GreatLakes
DIS Veteran
- Joined
- Aug 6, 2015
- Messages
- 5,524
I saw that post about the Fenix. I ran, walked, and biked with my 945 and it appears that I didn't lose any data at all. Considering how close the Fenix and 945 are I'm surprised they are so different with the activities.
Late last night I couldn't get into Connect but WiFi sync worked and it kicked off my linked services like Strava and SportTracks.
I agree with all of this. I was really just saying it is in the interest of the bad actor to decrypt your data if they pay, not that it is the best route.
Even with the restore they need to find out how they got infected so they don't just get their restored data encrypted again. I suspect that was the reason for the length of the outage. Now a day's restoration is pretty straight forward, the forensic investigation is not.
Late last night I couldn't get into Connect but WiFi sync worked and it kicked off my linked services like Strava and SportTracks.
That is true but with wastedlocker in paticular, the infiltrate your network first, find out what you have, then customize the malware for your environment and then often have your serves disable everybody's anti-virus/malware before running the ransomware. The ransom note even mentioned garmin by name. My point is even if you pay and even if you get the key, you still have compromised servers in this type of attack. This wasn't somebody downloaded something they shouldn't have.
So even if you pay you still have the issues of comprimised servers that have to be dealt with before you can bring everything back online which also makes restoring from backup harder too since you have to figure out how far back to go.
This was a professional russion cyberattack group that has already been sanctioned by the US government (which likely means garmin can't pay even if they wanted to). These guys know what they are doing.
I agree with all of this. I was really just saying it is in the interest of the bad actor to decrypt your data if they pay, not that it is the best route.
Even with the restore they need to find out how they got infected so they don't just get their restored data encrypted again. I suspect that was the reason for the length of the outage. Now a day's restoration is pretty straight forward, the forensic investigation is not.