missing the point.
Of course Trainerroad has the great outdoor ride feature that requires 3rd parties to work. This is another nightmare for companies. Features can break and the fix is out of their hands.
But can you export to Garmin without connect?
Why do you assume that companies that run their servers on-prem are more secure than companies that utilize cloud infrastructure? There are lots and lots of instances where companies running on-prem infrastructure have been hacked. From a pure volume perspective, I would bet (and no, I don’t have actual statistics
) that more on-prem companies have been hacked than companies that utilize cloud infrastructure. Not because cloud infrastructure is inherently more secure (or less secure), but simple because there are more companies with on-prem infrastructure.
At the end of the day, the security of your infrastructure comes down to investment in people, processes, and systems (e.g., intrusion detection, firewalls, etc.). Companies that invest in an holistic security program are more secure, than companies that rely on a wing and a prayer (too many). Good security isn’t easy, but it isn’t rocket science either.
I hope that Garmin does get hit with a rather sizable fine, as that will probably (hopefully) convince management / board of directors to invest in a good data security program. Plus hopefully this will convince other players in the fitness space that they also need to invest in a data security program.
Just posted on the Garmin Facebook page:
That is not how it was meant to come across. I certainly don’t think the cloud is more secure. I was trying to say companies put infrastructure in the cloud and think they don’t have to work so hard to keep it secure because the provider will. S3 bucket miss configurations that has led to data leaks prove that you still have to work hard to keep it secure. Security is not easy!