Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

91–100 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#91
post #51

Should had paid for cybersecurity or not pay misery bug bounties. Attract talent to the blue team!

They had cyber insurance coverage[0]. But I have no idea if cyber insurance pays out ransomware ransoms.

[0]https://www.insidepandc.com/article/28is3dljuei18ioo7fri8/ax...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#92
I am definitely not an expert in these areas and I'm sure someone 100x smarter than I am has thought of this and discounted it already, but is there any ability to decompile the executable provided to Colonial and get to patterns of source code, then compel github to search their repositories for any patterns of that code? Not sure if that is even legal or whether a judge would authorize that fishing expedition, but it's an interesting thought exercise (in my head) assuming the code is even in GH.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#93

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

Indeed, not only should it be illegal, but the US Gov should offer any and all assistance for helping organizations get back online after such an attack. If organizations quit paying ransoms pretty soon the bad guys would give it up.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#94
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

Don't rely on technical details from Bloomberg.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#95
post #33

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

The federal government should commit to doing what it can to help make organizations who refuse to pay ransoms whole again.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#96
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

I’ve only helped people pay a couple of times but they always provided a shoddy .exe decryptor.

Consider that most victims are small fry who would not know what to do with just a key.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#97

I am definitely not an expert in these areas and I'm sure someone 100x smarter than I am has thought of this and discounted it already, but is there any ability to decompile the executable provided to Colonial and get to patterns of source code, then compel github to search their repositories for any patterns of that code? Not sure if that is even legal or whether a judge would authorize that fishing expedition, but…

> then compel github to search their repositories for any patterns of that code

Assuming we're talking private repos, compelling Github to do that is a pretty blatant fourth amendment violation unless there's a specific set of suspected repos.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#98
post #33

Earlier quoted context omitted.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone. If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off. The government can help coordination by making defecting more costly (with criminal penalties).

> The government can help coordination by making defecting more costly (with criminal penalties).

not just sticks, but also carrots: The federal government should commit to doing all it can to help organizations that refuse to pay ransoms. This would include help from 3-letter agencies as well as bringing in alternative IT infrastructure. Obviously the federal government doesn't have all of these capabilities now, but this should be a priority going forward.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#99
post #73

Earlier quoted context omitted.

So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t

That's a non sequitur. Certainly law enforcement should aggressively pursue criminals who engage in assault, burglary, and extortion. But that has nothing to do with paying off ransomware gangs.

Yes it does, it’s a crime, in this case a class of crime perpetrated, prosecuted, and prevented by experts. It falls under law enforcement

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#100

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

A greyhat should launch ransomware and then not decrypt when the ransom is paid. Make the ransomware industry unreliable.
Post reply on HN