Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

221–230 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#221

Earlier quoted context omitted.

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.

Not quite. The attacker still got access to the system in some way. They may have a permanent backdoor now and opportunity for messing with your backup operation.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#222

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

Imagine making it illegal to hand over your wallet to a mugger holding a gun to you. All you are doing is incentivizing companies to not report these attacks.

It would in incentivize more people to fight back rather than acquiesce, and therefore likely reduce the number of muggings.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#223

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

I mean, let's address the elephant in the room: there is no such thing as computer security. As we see with new leaks and hacks and vulnerabilities every single week, the idea that a computer that is connected to the Internet can be secure is a joke. The whole industry is built on protocols and tools that assume there will never be any bad actors, and we're reaping the rewards of that now. It will take decades of lay…

the assumption that there is no security in open protocols is badly misinformed here.

"Hiring some guy with an infosec cert would not have stopped this attack, because there is no way to stop this kind of attack."

blovation

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#225

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

I wonder how long you’d sit it out losing money before you paid. I think it’s very easy to talk a big game until you’ve lost many multiples of the ransom with no end in sight. It’s literally just a waiting game for the hackers, they have nothing to lose and everything to gain. So what if you don’t pay, you can just leave them screwed and move on to the next one.

Or if you're running a service which can't wait. Like a medical clinic with no access to patient records.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#226
post #150

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

The proper Milton Friedman / Reagan capitalism solution is to let the hacked oil company to bankrupt, wipe out the cap table and then competent new owners can take over for cheap

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#227

Earlier quoted context omitted.

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.

Nowadays the attackers will threaten to disclose the sensitive data publicly, as they did in this case. So ensuring your own access to your data, i.e. backups, is not the only concern. It's still important, of course.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#228
post #150

Earlier quoted context omitted.

I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

They could have started incentivizing after the Equifax hack. Personal data of hundreds of millions of people spilled over the web, everyone plus their dog gets to monitor their credit report or swap credit cards, yet Equifax still exists, and no meaningful consequences for anyone, including the CEO who sold his shares before the intrusion become public. Why is that even permitted?

I was going to say fine these companies a fair amount if there's a data breach;

But they would just turn around and add their costs on to the consumer.

I'll get hammered for this, but there's a part of me that would like to just outlaw all bitcoins worldwide, and even that might not work unless every country banned them?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#229
post #168

Earlier quoted context omitted.

You have a point. They should do minimum due diligence to harden their networks. However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.

He's a CEO. His job is to ask others to find him the experts needed and manage them. He doesn't need to know any actual security engineering.

He needs to know the basics. How does he know someone is a real expert?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#230

So, supposedly, Colonial paid the ransom "within hours after the attack". And, supposedly, the attack didn't even hit any ICS, just the payment infrastructure ( https://www.zdnet.com/article/colonial-pipeline-ransomware-a... ). Why are there still gas shortages 6 days later? Not a rhetorical question at all. To me, the idea that the infrastructure we rely on is controlled by middle managers with no sense of urgency a…

You do not need actual disruptions in supply to create a shortage. The threat of a disruption or a shortage for such a critical commodity can create a situation that it becomes a self fulfilling prophecy (short term).

That is what can often create bank runs and created the "great toilet paper shortage of 2020".

Post reply on HN