Earlier quoted context omitted.
Realistically, ransomware will just never stop until IT systems are sufficiently hardened.
Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
221–230 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#222Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
Imagine making it illegal to hand over your wallet to a mugger holding a gun to you. All you are doing is incentivizing companies to not report these attacks.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#223It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
I mean, let's address the elephant in the room: there is no such thing as computer security. As we see with new leaks and hacks and vulnerabilities every single week, the idea that a computer that is connected to the Internet can be secure is a joke. The whole industry is built on protocols and tools that assume there will never be any bad actors, and we're reaping the rewards of that now. It will take decades of lay…
"Hiring some guy with an infosec cert would not have stopped this attack, because there is no way to stop this kind of attack."
blovation
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#224Im in the wrong line of work.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#225Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
I wonder how long you’d sit it out losing money before you paid. I think it’s very easy to talk a big game until you’ve lost many multiples of the ransom with no end in sight. It’s literally just a waiting game for the hackers, they have nothing to lose and everything to gain. So what if you don’t pay, you can just leave them screwed and move on to the next one.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#226Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#227Earlier quoted context omitted.
Realistically, ransomware will just never stop until IT systems are sufficiently hardened.
Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#228Earlier quoted context omitted.
I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.
They could have started incentivizing after the Equifax hack. Personal data of hundreds of millions of people spilled over the web, everyone plus their dog gets to monitor their credit report or swap credit cards, yet Equifax still exists, and no meaningful consequences for anyone, including the CEO who sold his shares before the intrusion become public. Why is that even permitted?
But they would just turn around and add their costs on to the consumer.
I'll get hammered for this, but there's a part of me that would like to just outlaw all bitcoins worldwide, and even that might not work unless every country banned them?
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#229Earlier quoted context omitted.
You have a point. They should do minimum due diligence to harden their networks. However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.
He's a CEO. His job is to ask others to find him the experts needed and manage them. He doesn't need to know any actual security engineering.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#230So, supposedly, Colonial paid the ransom "within hours after the attack". And, supposedly, the attack didn't even hit any ICS, just the payment infrastructure ( https://www.zdnet.com/article/colonial-pipeline-ransomware-a... ). Why are there still gas shortages 6 days later? Not a rhetorical question at all. To me, the idea that the infrastructure we rely on is controlled by middle managers with no sense of urgency a…
That is what can often create bank runs and created the "great toilet paper shortage of 2020".