Earlier quoted context omitted.
why would Colonial Pipeline be the scumbag in this story?
For not taking the effort to secure such important infrastructure, despite bringing in huge profits. They have both the duty and the means to have first rate IT staff providing excellent tested back-ups as well as security.
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
331–340 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#332I don't have much to add here, but I've been going to Def Con and the other Las Vegas security conferences for a few years. Every year there is a section for infrastructure security (factories, refineries, etc). Its always the smallest section and the least populated. But its simultaneously the "most important" in terms of how much damage can be done from a single attack. Every year I went and was always terrified by…
[1] https://www.youtube.com/watch?v=C8lj45IL5J4&ab_channel=Madma...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#333Earlier quoted context omitted.
> At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. Even if that's true, it doesn't affect backups. Back your fucking systems up properly, and if you are attacked by ransomware, then do a scorched earth restore.
It absolutely does affect backups. If you stand to gain $5M from an attack you can also target the backup systems and still easily end up profitable. Only if you stand to gain less than $100k does the budget actually start to get tight. As for how you attack the backup system it depends. If it push based you send your payload during the push. If it is pull based you craft your payload in the data that will be backed…
Two friends are in the woods, having a picnic. They spot a bear running at them. One friend gets up and starts running away from the bear. The other friend opens his backpack, takes out his running shoes, changes out of his hiking boots, and starts stretching.
“Are you crazy?” the first friend shouts, looking over his shoulder as the bear closes in on his friend. “You can’t outrun a bear!”
“I don’t have to outrun the bear,” said the second friend. “I only have to outrun you.”
In our scenario, the bear is the ransomware attackers, and Colonial Pipeline is one of the runners.
There are hundreds or thousands or tens of thousands more runners that the bear can go after.
You don't need to have perfect security over every aspect of your operation (though you should of course aspire to that). In particular you don't need to give up because in theory someone could infiltrate your offsite backups.
You just need to make things hard enough that the ransomware guys will go after an easier target.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#334The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
They called this: "The extortion economy: How insurance companies are fueling a rise in ransomware attacks. Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom. Why? The attacks are good for business." [0]
[0]: https://www.propublica.org/article/the-extortion-economy-how...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#335If all these things like water, power and pipelines are on the internet for no reason but laziness (not like they used a USB thumb drive) then you can be sure some general has decided they want to monitor missiles on their smartphone.
Putin must be laughing his ass off.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#336I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…
Yes but BTC is far too valuable. The piñata was only online until it was worth too much. Might work well for other Alts.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#337Earlier quoted context omitted.
Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions
> I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions War.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#338The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#339Earlier quoted context omitted.
Well from the article, the decryption tool was so slow they kept using backups along with it. Sounds like future hackers need to improve their decryption tools, or companies where speed matters (like utilities) won't bother paying.
This was the error yeah.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#340Earlier quoted context omitted.
The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…
> The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Oh come on. It is just an excuse. Look up what FAANG pays for those jobs ( t…