Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

161–170 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#161
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…

How do they decrypt it then?? Just show the key to the computer??

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#162
post #150

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

They could have started incentivizing after the Equifax hack. Personal data of hundreds of millions of people spilled over the web, everyone plus their dog gets to monitor their credit report or swap credit cards, yet Equifax still exists, and no meaningful consequences for anyone, including the CEO who sold his shares before the intrusion become public. Why is that even permitted?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#163

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#164
post #33

Earlier quoted context omitted.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone. If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off. The government can help coordination by making defecting more costly (with criminal penalties).

Civil penalties may be more palatable. If organizations are willing and able to pay a ransom, there should be no problem with paying a fine as well.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#165
post #150

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

To add, I'm pretty sure ransomware groups provide tips on how to beef up security and how they got hacked in the first place.

Like dentistry, you can pay a little upfront for a better toothbrush or you can pay the dentist way more to repair your teeth later on.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#166

Earlier quoted context omitted.

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.

This is by far the cheapest solution.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#168

Earlier quoted context omitted.

> So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? First, in many jurisdictions, paying protection money for physical security is illegal. Second, Colonial Pipeline has an operating revenue of $1.32 billion. I suppose in the USA it's technically a person, but... it's not actually a person. > We have law enforcement so everyone can be free to focus on th…

You have a point. They should do minimum due diligence to harden their networks. However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.

He's a CEO. His job is to ask others to find him the experts needed and manage them. He doesn't need to know any actual security engineering.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#170

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

I am not a lawyer, but my understanding is that while paying a ransom is not illegal itself, anything that facilitates the payment of a ransom is. There is a chance some party that handled the ransom money broke this law by doing so.

There is another much greater chance that some party with a fiduciary duty to shareholders could be sued for misrepresenting the risk of this happening to shareholders.

Post reply on HN