Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

151–160 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#151

Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…

You'd damn well hope so. In civilized countries, when you leave the key in the ignition the cops will go after the thieves. The next thing that'll happen is that they'll also go after you because you just made the roads unsafe.

And this isn't a car, this is infrastructure with national security implications. Someone needs to go and do time.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#152

Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…

If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods.

This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry.

If you're found vulnerable, that's a fine. If something gets accidentally broken in the exercise, that's the price of commitment.

Nothing is going to change until you increase the frequency / likelihood of breaches for these companies. If it's a yearly cost, it gets addressed. If it's a catastrophic possibility, it gets ignored.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#153
post #121

Earlier quoted context omitted.

Ah yes, the code of the pirates. The epitome of ethics and morality.

I dont think it's a code. It's more of a guideline.

I’m sure at some point they must have just asked if they’d give them the password for free on account of all the collateral damage.. but it looks like they were disinclined to acquiesce to the request.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#155
post #117

Earlier quoted context omitted.

Why should this be a problem that the federal government is required to solve? Or in other words: why should my tax dollars go to help an organization that couldn't manage their security properly?

Because this organization endangered the economy of a significant chunk of the country by their negligence, then your tax dollars should go to setting standards and holding them liable when they fail to meet those standards.

Some board member resignations might be in order and being banned from being directors for 10-20 years

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#156

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…

> The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything.

Oh come on. It is just an excuse. Look up what FAANG pays for those jobs ( total compensation ). Pay 2x. Get people from FAANG to work for you.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#157

Earlier quoted context omitted.

Nobody in their right mind will consider a lot of attention by three letter agencies a reward or help. They may, and can, do a lot more damage than 0.4% of revenue, and can do a lot of damage to the individuals making the decisions as well. Even if they help out, it will alert everyone and everything in 5 governments to all details about their firm. Three letter agencies have used (and destroyed) companies for unrela…

It's the 3-letter agencies where the expertise lies. Maybe a new agency needs to be created outside of the intelligence agencies?

Yes, at least a 16-letter agency consisting of uppercase lowercase letters and special characters would be much better ;)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#158
post #16

Every corporation in the US should be lobbying to abolish Bitcoin. It’s an existential threat that could be eliminated if they pooled their financial and political resources.

Bitcoin has nothing to do with this news? It seems like you have an unrelated axe to grind.

They paid the ransom in Bitcoin.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#159
post #150

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

This sounds like the kind of argument a ransomware developer would use to delude themselves... or quite a lot like the "Bitcoin is actually good for the environment!" people.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#160
post #125
post #83

In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…

Suppose that everyone has raised their house up on a pile of dirt. The rain comes down. It fills up the large ditches between people's houses, and leaves the houses dry. Suppose I implement better, but imperfect, security. It now costs an attacker $6 million, in salaries, paying for exploits, whatever, to hack my system. They still can only get $5 million in ransom. The attack isn't worth doing anymore, so they find…

Like The Netherlands
Post reply on HN