Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

141–150 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#141
post #15
post #8

Too many companies prefer to skimp on security since it has no apparent payoff until it's too late. What I want to know are the circumstances of the hack; how did it work, what systems did it affect, what security were they lacking. Sadly these details are often ignored or hidden from view. Attacks of this kind should get a public report so that other companies can learn or at least be shamed into changing. It seems…

We need something like a fire diamond for software and data: some tuple like ((fails to)conform to spec/testing(and production) only (ie contains PII or is garbage data)/(permissive,restrictive,free) license/(un)safe library calls or language) or so. Some stuff is pretty subjective but so are the fire diamond numbers sometimes, plus we can pick objective boundaries (calls to gets cannot be safe for example.) I think…

[deleted]

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#142

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

No. The security problem is not a lack of effort or laxness, it is a fundamental inability to solve the problem. At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. The absolute best of the best commercial IT systems implemented as envisioned with full support can maybe protect up to the $10M level and I am just extrapolating upwards since I have never had any security professional or executive in a Fortune 500 company with a budget in the tens to hundreds of millions of dollars ever assess their own systems as more than $1M. With an ROI of 5 is it only a matter of time before criminal enterprises can bootstrap themselves up to exploit the entire total addressable market. At best, better, but still inadequate, security means that the thousands of hungry bears eat the slower fish in the barrel first to get the energy to reproduce and make more bears to eat the rest.

This is not a failure to live up to potential or incompetence, though there is a fair amount of both of those. We need solutions that are literally 100x better than the best systems currently available before we get to even adequate for critical infrastructure whose disruption can literally cause hundreds of millions or billions of dollars in damage let alone potential human lives. Anything less than that keeps extortion economically viable for the attackers and paying off extortion economically sound for the victims. That is how far away we are.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#143
Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes.

Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the company with shareholders abandoning it as the outage dragged on at the hands of an incompetent leadership.

Unfortunately it seems to have been a Pyrrhic victory as paying the ransom puts their shareholders at risk of serious sanctions and indictment from the US Dept. of the Treasury.

https://home.treasury.gov/system/files/126/ofac_ransomware_a...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#144
post #100

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

A greyhat should launch ransomware and then not decrypt when the ransom is paid. Make the ransomware industry unreliable.

I think a lot of businesses would still pay. Pay $2M for a 50% chance of getting out of the situation, versus $200M in losses if you don’t - you’d take the gamble.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#145

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#147
post #139

Earlier quoted context omitted.

You have a point. They should do minimum due diligence to harden their networks. However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.

Well then, perhaps there should be minimum requirements to become CEO of a large corporation in regulated areas like pipelines? If the alternative is large harm to the public, this seems like a no-brainer to me for future legislation.

It’s probably cleaner and easier to run this if the spooks set up a bureau of cyber security standards and fine strategically important companies for non-compliance. The gov can do security audits on these corps.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#148

Earlier quoted context omitted.

Nobody in their right mind will consider a lot of attention by three letter agencies a reward or help. They may, and can, do a lot more damage than 0.4% of revenue, and can do a lot of damage to the individuals making the decisions as well. Even if they help out, it will alert everyone and everything in 5 governments to all details about their firm. Three letter agencies have used (and destroyed) companies for unrela…

It's the 3-letter agencies where the expertise lies. Maybe a new agency needs to be created outside of the intelligence agencies?

Yet another one :-)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#149

Earlier quoted context omitted.

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

> No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. Uh, why? The system is already compromised. They’re already in.

Well if the company is already that messed up to not have backups and desperate that they paid criminals...

One would hope they'd just run the decryption program on each computer, not connected to the network. Or maybe hire some experts to extract the decryption key.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#150

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

I think ransomware is the best thing that happened in computer security in a long time.

All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security.

A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

Post reply on HN