Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

341–350 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#341

Earlier quoted context omitted.

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

I don’t know. Did any of it matter? It was bad when people started hoarding gas. Just a few unfathomably stupid people - as always in this country. If idiots didn’t hoard gas, nothing would really have gone wrong.

The preppers are the other side of the same coin. The only thing they seem to never run out of is toilet paper. Who the fuck cares? Pentesters have the same energy. They tell you about what software not to use (anything in their automated suite), followed by a bunch of meaningless bullshit. It is a form of anti preparation, it would not have helped Colonial at all.

You talk about crippling, and in the biggest audition for crippling society in the world, time after time it’s the Everyman being an idiot - or a Prepper being too smart for their own good - that is responsible for all the bad.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#342
post #318

I don't have much to add here, but I've been going to Def Con and the other Las Vegas security conferences for a few years. Every year there is a section for infrastructure security (factories, refineries, etc). Its always the smallest section and the least populated. But its simultaneously the "most important" in terms of how much damage can be done from a single attack. Every year I went and was always terrified by…

In 50 years I hope to find out it was pulled off by the infrastructure teams who have been arguing for more security all along and that they did some good with the money.

Ha. The people that man the booths there are generally researchers for pen testing companies or universities.

Also, just a cool thing https://www.wired.com/story/evil-bubbles-industrial-pump-hac... There are like tons of attack like this that are possible and they demonstrate those at the booths

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#343
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…

Which option maximizes the long-term rate of growth of your wealth depends on how much money you already have. The Kelly Criterion takes this into account and handles a wide range of situations including this one.

Example: Say you have $10⁵, and you have the option to play game 1, which offers a 95% chance of a $5×10⁶ prize, or game 2, which offers a 50% chance of a $5×10⁷ prize. By the Kelly Criterion, the value of a scenario is the expected value of the logarithm of your wealth under that scenario:

• not playing at all = lg[10⁵] = 5

• game 1 = 95%×lg[10⁵ + 5×10⁶] + 5%×lg[10⁵ + 0] ≈ 6.6

• game 2 = 50%×lg[10⁵ + 5×10⁷] + 50%×lg[10⁵ + 0] ≈ 6.3

So game 1 is the best option if you have only $10⁵. On the other hand, if you have, say, $10⁶, then game 2 is the best option.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#344

Earlier quoted context omitted.

Yes but BTC is far too valuable. The piñata was only online until it was worth too much. Might work well for other Alts.

You know you can have fractional BTC, right?

What I’m more worried about is when the sat is too valuable. We can millisat it with LN, but it’s still not enough. I used to think eth was absurd with 18 but we kinda wish for more than 2.1 quadrillion of the beasties.

There are world currencies used by 100M+ that are worth less than a sat today (IDR). In short while it’s more like 1B+ as BTC grows rarer.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#345
Seeing the most advanced technological processes now subject to what is crudely a protection racket brings to mind a quote by Debord:

"Founded on obscurantism and poverty, the Mafia at that time was not even able to implant itself in Northern Italy. It seemed condemned to vanish before the modern State. It was a form of organized crime that could only prosper through the ‘protection’ of backward minorities, outside the world of the towns, where the laws of the bourgeoisie and the control of a rational police force could not penetrate. The defensive tactics of the Mafia could only suppress witnesses, neutralize the police and judiciary, and install as ruler in its sphere of activity the secret that is necessary to it. Subsequently it found a new field in the new obscurantism of the society of the diffuse spectacular, then in its integrated form: with the total victory of the secret, the general resignation of citizens, the complete loss of logic, and universal cowardice, all the favorable conditions were united for it to become a modern and offensive power"

https://theanarchistlibrary.org/library/guy-debord-comments-...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#346

Earlier quoted context omitted.

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

> I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states These may be the same thing however.

If the terrorists and nation states are content with going after random single targets, causing low disruption, and leaving with some money, then good! That's not the scary scenario.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#347
post #308

I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…

It’s the old being-hacked-as-a-service startup idea.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#348
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

[deleted]

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#349
post #334
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

In 2019, ProPublica wrote how paying ransoms benefit insurance companies. They called this: "The extortion economy: How insurance companies are fueling a rise in ransomware attacks. Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom. Why? The attacks are good for business." [0] [0]: https://www.propublica.org/article/the-extortion-econom…

For such a long article it's (IMHO) a fairly naive view. Sure insurance companies make some profit, specially in the beginning but, eventually, the price gets higher and higher and the cost to secure becomes less than the cost of insurance.

We had a similar issue with builder's insurance down here in Australia. It's was (and still is) cheaper to get insurance than build a quality building. Eventually that caught up with the builders (and they moved to using a seperate corporate entity for each building and closing it after the building is built, but that's another story of corruption).

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#350

Earlier quoted context omitted.

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

Company: Well this is a painful lesson

Me: Only if you learn it.

Penetration testing is part of a security program. If you don't have a security program, penetration "testing" isn't useful whether it's painful or not.

Haves the careers or investments of anyone significant who brought things to this point been screwed? If not, nothing will change.

Post reply on HN