19
Corporate Hacking Has Hacking Finally Made it to the Boardroom? F-Secure / Erka Koivunen @ekoivune https://business.f-secure.com/ Software ???? Profit!!

Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

  • Upload
    others

  • View
    6

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

Corporate Hacking

Has Hacking Finally Made it to the Boardroom?

F-Secure / Erka Koivunen@ekoivune

https://business.f-secure.com/

Software ???? Profit!!

Page 2: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 3: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 4: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 5: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

"

Photo: Wired

Page 6: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 7: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 8: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

Photo: The Telegraph

Page 9: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 10: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 11: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 12: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

Cases of Ethically-Challenged Corporate Hacking

• Sony BMG rootkit 2005• Lenovo 2014 – 2015

– Superfish et al.

• Ashley Madison– Female bots– $19 deletion fee

• Volkswagen– emissions test rigging

Page 13: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

Cases of Ethically-Challenged Corporate Hacking

• Sony BMG rootkit 2005• Lenovo 2014 – 2015

– Superfish et al.

• Ashley Madison– Female bots– $19 deletion fee

• Volkswagen– emissions test rigging

Turn your Product intoSoftware

Profit!!

Hack Away

(Just don’t get caught)

Page 14: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de
Page 15: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

PROMOTE VULNERABILITY RESEARCH

Proposed Solution #1: Encourage Third Parties to Find Deficiencies

Page 16: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

SOFTWARE LIABILITY?Proposed Solution #2: Address the Externality of Risks

Page 17: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

MANDATORY REPORTING?Proposed Solution #3: Force Threats and Incidents more Visible

Page 18: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de

• Software is everywhere

• Software is capable of everything

• Software will be used for everything

Strong incentives to engage in unethical business practices

Need to ensure that cheaters will be exposed

Page 19: Corporate Hacking Has Hacking Finally Made it to the ... · Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de la Ciberseguridad tsmS "FOt0CEC gcutersecunru . Fora de