Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

41–50 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#41
post #32

Earlier quoted context omitted.

How do you know that? What evidence is there that it's any more secure than it used to be?

These pirates have committed to not hitting the same target again?

And what about the others?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#43

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

The ransom payments are covered by insurance. It’s the insurance companies making the payments.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#44
post #32

Earlier quoted context omitted.

How do you know that? What evidence is there that it's any more secure than it used to be?

These pirates have committed to not hitting the same target again?

But they could have made holes in the system or not disclosed all system holes which other hackers might take advantage of in the future

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#45
post #40
post #23

Earlier quoted context omitted.

No, there's a hard upper limit on ransoms; the cost of recovery.

What about when the cost of having the data exposed to the public is higher than that of recovery

That requires you to have that kind of data. The company could have be operating legally and not have compromising stuff. The ransomware team gains nothing if a company refuses to pay and has everything to lose by hacking. If there price is to high they are taking on a lot of risk for no reason. Hacks are smart people (I find breaking the law to be a bad decision but if one does it knowing the consequences and mitigations then they aren't dumb just unethical)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#46
post #33

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#47
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

The ransomware typically has both the encrypter and decryptor built in.

It's a simple matter of copy-pasting the key into a box, and the decryption will happen.

Over a slow network link (like a VPN to a remote NAS), I could totally imagine it taking days/weeks/months to scan every file though...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#48
post #24
post #21

Earlier quoted context omitted.

It's as direct any other revenue => business activity connection. More direct than how buying coffee causes fields to be planted with coffee trees. Of this $5M, expect $4M to be spent on salaries in the next year or 2, funding 20 person-years of malicious hacking. 20 skilled people paid to hurt the internet instead of building it up. A terrible crime.

Now we have one less critical piece of infrastructure that could be trivially knocked out by a hostile state.

They are installing more software from the hacker voluntarily after paying the ransom. At this rate it looks more like they just hired a competent and highly unethical vendor..

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#49
post #32

Earlier quoted context omitted.

How do you know that? What evidence is there that it's any more secure than it used to be?

These pirates have committed to not hitting the same target again?

Ah yes, the code of the pirates. The epitome of ethics and morality.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#50
post #25

Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…

I am curious what your thoughts are on other commenters making as if it is possible to prevent these types of attacks by just taking security 'more seriously'. My guess is that you know that no matter how much is spent with a large entity and many employees it's near impossible to prevent this type of attack. People make mistakes people are easily fooled people don't follow what they are told to do and so on.

I can't even begin to imagine the amount of people that could cause an issue in the size company you are a CISO at.

Post reply on HN