Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

101–110 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#101

Earlier quoted context omitted.

So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t

> So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? First, in many jurisdictions, paying protection money for physical security is illegal. Second, Colonial Pipeline has an operating revenue of $1.32 billion. I suppose in the USA it's technically a person, but... it's not actually a person. > We have law enforcement so everyone can be free to focus on th…

You have a point. They should do minimum due diligence to harden their networks.

However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#102
post #83

In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…

>I don’t even know what the underlying problem is though...

Lack of accountability for either criminals or negligent operators?

Monsoons are not directly caused by individuals, and they cannot be prevented.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#103
post #89
post #74

Earlier quoted context omitted.

That's pretty easy to say when it's not e.g. your child being held for ransom.

I don't think people here are considering all forms of ransoms, but you hit on an interesting aspect of it all the same. It's why, I think, such a law wouldn't pass Constitutional review. If your person is threatened with imminent danger, you have a right to self-defense, we'll even let you commit intentional homicide if the threat is serious enough. And self-defense also covers your property and livelihood to a less…

The US Constitution contains no explicit right to self defense. There are a variety of state and federal laws covering justifiable use of force but none of them are even remotely applicable to paying ransoms. If you disagree then please cite a specific legal case.

https://www.natlawreview.com/article/us-government-warns-com...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#104
post #33

Earlier quoted context omitted.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

The federal government should commit to doing what it can to help make organizations who refuse to pay ransoms whole again.

Why should this be a problem that the federal government is required to solve? Or in other words: why should my tax dollars go to help an organization that couldn't manage their security properly?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#105
post #91
post #51

Should had paid for cybersecurity or not pay misery bug bounties. Attract talent to the blue team!

They had cyber insurance coverage[0]. But I have no idea if cyber insurance pays out ransomware ransoms. [0] https://www.insidepandc.com/article/28is3dljuei18ioo7fri8/ax...

They should, most policies do cover ransomware. If their policy did not, CIO loses their job in 5…4…

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#106
post #50
post #25

Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…

I am curious what your thoughts are on other commenters making as if it is possible to prevent these types of attacks by just taking security 'more seriously'. My guess is that you know that no matter how much is spent with a large entity and many employees it's near impossible to prevent this type of attack. People make mistakes people are easily fooled people don't follow what they are told to do and so on. I can't…

It's certainly possible to achieve serious security but probably not practical for most private entities. I've spent most of my development career making software for the US intelligence community and their systems were definitely not going to get broken into by a ransomware gang. Security measures include multilevel air gapping plus heavily armed physical security, six foot thick concrete walls set back from the street by other concrete barriers, locating facilities on military installations, disabling USB ports on most devices, banning anything radio enabled from being anywhere near your workstations, jamming radio signals anyway, severely punishing, possibly executing, anyone caught working as an intentional insider threat, requiring multiple persons in the custody and approval chains to move any files from one network to another via write-once media like DVDs, having the transfer media itself in a separate locked cabinet in a separate locked room inside the actual classified vault serving as an office. Installing and running everything in a separately sandboxed staging environment even after it gets through all the walls and air gaps and DVDs and running it through some fairly extensive testing and analysis before putting it anywhere near a production system.

Clearly, you can never make it literally impossible, but to my knowledge, nobody has ever managed to get malicious software onto a classified production system. Information leaks are, of course, another story.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#107

All that money and lawlessness that went into enabling security agencies must be crowned as the worst investment ever

That has nothing to do with this the FBI presumably cannot enforce security on a company. Maybe for some industries they need to start mandating Security Clearances and background checks and no outsourcing of certain critical systems work.

I am not familiar with any details of this hack that could point to employees or contractors. Also, I am not sure what exactly are the roles of FBI and NSA when it comes to protecting US infrastructure, can you clarify?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#108

Earlier quoted context omitted.

How do you know that? What evidence is there that it's any more secure than it used to be?

The 5M ransom plus all the other damage such as reputation loss, increased government scrutiny and potential damages to pay to partners (I'm sure they provide some sort of SLA for their oil delivery services?) is a good enough deterrent from allowing this to happen again.

5M is nothing to that pipeline management firm. I think nothing will change because the "fine" is tiny and later, when a VP of opsec gets to decide between a massively expensive hardening of security which includes big recurring costs to keep an opsec team on payroll and just pocketing a multimillion dollar bonus for optimizing the opsec budget, he will choose the latter. There's no risk of getting jail time and any reputation damage won't be to his personal reputation, but to that firm he will have left long ago.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#109
post #33

Earlier quoted context omitted.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

The federal government should commit to doing what it can to help make organizations who refuse to pay ransoms whole again.

That role can be better handled by private insurers in the same way they make policy holders whole after physical thefts.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#110
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

> No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid.

Uh, why? The system is already compromised. They’re already in.

Post reply on HN