Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

321–330 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#321

Earlier quoted context omitted.

Imagine making it illegal to hand over your wallet to a mugger holding a gun to you. All you are doing is incentivizing companies to not report these attacks.

If the mugger isn't bluffing, then he'll get your money one way or the other. This makes it different from paying ransoms. Furthermore, a corporation's bottom line is not truly comparable to a human life. However it is my understanding that paying ransoms to save human lives is technically illegal to. If paying a ransom to save your family member's life is illegal, then corporations paying ransoms to protect their fi…

>However it is my understanding that paying ransoms to save human lives is technically illegal to

You are wrong.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#322

Earlier quoted context omitted.

Are you talking about the hackers or Colonial Pipeline?

why would Colonial Pipeline be the scumbag in this story?

For not taking the effort to secure such important infrastructure, despite bringing in huge profits.

They have both the duty and the means to have first rate IT staff providing excellent tested back-ups as well as security.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#323
post #183

Earlier quoted context omitted.

I think criminal penalties is too much. I think at some point paying ransom is better than not paying, for example, in case of attacks on hospitals. People can literally die. What needs to happen is that when an organization that skips IT security practices, it should have large monetary penalties and its executives held responsible, no golden parachutes for them. You can imagine any factory where they don't practice…

Kidnapping for ransom is basically a dead enterprise in the US because of laws essentially forbidding the paying of ransom. Your appeal to emotion is exactly the sort of thing that ransomware gangs want people to hear because its how they make money. In the long run though its a terrible idea.

>Kidnapping for ransom is basically a dead enterprise in the US because of laws essentially forbidding the paying of ransom.

This is bullshit. US laws do not prohibit ransom payments except to sanctioned and/or designated entities which tend to not operate within the US.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#325

Earlier quoted context omitted.

Nah. It will never stop. The problem is information density. So long as billions of records that are needed for the business exist in a device the size of a shoebox, we’re fucked. An insider can always take the shoebox, lock the shoebox, etc. Three stories of paper files in file cabinets can’t be ransomed short of a physical bomb threat. Don’t know what the solution is. But I do know the problem. Exfiltrarion is simi…

Your metaphor works both ways: the ability to fit billions of records in a shoebox means that it’s perfectly manageable to keep another shoebox as a backup, under independent control.

So now there are two shoeboxes. Hasn’t solved exfiltration. In fact, you’ve just doubled the risk.

There may not be a solution if the problem is untrustworthy people.

The custodians of your ‘independent control’ will eventually get ransomwared themselves.

Then what?

It’s like cash... If you are a sophisticated criminal, do you waste time burglarizing individuals? Or, do you rob the bank where the individuals keep their money for ‘safekeeping’?

How many people at Amazon have access to the database other companies use to store info?

2? 20? 200?

I don’t know, but I bet it’s a lot. And I doubt they get paid enough to make them immune to a generous offer (or a scary threat) from a bad guy.

Seriously, how many individuals at Amazon have the ability — if they wanted - to irreparable corrupt, encrypt, or destroy data?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#326
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…

[deleted]

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#327
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

This was extremely poor (I'd say weak) leadership by Colonial Pipeline. While continuing to be down is painful, it puts a spotlight on the issue and forces hands of critical infrastructure to improve security and reach out to security companies for audits and consulting. Also, they could have gotten additional support from the US government and political support by continuing to stay down instead of the back alley payout.

Not to mention, rewarding people for bad behavior is never a good idea. I learned this as a child... "If you give a mouse a cookie, then he'll ask you for a glass of milk."

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#328
post #308

I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…

Yes but BTC is far too valuable. The piñata was only online until it was worth too much. Might work well for other Alts.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#329
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

They could always just keep the "X" unplugged, it is doubtful hackers from Russia go onsite and sabotage things. Maybe this will make companies realize if they can't secure it at least just disconnect it. Everything doesn't have to be online.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#330

Earlier quoted context omitted.

Nah. It will never stop. The problem is information density. So long as billions of records that are needed for the business exist in a device the size of a shoebox, we’re fucked. An insider can always take the shoebox, lock the shoebox, etc. Three stories of paper files in file cabinets can’t be ransomed short of a physical bomb threat. Don’t know what the solution is. But I do know the problem. Exfiltrarion is simi…

There is a part of me that would like to go back to the way we dud business before the internet, and computers. I think three daily encrypted backups mandated by law would be enough to stop the multi-million dollar ransoms. We will still see companies paying ransom for a business days loss, but not complete shutouts? And infrastructure specific operations, like this pipe line, should be air gapped.

It’s good practice for a cash business to make daily runs to deposit daily at the bank. Stupid to leave cash laying in the till overnight.

Which is why thieves rob banks.

But, money is fungible... if it’s stolen, it can be replaced. If the bank can’t replace it without going broke, the FDIC steps in and, essentially, prints more money to make you whole (up to a point.)

But, data is unique and irreplaceable.

If everyone is backing up to a smaller and smaller number of ‘cloud’ companies, it’s just centralizing the problem... putting everyone’s eggs in one basket.

Post reply on HN