It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
61–70 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#62Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#63Every corporation in the US should be lobbying to abolish Bitcoin. It’s an existential threat that could be eliminated if they pooled their financial and political resources.
Being legal means that you can run big mining operations, so you could clamp down on those and slow mining. That would not stop it, though.
Being legal means that it can be used to trade goods and services, and you could clamp down on that and harm its value as a currency.
And being legal means that legal businesses can exchange it for other currencies, so clamping down on that harms its liquidity.
Even if you can make it broadly illegal across the globe, it's hard to see how effective that would be. Illegality has made anything else on the black market go away, after all, and the whole point of a crypto-currency is to thrive despite government suppression.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#64Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
The ransom payments are covered by insurance. It’s the insurance companies making the payments.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#65All that money and lawlessness that went into enabling security agencies must be crowned as the worst investment ever
Maybe for some industries they need to start mandating Security Clearances and background checks and no outsourcing of certain critical systems work.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#66It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
Being hit by ransomware is not an indicator of total IT incompetence.
Having no good options but to pay the ransom absolutely is.
All ransomware is doing is exposing the existing hope-based DR plans (that is to say, lack thereof) in the industry.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#67Every corporation in the US should be lobbying to abolish Bitcoin. It’s an existential threat that could be eliminated if they pooled their financial and political resources.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#68Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
If a have a firm that makes $100,000,000 a year in net-profit , paying a $5 ransomware is a cost of doing business, an unfortunate one nonetheless
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#69It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#70Earlier quoted context omitted.
That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.
So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t
First, in many jurisdictions, paying protection money for physical security is illegal.
Second, Colonial Pipeline has an operating revenue of $1.32 billion. I suppose in the USA it's technically a person, but... it's not actually a person.
> We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t
I submit that oil pipeline operators, hospitals, and large corps are part of that 1%.