Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

171–180 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#171
post #10

Every corporation in the US should be lobbying to abolish Bitcoin. It’s an existential threat that could be eliminated if they pooled their financial and political resources.

Isn't it better that these networks are getting hardened in exchange for a small cryptocurrency payment, instead of waiting for all the exploits to be used by an adversary in World War Three?

How are they getting hardened?? Magically??

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#172
post #152

Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…

If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…

The market has already solved this in the form of ransomware groups. No need to have the government do it and issue a fine, ransomware groups literally are doing what you said.

I guess the government could legalize ransomware hacking to encourage it, but that'll never happen.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#173

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

Absolutely this. Paying a ransom should be illegal and company officers should face personal criminal liability for allowing it. If the CEO of Colonial was facing jail time, there is no way the payment would have happened.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#174

Earlier quoted context omitted.

Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.

This is by far the cheapest solution.

unless your data is legally required to stay confidential under HIPPA or similar law. Then a backup just keeps you operating but not immune to the threat of data publication.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#175
post #152

Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…

If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…

They could do it indirectly, by requiring insurance against security holes.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#176
post #150

Earlier quoted context omitted.

I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

This sounds like the kind of argument a ransomware developer would use to delude themselves... or quite a lot like the "Bitcoin is actually good for the environment!" people.

Maybe let's try more substantive arguments than a genetic fallacy.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#177
post #150

Earlier quoted context omitted.

I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

This sounds like the kind of argument a ransomware developer would use to delude themselves... or quite a lot like the "Bitcoin is actually good for the environment!" people.

Wasn't that what Jesus said about Judas Iskariot? To paraphrase: there must necessarily be evil in the world, but woe to the one who makes himself its conduit.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#178
post #108

Earlier quoted context omitted.

The 5M ransom plus all the other damage such as reputation loss, increased government scrutiny and potential damages to pay to partners (I'm sure they provide some sort of SLA for their oil delivery services?) is a good enough deterrent from allowing this to happen again.

5M is nothing to that pipeline management firm. I think nothing will change because the "fine" is tiny and later, when a VP of opsec gets to decide between a massively expensive hardening of security which includes big recurring costs to keep an opsec team on payroll and just pocketing a multimillion dollar bonus for optimizing the opsec budget, he will choose the latter. There's no risk of getting jail time and any…

> keep an opsec team on payroll and just pocketing a multimillion dollar bonus for optimizing the opsec budget

This is not how companies actually work. This is a fun “incompetent executive” fantasy that floats around but in real businesses you don’t pocket a huge bonus solely by cutting costs.

You’re gonna have a lot of explaining to do on why that money was being spent in the first place and why it’s not needed now.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#179

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

And if the penalty for hacking systems for malicious purpose goes up.

Hopefully every member of DarkSide ends up in court if they're US or friendly nation citizens or in Gitmo otherwise

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#180

Earlier quoted context omitted.

Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone. If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off. The government can help coordination by making defecting more costly (with criminal penalties).

I think criminal penalties is too much. I think at some point paying ransom is better than not paying, for example, in case of attacks on hospitals. People can literally die. What needs to happen is that when an organization that skips IT security practices, it should have large monetary penalties and its executives held responsible, no golden parachutes for them. You can imagine any factory where they don't practice…

> in case of attacks on hospitals. People can literally die.

Setting aside the appeal to emotion, there are a couple of things to unpack. In real-world ransom kidnappings, life and death was always at stake and the government still errs on the side of not paying.

Second, you presume ransomware authors are prepared to commit murder. If a hospital cannot legally pay, the only thing to gain by shutting it down is murder.

Post reply on HN