Earlier quoted context omitted.
These pirates have committed to not hitting the same target again?
Ah yes, the code of the pirates. The epitome of ethics and morality.
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
121–130 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#122Earlier quoted context omitted.
Why should this be a problem that the federal government is required to solve? Or in other words: why should my tax dollars go to help an organization that couldn't manage their security properly?
Because this organization endangered the economy of a significant chunk of the country by their negligence, then your tax dollars should go to setting standards and holding them liable when they fail to meet those standards.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#123Earlier quoted context omitted.
> The government can help coordination by making defecting more costly (with criminal penalties). not just sticks, but also carrots: The federal government should commit to doing all it can to help organizations that refuse to pay ransoms. This would include help from 3-letter agencies as well as bringing in alternative IT infrastructure. Obviously the federal government doesn't have all of these capabilities now, bu…
Nobody in their right mind will consider a lot of attention by three letter agencies a reward or help. They may, and can, do a lot more damage than 0.4% of revenue, and can do a lot of damage to the individuals making the decisions as well. Even if they help out, it will alert everyone and everything in 5 governments to all details about their firm. Three letter agencies have used (and destroyed) companies for unrela…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#124Earlier quoted context omitted.
Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…
> More charitable reading is that the encryption key was sent over, and they started restoring with that but using standard OSS tooling. That would make a lot more sense but I also bet there's a non-zero chance that in a day some dumb media outlet will conflate those tools as "hacker tools" and the headline will be "Hacker tools used in Colonial pipeline hack available freely on Internet. News at 10."
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#125In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…
Suppose I implement better, but imperfect, security. It now costs an attacker $6 million, in salaries, paying for exploits, whatever, to hack my system. They still can only get $5 million in ransom. The attack isn't worth doing anymore, so they find a different business.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#126All that money and lawlessness that went into enabling security agencies must be crowned as the worst investment ever
That has nothing to do with this the FBI presumably cannot enforce security on a company. Maybe for some industries they need to start mandating Security Clearances and background checks and no outsourcing of certain critical systems work.
https://www.nbcnews.com/tech/security/fbi-might-gone-ahead-f...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#127Earlier quoted context omitted.
I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.
That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#128Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#129AAA warns on gas prices, North Carolina invokes emergency as hackers apologize - https://news.ycombinator.com/item?id=27117515 - May 2021 (111 comments)
US passes emergency waiver over fuel pipeline cyber-attack - https://news.ycombinator.com/item?id=27101092 - May 2021 (448 comments)
U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack - https://news.ycombinator.com/item?id=27086403 - May 2021 (202 comments)
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#130It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…