Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

71–80 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#72
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

> If some kind of software was provided by the attackers, and Colonial installed it, this could be far from over.

To be fair, malicious code has already ran on the affected machines, so if the ransomware authors wanted to do further damage they wouldn't need a malicious decryptor to do that.

So you'd either:

1) not trust the ransomware authors, rebuild everything from scratch (potentially paying the ransom and reverse-engineering the decryptor or running it isolated from the internet) and make sure to not carry over any executable code that could allow potential malware to persist

2) trust the ransomware authors and not rebuild everything, in which case you may as well run their decryptor

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#73
post #46

Earlier quoted context omitted.

That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.

So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t

That's a non sequitur. Certainly law enforcement should aggressively pursue criminals who engage in assault, burglary, and extortion. But that has nothing to do with paying off ransomware gangs.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#74
post #46
post #33

Earlier quoted context omitted.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.

That's pretty easy to say when it's not e.g. your child being held for ransom.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#75
post #33

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone.

If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off.

The government can help coordination by making defecting more costly (with criminal penalties).

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#76

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

For many companies, security threats are all theoretical, but they are required to have the positions to meet some compliance requirement. They need to have them, but don’t really want them, which would explain the lack of enthusiasm (as demonstrated by the low salaries) in getting the jobs actually filled.

Also, a lot of infosec positions are just chugging through audits and ticking boxes to say whether you have some control in place or not. Those are more clerical positions that don’t require deep technical knowledge that could command a higher salary.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#77
post #24

Earlier quoted context omitted.

Now we have one less critical piece of infrastructure that could be trivially knocked out by a hostile state.

How do you know that? What evidence is there that it's any more secure than it used to be?

The 5M ransom plus all the other damage such as reputation loss, increased government scrutiny and potential damages to pay to partners (I'm sure they provide some sort of SLA for their oil delivery services?) is a good enough deterrent from allowing this to happen again.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#78

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up, and they still get hacked routinely, I can’t imagine how low quality the applicant pool is at Colonial, and doubt it would have made a difference. Almost every company of moderate size perpetually has openings for security roles.

The other problem is that the industry has an oversupply of by-the-book certified security people who can configure firewalls and run scanners, but who have never dealt with live hackers or hacked anything themselves. But hackers are clever and artistic, and defending against them isn’t like following a recipe for baking a cake.

And as an employer looking to introduce security, there is no way to really evaluate a good security leader vs a charlatan, and then it’s either bad hires all the way down, or talented people on the bottom who lack leadership and are ineffective in the bureaucracy.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#79
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

> More charitable reading is that the encryption key was sent over, and they started restoring with that but using standard OSS tooling.

That would make a lot more sense but I also bet there's a non-zero chance that in a day some dumb media outlet will conflate those tools as "hacker tools" and the headline will be "Hacker tools used in Colonial pipeline hack available freely on Internet. News at 10."

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#80

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

From my experience, the problem is that most infosec positions are powerless to do anything to increase security at the company, and are primarily there for PR or compliance reasons. The positions seem to be mostly filled with people who wanted to make a career change for the money; experienced people usually leave to work at private security companies, or FAANG sized companies.
Post reply on HN