Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

121–130 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#121
post #32

Earlier quoted context omitted.

These pirates have committed to not hitting the same target again?

Ah yes, the code of the pirates. The epitome of ethics and morality.

I dont think it's a code. It's more of a guideline.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#122
post #117

Earlier quoted context omitted.

Why should this be a problem that the federal government is required to solve? Or in other words: why should my tax dollars go to help an organization that couldn't manage their security properly?

Because this organization endangered the economy of a significant chunk of the country by their negligence, then your tax dollars should go to setting standards and holding them liable when they fail to meet those standards.

That's not what the OP said though. That is something completely different.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#123

Earlier quoted context omitted.

> The government can help coordination by making defecting more costly (with criminal penalties). not just sticks, but also carrots: The federal government should commit to doing all it can to help organizations that refuse to pay ransoms. This would include help from 3-letter agencies as well as bringing in alternative IT infrastructure. Obviously the federal government doesn't have all of these capabilities now, bu…

Nobody in their right mind will consider a lot of attention by three letter agencies a reward or help. They may, and can, do a lot more damage than 0.4% of revenue, and can do a lot of damage to the individuals making the decisions as well. Even if they help out, it will alert everyone and everything in 5 governments to all details about their firm. Three letter agencies have used (and destroyed) companies for unrela…

It's the 3-letter agencies where the expertise lies. Maybe a new agency needs to be created outside of the intelligence agencies?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#124

Earlier quoted context omitted.

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

> More charitable reading is that the encryption key was sent over, and they started restoring with that but using standard OSS tooling. That would make a lot more sense but I also bet there's a non-zero chance that in a day some dumb media outlet will conflate those tools as "hacker tools" and the headline will be "Hacker tools used in Colonial pipeline hack available freely on Internet. News at 10."

These inane arguments didn't kill GTA, or virtually anything else. How are they going to kill OSS that hasn't needed mainstream appeal and still doesn't? So, maybe some high school kids end up on the github pages and become 1337 hackers? Quite a stretch..

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#125
post #83

In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…

Suppose that everyone has raised their house up on a pile of dirt. The rain comes down. It fills up the large ditches between people's houses, and leaves the houses dry.

Suppose I implement better, but imperfect, security. It now costs an attacker $6 million, in salaries, paying for exploits, whatever, to hack my system. They still can only get $5 million in ransom. The attack isn't worth doing anymore, so they find a different business.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#126

All that money and lawlessness that went into enabling security agencies must be crowned as the worst investment ever

That has nothing to do with this the FBI presumably cannot enforce security on a company. Maybe for some industries they need to start mandating Security Clearances and background checks and no outsourcing of certain critical systems work.

I believe a judge recently signed an order allowing the FBI to access and patch hacked exchange servers.

https://www.nbcnews.com/tech/security/fbi-might-gone-ahead-f...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#127
post #46
post #33

Earlier quoted context omitted.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.

This would only protect those without proper cyber security. Why is it acceptable to let random targets suffer as opposed to everyone without proper security?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#128
post #32

Earlier quoted context omitted.

How do you know that? What evidence is there that it's any more secure than it used to be?

These pirates have committed to not hitting the same target again?

Can you name some examples of orgs getting hit twice?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#129
Recent and related:

AAA warns on gas prices, North Carolina invokes emergency as hackers apologize - https://news.ycombinator.com/item?id=27117515 - May 2021 (111 comments)

US passes emergency waiver over fuel pipeline cyber-attack - https://news.ycombinator.com/item?id=27101092 - May 2021 (448 comments)

U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack - https://news.ycombinator.com/item?id=27086403 - May 2021 (202 comments)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#130

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

I mean, let's address the elephant in the room: there is no such thing as computer security. As we see with new leaks and hacks and vulnerabilities every single week, the idea that a computer that is connected to the Internet can be secure is a joke. The whole industry is built on protocols and tools that assume there will never be any bad actors, and we're reaping the rewards of that now. It will take decades of layering on band-aids to approach anything like security, and more likely we will have to rebuild the entire industry from the ground up without that assumption. Both will take a very long time and a lot of money. Hiring some guy with an infosec cert would not have stopped this attack, because there is no way to stop this kind of attack.
Post reply on HN