Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

81–90 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#81
post #40
post #23

Earlier quoted context omitted.

No, there's a hard upper limit on ransoms; the cost of recovery.

What about when the cost of having the data exposed to the public is higher than that of recovery

Yeah, I was pushing that all under "recovery." Say it all sums to $C.

Arguably the bigger problem is you don't know that the ransomer will actually give you a valid key, but suppose you guess a likelihood P that they do.

Now you have some scenarios:

1. Don't pay. We're out $C.

2. Do pay, and get a valid key. We're out $R.

3. Do pay, and get no key. We're out $R + $C.

So the limit is at scenario 1 being equal to the combination of 2 and 3.

Set C = PR + (1-P)(R + C), and your max ransom R = CP

(You could probably work in additional costs for cleaning up even if the ransom is paid.)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#82
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

I don’t think the hacking group would want to show future targets that paying the ransom won’t get them un-hacked. People would stop paying them. It would be bad for business.

If anything they’re working on speeding up their decrypting tool for the next release :)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#83
In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood.

It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely target.

I don’t even know what the underlying problem is though...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#84

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

Are there enough Infosec people to fill every open job for it in the USA? I would imagine that it is like software development, where the unemployed software devs are the kind that can't figure out git.

This is basically accurate but with an added problem. When devs do their job, the product is software. When security does their job, the product is “not getting hacked”, so if you act busy enough, it’s easy to appear as though you’re doing important work, until it’s too late.

Then, paradoxically, you aren’t actually punished, but usually rewarded, when you do get hacked. That’s the one time you’re needed most, and you get to act like the hero for saving the company.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#85

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

It should be illegal on another basis as well. Paying it contributes to a norm that randoms will be paid that will encourage more randomware in the future against other companies. So you're harming other people when you pay it. That's an externality that won't be factored into the decision to pay the ransom.

Suppose god handed down powers that allowed you to smite from the earth anyone who ever paid a ransom with perfect accuracy and you made a credible commitment to do so. If this fact was well known, presumably random-paying would disappear overnight and ransomware attacks would soon cease to exist as well (ironically rendering the power to smite ransom-payers redundant). We won't ever live in that world but we can move marginally toward it by severaly penalizing clear cut cases where a company or individual pays a ransom.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#86

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…

The problem I see is that there are tradeoffs between security and usability, and again between developing security vs developing features. Security doesn't make money next quarter, while features and ease of use do.

Any software engineer can do security if they spend time learning and working on it. But executives don't seem to care about it.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#87
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

What? No, the ransomware people truly do send a decryption tool, or the decryption functionality is built into the ransomware. Do you think they are sending people some AES key and then everyone goes off and builds some python tool to decrypt his data?

This is a fundamental misunderstanding of the ransomware business. The whole reason people pay up is because the hackers don't run and leave you hanging; if you pay they will decrypt your data. Trust and convenience are essential to making this work.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#88
post #83

In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…

What a great story reminds me of this: https://slatestarcodex.com/2017/02/22/repost-the-non-liberta...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#89
post #74
post #46

Earlier quoted context omitted.

That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.

That's pretty easy to say when it's not e.g. your child being held for ransom.

I don't think people here are considering all forms of ransoms, but you hit on an interesting aspect of it all the same.

It's why, I think, such a law wouldn't pass Constitutional review.

If your person is threatened with imminent danger, you have a right to self-defense, we'll even let you commit intentional homicide if the threat is serious enough.

And self-defense also covers your property and livelihood to a lesser extent.

I think it'd be extremely hard to convince courts that this right to self-defense doesn't include negotiating with an attacker. Imagine if it were a crime to toss some money at a mugger and run away, for instance.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#90
post #10

Every corporation in the US should be lobbying to abolish Bitcoin. It’s an existential threat that could be eliminated if they pooled their financial and political resources.

Isn't it better that these networks are getting hardened in exchange for a small cryptocurrency payment, instead of waiting for all the exploits to be used by an adversary in World War Three?

idk, considering humans are the weakest link and socially engineering them is easy, I don't think they're going to end up much safer. A determined nation state will always be able to get in, at least with how computers currently work.
Post reply on HN