Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

11–20 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#13

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

I feel the same way. It seems like the government wouldn't do it, but was practically encouraging the company to pay.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#14

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

Ransoms would still be paid. We just wouldn't know about it. I think it's better to allow companies to be transparent.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#15
post #8

Too many companies prefer to skimp on security since it has no apparent payoff until it's too late. What I want to know are the circumstances of the hack; how did it work, what systems did it affect, what security were they lacking. Sadly these details are often ignored or hidden from view. Attacks of this kind should get a public report so that other companies can learn or at least be shamed into changing. It seems…

We need something like a fire diamond for software and data:

some tuple like ((fails to)conform to spec/testing(and production) only (ie contains PII or is garbage data)/(permissive,restrictive,free) license/(un)safe library calls or language) or so.

Some stuff is pretty subjective but so are the fire diamond numbers sometimes, plus we can pick objective boundaries (calls to gets cannot be safe for example.) I think it could probably work.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#16

Every corporation in the US should be lobbying to abolish Bitcoin. It’s an existential threat that could be eliminated if they pooled their financial and political resources.

Bitcoin has nothing to do with this news? It seems like you have an unrelated axe to grind.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#17

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

Ransomware actors could easily punish such legislation. By continuing ransomware attacks they would place many companies in an impossible situation, either break the law by paying or face imminent collapse.

How many jobs are you willing to lose in order to stop ransomware attacks?

One ransomware attack probably costs the ransomware operation a few thousand dollars, any legislation would have to be extremely successful to result in a negative ROI.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#18

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

Ransoms would still be paid. We just wouldn't know about it. I think it's better to allow companies to be transparent.

The next group will want more than $5 million, and so on. If the lottery didnt allow advertising of big wins that were made, a lot less people would buy lottery tickets.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#19
post #7

So they paid a penetration-testing firm a consultancy fee to help harden their network.

Well, all we really know for sure is that they paid a penetration-testing firm a consultancy fee to identify where the network needs to be hardened. No guarantee they'll actually prioritize doing it.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#20

It's better to have criminals who are only interested in a relatively small payout exposing to the general public how vulnerable critical infrastructure is than people who are interested in causing mass destruction.

They should have just called it a bug bounty and then everyone would be happy.
Post reply on HN