Too many companies prefer to skimp on security since it has no apparent payoff until it's too late. What I want to know are the circumstances of the hack; how did it work, what systems did it affect, what security were they lacking. Sadly these details are often ignored or hidden from view. Attacks of this kind should get a public report so that other companies can learn or at least be shamed into changing. It seems…
We need something like a fire diamond for software and data: some tuple like ((fails to)conform to spec/testing(and production) only (ie contains PII or is garbage data)/(permissive,restrictive,free) license/(un)safe library calls or language) or so. Some stuff is pretty subjective but so are the fire diamond numbers sometimes, plus we can pick objective boundaries (calls to gets cannot be safe for example.) I think…
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
141–150 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#142It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
This is not a failure to live up to potential or incompetence, though there is a fair amount of both of those. We need solutions that are literally 100x better than the best systems currently available before we get to even adequate for critical infrastructure whose disruption can literally cause hundreds of millions or billions of dollars in damage let alone potential human lives. Anything less than that keeps extortion economically viable for the attackers and paying off extortion economically sound for the victims. That is how far away we are.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#143Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the company with shareholders abandoning it as the outage dragged on at the hands of an incompetent leadership.
Unfortunately it seems to have been a Pyrrhic victory as paying the ransom puts their shareholders at risk of serious sanctions and indictment from the US Dept. of the Treasury.
https://home.treasury.gov/system/files/126/ofac_ransomware_a...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#144Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
A greyhat should launch ransomware and then not decrypt when the ransom is paid. Make the ransomware industry unreliable.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#145Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#146I could think of several scenarios where they would want to shut down by making up the whole story. Or maybe even hired the hackers them selves.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#147Earlier quoted context omitted.
You have a point. They should do minimum due diligence to harden their networks. However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.
Well then, perhaps there should be minimum requirements to become CEO of a large corporation in regulated areas like pipelines? If the alternative is large harm to the public, this seems like a no-brainer to me for future legislation.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#148Earlier quoted context omitted.
Nobody in their right mind will consider a lot of attention by three letter agencies a reward or help. They may, and can, do a lot more damage than 0.4% of revenue, and can do a lot of damage to the individuals making the decisions as well. Even if they help out, it will alert everyone and everything in 5 governments to all details about their firm. Three letter agencies have used (and destroyed) companies for unrela…
It's the 3-letter agencies where the expertise lies. Maybe a new agency needs to be created outside of the intelligence agencies?
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#149Earlier quoted context omitted.
Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…
> No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. Uh, why? The system is already compromised. They’re already in.
One would hope they'd just run the decryption program on each computer, not connected to the network. Or maybe hire some experts to extract the decryption key.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#150Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security.
A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.