Earlier quoted context omitted.
If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…
The market has already solved this in the form of ransomware groups. No need to have the government do it and issue a fine, ransomware groups literally are doing what you said. I guess the government could legalize ransomware hacking to encourage it, but that'll never happen.
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
181–190 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#182Earlier quoted context omitted.
The market has already solved this in the form of ransomware groups. No need to have the government do it and issue a fine, ransomware groups literally are doing what you said. I guess the government could legalize ransomware hacking to encourage it, but that'll never happen.
I'd rather the money and fines flow to the US government, not random hacker groups.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#183Earlier quoted context omitted.
Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone. If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off. The government can help coordination by making defecting more costly (with criminal penalties).
I think criminal penalties is too much. I think at some point paying ransom is better than not paying, for example, in case of attacks on hospitals. People can literally die. What needs to happen is that when an organization that skips IT security practices, it should have large monetary penalties and its executives held responsible, no golden parachutes for them. You can imagine any factory where they don't practice…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#184Earlier quoted context omitted.
This is by far the cheapest solution.
unless your data is legally required to stay confidential under HIPPA or similar law. Then a backup just keeps you operating but not immune to the threat of data publication.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#185Earlier quoted context omitted.
This is by far the cheapest solution.
unless your data is legally required to stay confidential under HIPPA or similar law. Then a backup just keeps you operating but not immune to the threat of data publication.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#186Earlier quoted context omitted.
How do you know that? What evidence is there that it's any more secure than it used to be?
These pirates have committed to not hitting the same target again?
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#187Earlier quoted context omitted.
This is by far the cheapest solution.
unless your data is legally required to stay confidential under HIPPA or similar law. Then a backup just keeps you operating but not immune to the threat of data publication.
I'm sure that there's proprietary data. Maybe knowing how much oil / gasoline is flowing might allow some traders to make unfairly informed trades (or maybe not: only inside trading is illegal. If someone figures out the information some other way, its not illegal IIRC).
And maybe employee data should be kept private, but there's no HIPPA requirement on that. Its not like there's payment processors on this thing either, so no PCI compliance here.
So I'm not exactly seeing why backing up data would be an issue in this case.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#188Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
Absolutely this. Paying a ransom should be illegal and company officers should face personal criminal liability for allowing it. If the CEO of Colonial was facing jail time, there is no way the payment would have happened.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#189Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
Realistically, ransomware will just never stop until IT systems are sufficiently hardened.
The problem is information density.
So long as billions of records that are needed for the business exist in a device the size of a shoebox, we’re fucked. An insider can always take the shoebox, lock the shoebox, etc.
Three stories of paper files in file cabinets can’t be ransomed short of a physical bomb threat.
Don’t know what the solution is. But I do know the problem. Exfiltrarion is similar: the odd quirk of technology that has enabled these massive thefts is the ability to load millions of pages in a few seconds into a thumb drive. Odd pickle we’ve got ourselves into.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#190It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
I mean, let's address the elephant in the room: there is no such thing as computer security. As we see with new leaks and hacks and vulnerabilities every single week, the idea that a computer that is connected to the Internet can be secure is a joke. The whole industry is built on protocols and tools that assume there will never be any bad actors, and we're reaping the rewards of that now. It will take decades of lay…
This is just flat out wrong.