Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

311–320 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#311

Per the Boston Globe story [0] they were actually in the process of restoring from backups but it was going too slow. Something to remember: when downtime is so critical that key pieces of a country's infrastructure is at stake, backups can't be enough-- there also has to be a rapid recovery plan to actually use them. [0] https://www.bostonglobe.com/2021/05/13/business/colonial-pip...

From the article you linked, it sounds like it was the other way around, but both ways to restore must be slow...

“Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said.”

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#313

So, supposedly, Colonial paid the ransom "within hours after the attack". And, supposedly, the attack didn't even hit any ICS, just the payment infrastructure ( https://www.zdnet.com/article/colonial-pipeline-ransomware-a... ). Why are there still gas shortages 6 days later? Not a rhetorical question at all. To me, the idea that the infrastructure we rely on is controlled by middle managers with no sense of urgency a…

The population created the gas shortage, even where there was no threat of a gas shortage.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#314
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

> I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states

These may be the same thing however.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#315

Earlier quoted context omitted.

The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…

The difference in actual value between the two for me at least is much smaller than the difference in numerical value. Both amounts are enough for me to never work another day in my life, and instead focus on building what I want to build. Past that massive increase in quality of life extra money is relatively meaningless (to me) . This is the same reason that people who decry spending money on lottery tickets as a s…

[deleted]

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#317

Earlier quoted context omitted.

The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…

Is being a "good" security person really more involved than: * making sure you have all your ports locked down * limit connectivity between all instances to only the bare minimum * any public access is via protocols such as ssh which have zero-to-none vulnerabilities * any 3rd party software you dont know is secure should never be public * routinely run employee training on how not to let themselves get hacked via so…

I'm sorry, but this just doesn't work in the real-world.

As the "security guy", you're seen as the troll under the bridge. Someone to get past via any means necessary, including lying.

But lets say you get your way.

"making sure you have all your ports locked down"

You can't imagine how much work this actually is on a network with 1,000+ servers running at least 10,000 distinct pieces of software. Most of which don't document their firewall requirements.

Oh, did you know that Active Directory domain controllers -- the single most valuable attack targets -- require essentially all ports open to all computers on the network?

What is your firewall going to do when all modern software communication is over HTTPS and "looks the same"?

How are you going to firewall off just one modern server with 200 Gbps Ethernet? Do you have any idea how much you'd have to spend with CheckPoint or Juniper or Cisco or whomever to do that?

"limit connectivity between all instances to only the bare minimum"

That lasts right up to the point that the shouty guy in finance that talks directly to the CxOs wants PowerBI on his desktop to be able to pull in data directly from all the databases. Did I say desktop? I meant a laptop on unencrypted airport WiFi.

"any public access is via protocols such as ssh which have zero-to-none vulnerabilities"

You don't get to choose the software. Windows doesn't use SSH for anything, and can't be made to.

Also, if you know anything about ransomware attacks, you would know that protocol encryption does nothing to even slow them down. If anything, it makes detecting attacks harder!

"routinely run employee training on how not to let themselves get hacked via social engineering"

Meet Mr Bell's Curve, and its unavoidable left hand side. Some people are just incorrigibly stupid and will routinely fall for phishing attacks, no matter how much training they receive. At any large corporation -- the type worth ransoming -- these people are inevitable. You, Mr Security Person, don't work in HR and don't make hiring and firing decisions.

"I'm sure I'm missing other stuff"

You're missing the fundamentals of the problem, which is that as a security guy:

- You must come up with security solutions that work in the face of morons.

- You must be able to secure software written by morons with no interest in, or ability to write secure code.

- You must do this without impacting the business in any material way, because if you stand in the way of anyone more senior than you -- even once -- you'll never be listened to again.

"Or are hackers so creative that even following these basic rules will still not make you a hard target?"

Currently, for any large org above about 1K staff, security against targetted attacks is basically impossible. Certainly not financially viable. Your competition will not spend the money, make more profit, pay out the ransom, and come out ahead of you.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#318

I don't have much to add here, but I've been going to Def Con and the other Las Vegas security conferences for a few years. Every year there is a section for infrastructure security (factories, refineries, etc). Its always the smallest section and the least populated. But its simultaneously the "most important" in terms of how much damage can be done from a single attack. Every year I went and was always terrified by…

In 50 years I hope to find out it was pulled off by the infrastructure teams who have been arguing for more security all along and that they did some good with the money.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#319
post #152

Earlier quoted context omitted.

If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…

>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…

Agree. The govt need not provide the teams as they must compete for talent like anyone else and don't have much to spare.

The govt only has a relative abundance of talent [largely interspersed with its contractors] in highly regulated activites like making nuclear weapons, where private entities don't participate.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#320

Earlier quoted context omitted.

Or more likely insurance. The insurance may demand better practices for lower premium in turn

There were some news reports yesterday about insurance companies dropping cyber-ransom insurance from their offerings (AXA, I think). Very likely more insurance companies will do the same soon, or at least, refuse to insure the company unless they comply with some cybersecurity standards.

Pretty much. Insurance industry can be helpful here. They can develop audits and make requirements same as they do for worker safety procedures.
Post reply on HN