Every corporation in the US should be lobbying to abolish Bitcoin. It’s an existential threat that could be eliminated if they pooled their financial and political resources.
Isn't it better that these networks are getting hardened in exchange for a small cryptocurrency payment, instead of waiting for all the exploits to be used by an adversary in World War Three?
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
171–180 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#172Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…
If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…
I guess the government could legalize ransomware hacking to encourage it, but that'll never happen.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#173Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#174Earlier quoted context omitted.
Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.
This is by far the cheapest solution.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#175Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…
If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#176Earlier quoted context omitted.
I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.
This sounds like the kind of argument a ransomware developer would use to delude themselves... or quite a lot like the "Bitcoin is actually good for the environment!" people.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#177Earlier quoted context omitted.
I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.
This sounds like the kind of argument a ransomware developer would use to delude themselves... or quite a lot like the "Bitcoin is actually good for the environment!" people.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#178Earlier quoted context omitted.
The 5M ransom plus all the other damage such as reputation loss, increased government scrutiny and potential damages to pay to partners (I'm sure they provide some sort of SLA for their oil delivery services?) is a good enough deterrent from allowing this to happen again.
5M is nothing to that pipeline management firm. I think nothing will change because the "fine" is tiny and later, when a VP of opsec gets to decide between a massively expensive hardening of security which includes big recurring costs to keep an opsec team on payroll and just pocketing a multimillion dollar bonus for optimizing the opsec budget, he will choose the latter. There's no risk of getting jail time and any…
This is not how companies actually work. This is a fun “incompetent executive” fantasy that floats around but in real businesses you don’t pocket a huge bonus solely by cutting costs.
You’re gonna have a lot of explaining to do on why that money was being spent in the first place and why it’s not needed now.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#179Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
Realistically, ransomware will just never stop until IT systems are sufficiently hardened.
Hopefully every member of DarkSide ends up in court if they're US or friendly nation citizens or in Gitmo otherwise
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#180Earlier quoted context omitted.
Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone. If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off. The government can help coordination by making defecting more costly (with criminal penalties).
I think criminal penalties is too much. I think at some point paying ransom is better than not paying, for example, in case of attacks on hospitals. People can literally die. What needs to happen is that when an organization that skips IT security practices, it should have large monetary penalties and its executives held responsible, no golden parachutes for them. You can imagine any factory where they don't practice…
Setting aside the appeal to emotion, there are a couple of things to unpack. In real-world ransom kidnappings, life and death was always at stake and the government still errs on the side of not paying.
Second, you presume ransomware authors are prepared to commit murder. If a hospital cannot legally pay, the only thing to gain by shutting it down is murder.