Episode 42 · 2020-10-26 · 36:24 · Original in Finnish
White hats and the Vastaamo extortion | Juho Ranta | Negotiator 42
Originally published as “2NS-Valkohatut ja Vastaamon kiristys | Juho Ranta | Neuvottelija 42”
Second Nature Security CTO Juho Ranta unpacks the Vastaamo data breach and extortion while it was still unfolding: what white hat and black hat actually mean, why Tor and bitcoin are double-edged in the same way, and why you should neither pay the extortionist nor read the leaked files. The episode also covers common misunderstandings about GDPR, password practice and two-factor authentication, the three identifiers of which only two can be changed, and why security has to be run on the business's terms rather than by staring at a single system.
Core theses
- The Vastaamo case is unique in Finland not for the technique but for the sensitivity of the data and its direct reach into ordinary citizens' lives — every party, company and patients alike, is the victim of a crime.
- White hat and black hat use identical tools; what separates them is a client engagement and responsible disclosure rather than sitting on, selling or exploiting the findings.
- Tor and bitcoin are double-edged in the same way: both protect dissidents and criminals, and bitcoin's defining property is decentralisation rather than anonymity, since converting coins to euros leaves a trace.
- A secret must be replaceable. Passwords and credit cards can be reissued; a Finnish national identity number cannot, which is why its exposure is the lasting harm and why reform is important but slow and expensive.
- Security has to be managed with the business rather than as a technical silo, because the risks are business risks and the consequences land in revenue and profit.
Watch and listen
Key moments
- 00:00 — A case unique in Finnish scale
- 02:31 — The Twitter hack and what phishing means
- 05:06 — White hats and black hats
- 07:36 — Tor and the two sides of anonymity
- 10:10 — Bitcoin and operational security
- 12:44 — GDPR: legitimate interest and misunderstandings
- 15:26 — Security as a whole, not a single system
- 17:58 — Passwords and two-factor authentication
- 20:41 — Three identifiers: email, phone and identity number
- 23:12 — Can a Finnish identity number be renewed?
- 25:42 — Strong authentication, Estonia and deepfakes
- 28:16 — For companies: the business owns the risk
- 30:53 — Notification duties and contradictory instructions
- 33:28 — Do not pay, and do not read the leaks
- 36:00 — Crisis as an opportunity to improve
Summary
Second Nature Security CTO Juho Ranta unpacks the Vastaamo data breach and extortion while it was still unfolding: what white hat and black hat actually mean, why Tor and bitcoin are double-edged in the same way, and why you should neither pay the extortionist nor read the leaked files. The episode also covers common misunderstandings about GDPR, password practice and two-factor authentication, the three identifiers of which only two can be changed, and why security has to be run on the business’s terms rather than by staring at a single system.
What is discussed
- Why this case is different. Ransomware and ransom demands have appeared in Finland before; what is unprecedented is the sensitivity of the data and how directly it reaches ordinary people. Both men stress the company and its customers are all victims of a crime.
- Phishing, explained. The victim is tricked into surrendering credentials by mail impersonating a delivery firm, the police or the postal service — as in the summer 2020 Twitter breach, where a 17-year-old obtained admin access and ran a bitcoin scam through Musk’s and Obama’s accounts.
- White hat versus black hat. Identical tools and methods; the difference is a client engagement and responsible disclosure. Ranta concedes the line blurs for state intelligence services on both sides.
- Tor. Born from a US Navy-supported anonymisation project; the onion structure hides source and destination, which serves dissidents in dictatorships and criminals equally.
- Bitcoin and OPSEC. Anonymity depends on how it is used; converting to euros leaves the trace. The Twitter teenager failed at this, the Vastaamo extortionist used a separate wallet per target. Volatility and settlement time rule bitcoin out as an everyday currency.
- GDPR is misunderstood. Recruitment creates a legitimate interest, so an applicant cannot demand deletion mid-process. The aim was to bring member states onto one line — Finland’s old act already required much of it — and the EU–US transfer arrangements collapse and restart every few years.
- Security is a whole. A clinic leaving a patient record system open in an empty room is the same category of failure as a database flaw. Focusing on one system leaves large gaps unseen.
- The business owns the risk. Security management is done with the business, which makes conscious decisions about which risks to accept, because it is the business that takes the hit in revenue and profit.
- Three identifiers, two replaceable. Email, phone number and identity number are all exposed for victims. A secret must be replaceable — and Finland’s identity number is not, which is why identity theft risk persists and reform, though important, is a multi-year and expensive project.
- Do not pay, do not read. Payment guarantees nothing and invites a second demand; reading the leaked files is itself a crime and strengthens the extortionist’s leverage. The closing analogy is aviation, where learning from accidents produced exceptional safety.
Watch
The recording lives on the Neuvottelija channel: 2NS-Valkohatut ja Vastaamon kiristys | Juho Ranta | Neuvottelija 42. A Finnish edition of this episode is published at www.neuvottelija.fi.
People and topics
Guests: Juho Ranta