Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

331–340 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#331

Earlier quoted context omitted.

why would Colonial Pipeline be the scumbag in this story?

For not taking the effort to secure such important infrastructure, despite bringing in huge profits. They have both the duty and the means to have first rate IT staff providing excellent tested back-ups as well as security.

So victims of ransomware are now scumbags? Interesting

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#332

I don't have much to add here, but I've been going to Def Con and the other Las Vegas security conferences for a few years. Every year there is a section for infrastructure security (factories, refineries, etc). Its always the smallest section and the least populated. But its simultaneously the "most important" in terms of how much damage can be done from a single attack. Every year I went and was always terrified by…

Completely agree. If interested check out the documentary Zero Days. Insane, essentially the NSA in tandem with Israel took down Iran's nuclear program by impacting their industrial control units. Many Zero Days were used with nearly an unlimited budget.

[1] https://www.youtube.com/watch?v=C8lj45IL5J4&ab_channel=Madma...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#333
post #245
post #218

Earlier quoted context omitted.

> At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. Even if that's true, it doesn't affect backups. Back your fucking systems up properly, and if you are attacked by ransomware, then do a scorched earth restore.

It absolutely does affect backups. If you stand to gain $5M from an attack you can also target the backup systems and still easily end up profitable. Only if you stand to gain less than $100k does the budget actually start to get tight. As for how you attack the backup system it depends. If it push based you send your payload during the push. If it is pull based you craft your payload in the data that will be backed…

It seems appropriate to regurgitate the one about the bear and the hikers....

Two friends are in the woods, having a picnic. They spot a bear running at them. One friend gets up and starts running away from the bear. The other friend opens his backpack, takes out his running shoes, changes out of his hiking boots, and starts stretching.

“Are you crazy?” the first friend shouts, looking over his shoulder as the bear closes in on his friend. “You can’t outrun a bear!”

“I don’t have to outrun the bear,” said the second friend. “I only have to outrun you.”

In our scenario, the bear is the ransomware attackers, and Colonial Pipeline is one of the runners.

There are hundreds or thousands or tens of thousands more runners that the bear can go after.

You don't need to have perfect security over every aspect of your operation (though you should of course aspire to that). In particular you don't need to give up because in theory someone could infiltrate your offsite backups.

You just need to make things hard enough that the ransomware guys will go after an easier target.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#334
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

In 2019, ProPublica wrote how paying ransoms benefit insurance companies.

They called this: "The extortion economy: How insurance companies are fueling a rise in ransomware attacks. Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom. Why? The attacks are good for business." [0]

[0]: https://www.propublica.org/article/the-extortion-economy-how...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#335
Somewhere there an ICBM on the internet.

If all these things like water, power and pipelines are on the internet for no reason but laziness (not like they used a USB thumb drive) then you can be sure some general has decided they want to monitor missiles on their smartphone.

Putin must be laughing his ass off.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#336
post #308

I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…

Yes but BTC is far too valuable. The piñata was only online until it was worth too much. Might work well for other Alts.

You know you can have fractional BTC, right?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#337

Earlier quoted context omitted.

Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions

> I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions War.

Too grandiose a word for a targeted assassination of a handful of folks.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#338
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

It is much better to pay a 50M bug bounty than to have a system downtime cause billions in damage.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#339
post #299

Earlier quoted context omitted.

Well from the article, the decryption tool was so slow they kept using backups along with it. Sounds like future hackers need to improve their decryption tools, or companies where speed matters (like utilities) won't bother paying.

This was the error yeah.

Given how encryption is generally symmetric in terms of operations and speed, I wonder how long the original encryption took as well? What warnings were overlooked leading up to the attack fully going into place?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#340

Earlier quoted context omitted.

The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…

> The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Oh come on. It is just an excuse. Look up what FAANG pays for those jobs ( t…

Game theory says nah, just do enough so the other guy gets hit first. I mean I could spend the kids' college fund turning the house into an impenetrable fort with bulletproof glass, booby traps, 2 ton doors and concrete walls; or I can spend a few thousand and get a really grumpy window cat so a burglar moves on to an easier target.
Post reply on HN