Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

111–120 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#111
post #87

Earlier quoted context omitted.

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

What? No, the ransomware people truly do send a decryption tool, or the decryption functionality is built into the ransomware. Do you think they are sending people some AES key and then everyone goes off and builds some python tool to decrypt his data? This is a fundamental misunderstanding of the ransomware business. The whole reason people pay up is because the hackers don't run and leave you hanging; if you pay th…

[deleted]

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#112
post #87

Earlier quoted context omitted.

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

What? No, the ransomware people truly do send a decryption tool, or the decryption functionality is built into the ransomware. Do you think they are sending people some AES key and then everyone goes off and builds some python tool to decrypt his data? This is a fundamental misunderstanding of the ransomware business. The whole reason people pay up is because the hackers don't run and leave you hanging; if you pay th…

Great, we should get the word out then that some don't.

Perhaps a few cases of high-profile companies falsly claiming „wow, what a load of shit! we got ransommed and after paying up the hackers disappeared! we had to restore from backup, AND the money is gone“.

What are the hackers gonna do, sue those companies? :-)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#113
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

> I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool."

Fair, but anyone who pays me $5M and wants a powershell script gets one, and an air freshener of their choice.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#114

I am definitely not an expert in these areas and I'm sure someone 100x smarter than I am has thought of this and discounted it already, but is there any ability to decompile the executable provided to Colonial and get to patterns of source code, then compel github to search their repositories for any patterns of that code? Not sure if that is even legal or whether a judge would authorize that fishing expedition, but…

are you assuming the ransomware is collaboratively coded on github?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#115
post #87

Earlier quoted context omitted.

What? No, the ransomware people truly do send a decryption tool, or the decryption functionality is built into the ransomware. Do you think they are sending people some AES key and then everyone goes off and builds some python tool to decrypt his data? This is a fundamental misunderstanding of the ransomware business. The whole reason people pay up is because the hackers don't run and leave you hanging; if you pay th…

Great, we should get the word out then that some don't. Perhaps a few cases of high-profile companies falsly claiming „wow, what a load of shit! we got ransommed and after paying up the hackers disappeared! we had to restore from backup, AND the money is gone“. What are the hackers gonna do, sue those companies? :-)

Oh I don't know. Maybe the hackers will hold their operation hostage for ransom? Get the money and get some nice PR all at the same time!

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#116

Earlier quoted context omitted.

So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t

> So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? First, in many jurisdictions, paying protection money for physical security is illegal. Second, Colonial Pipeline has an operating revenue of $1.32 billion. I suppose in the USA it's technically a person, but... it's not actually a person. > We have law enforcement so everyone can be free to focus on th…

So, you are saying that there are jurisdictions where home security systems are illegal? Night watchmen/security guards and body guards are illegal? Where would these jurisdictions be located?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#117

Earlier quoted context omitted.

The federal government should commit to doing what it can to help make organizations who refuse to pay ransoms whole again.

Why should this be a problem that the federal government is required to solve? Or in other words: why should my tax dollars go to help an organization that couldn't manage their security properly?

Because this organization endangered the economy of a significant chunk of the country by their negligence, then your tax dollars should go to setting standards and holding them liable when they fail to meet those standards.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#118
post #25

Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…

Having read the release by the attacker, my initial thought is that the immediacy of paying was probably due to the threat of the release of sensitive data, not the ability to restore operations.

I’m sitting here wondering what exactly about the release of their financials and internal procedures prompted them to immediately pay $4-5m in the hopes of preventing it from happening?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#119
post #10

Every corporation in the US should be lobbying to abolish Bitcoin. It’s an existential threat that could be eliminated if they pooled their financial and political resources.

Isn't it better that these networks are getting hardened in exchange for a small cryptocurrency payment, instead of waiting for all the exploits to be used by an adversary in World War Three?

I’ve thought about this. No.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#120

Earlier quoted context omitted.

Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone. If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off. The government can help coordination by making defecting more costly (with criminal penalties).

> The government can help coordination by making defecting more costly (with criminal penalties). not just sticks, but also carrots: The federal government should commit to doing all it can to help organizations that refuse to pay ransoms. This would include help from 3-letter agencies as well as bringing in alternative IT infrastructure. Obviously the federal government doesn't have all of these capabilities now, bu…

Nobody in their right mind will consider a lot of attention by three letter agencies a reward or help. They may, and can, do a lot more damage than 0.4% of revenue, and can do a lot of damage to the individuals making the decisions as well.

Even if they help out, it will alert everyone and everything in 5 governments to all details about their firm.

Three letter agencies have used (and destroyed) companies for unrelated reasons and then left everyone without any recourse. With smaller companies, this happens regularly.

Those governments will have representatives from their lenders, from their investors, from their large clients and so on in them, who will get a lot of details they wouldn't normally get access to.

This is not happening.

Post reply on HN