Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

131–140 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#131

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

This fees will support next 1000's attacks , if someone gets attacked next i think should sue colonial pipeline

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#132

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

I mean, let's address the elephant in the room: there is no such thing as computer security. As we see with new leaks and hacks and vulnerabilities every single week, the idea that a computer that is connected to the Internet can be secure is a joke. The whole industry is built on protocols and tools that assume there will never be any bad actors, and we're reaping the rewards of that now. It will take decades of lay…

There are companies that get hacked a lot and there are companies that don't. It is for sure true to say everyone is vulnerable, but it's also true to say that you can reduce your risk without reducing your revenue.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#133
post #100

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

A greyhat should launch ransomware and then not decrypt when the ransom is paid. Make the ransomware industry unreliable.

This is the chaotic evil way of dealing with the problem

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#134
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

> they cannot be that stupid

Oh yes they can.

Also, assume you have the key - what you do with it? You don't know how the files were encrypted, in which way they were stored afterwards, etc. There are many ways one can encrypt and write data, even with the same key - you obviously need the algorithm, but also there are often parameters (e.g. block sizes), storage formats etc. The easiest way to deliver all that is to provide a program.

Otherwise, what a random "press any key" IT person would do with an encryption key? They probably don't even have any tools that can do encryption on any of the systems. Do they have to write those themselves? Use OSS tools - which ones? With which parameters? What if it doesn't work?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#135

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…

Is being a "good" security person really more involved than:

* making sure you have all your ports locked down

* limit connectivity between all instances to only the bare minimum

* any public access is via protocols such as ssh which have zero-to-none vulnerabilities

* any 3rd party software you dont know is secure should never be public

* routinely run employee training on how not to let themselves get hacked via social engineering

I'm sure I'm missing other stuff, but I feel like if you follow these "best practices", you have just made yourself a very hard target and hackers will probably skip over you unless they have some weird reason to target your org specifically. So for 95% of companies out there, this level of security should be sufficient.

I'm legitimately asking - is this sufficient? Or are hackers so creative that even following these basic rules will still not make you a hard target?

This stuff seems fairly easy to do but I agree you need training or an info-sec person making sure your dev teams are doing it all. You can't have any slip ups. Your devs / managers have to take it seriously.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#136
post #24
post #21

Earlier quoted context omitted.

It's as direct any other revenue => business activity connection. More direct than how buying coffee causes fields to be planted with coffee trees. Of this $5M, expect $4M to be spent on salaries in the next year or 2, funding 20 person-years of malicious hacking. 20 skilled people paid to hurt the internet instead of building it up. A terrible crime.

Now we have one less critical piece of infrastructure that could be trivially knocked out by a hostile state.

They didn’t need security experts for that- all they had to do was not connect it to the Internet ...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#137
post #33

Earlier quoted context omitted.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone. If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off. The government can help coordination by making defecting more costly (with criminal penalties).

I think criminal penalties is too much. I think at some point paying ransom is better than not paying, for example, in case of attacks on hospitals. People can literally die.

What needs to happen is that when an organization that skips IT security practices, it should have large monetary penalties and its executives held responsible, no golden parachutes for them. You can imagine any factory where they don't practice OSHA safety guidelines will get in major trouble.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#138
post #33

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

Let's be clear that the victims here are the public and the perpetrators are the computer operators at the pipeline firm.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#139

Earlier quoted context omitted.

> So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? First, in many jurisdictions, paying protection money for physical security is illegal. Second, Colonial Pipeline has an operating revenue of $1.32 billion. I suppose in the USA it's technically a person, but... it's not actually a person. > We have law enforcement so everyone can be free to focus on th…

You have a point. They should do minimum due diligence to harden their networks. However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.

Well then, perhaps there should be minimum requirements to become CEO of a large corporation in regulated areas like pipelines? If the alternative is large harm to the public, this seems like a no-brainer to me for future legislation.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#140
Ugh. This ransomware crap doesn't stop until the money stops. At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-...). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can set this up in a totally plausibly deniable way - the employee just "accidentally" opens that attachment and off you go.

A lot of ransomware operators are on sanctions lists. Paying them is already illegal. The US DoJ might want to check if Colonial has violated any laws in making these payments - and if they have, punishing them to serve as an example could well discourage future ransomware payers. As long as ransomware operators know they can get paid for their work, they're going to keep doing it.

Post reply on HN