Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

351–360 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#352

Earlier quoted context omitted.

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

Maybe the NSA should hack these companies for free. That would be helpful.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#353
post #152

Earlier quoted context omitted.

If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…

>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…

Do corporations defend their factories with their own weapons?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#354

Earlier quoted context omitted.

> I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions War.

Too grandiose a word for a targeted assassination of a handful of folks.

Not if the hacker group is a nation state. Sure, small time hacking is cute and all, but the US isn’t going to just roll over and be all like “oh no, you hit critical infrastructure that had a big impact on peoples life. Carry on”

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#355

Earlier quoted context omitted.

Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions

> I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions War.

Wouldn't it cause more ransoms and more damage to millions of Americans?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#356
post #334
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

In 2019, ProPublica wrote how paying ransoms benefit insurance companies. They called this: "The extortion economy: How insurance companies are fueling a rise in ransomware attacks. Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom. Why? The attacks are good for business." [0] [0]: https://www.propublica.org/article/the-extortion-econom…

Thank you for posting that link, it was really informative.

> ProPublica has found that they [insurers] often accommodate attackers’ demands, even when alternatives such as saved backup files may be available.

What a perverse set of incentives. Insurance companies are paid to manage risk. Risks go up the more they pay ransoms. As risks go up, the risks are more visible, more companies get policies, insurance gets more money. This is bordering or racketeering.

How many times do people on HN say “back up your files”. Certainly that’s the way to do it if you want less ransomware. It’s not sexy, it’s not “visible”, but it will reduce your risk. But apparently, the goal here is to encourage more ransomware.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#357

Per the Boston Globe story [0] they were actually in the process of restoring from backups but it was going too slow. Something to remember: when downtime is so critical that key pieces of a country's infrastructure is at stake, backups can't be enough-- there also has to be a rapid recovery plan to actually use them. [0] https://www.bostonglobe.com/2021/05/13/business/colonial-pip...

TFA says the opposite - that backups are faster than the decryption tool supplied by the hackers. Would you run a tool supplied to you by the hackers on your network? This thing could be scrubbing, adding backdoors, really anything. >Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using i…

Yes, that also means they had backups since the original outage but they were slow. Since they had backups they should never have paid for even slow decryption and, as you said, potential other security issues using the hackers software. So my reading of the situation is that the situation was urgent, backups were too slow, so they paid to try to have a quick fix only to have the description also be very slow. Paying might have been a complete waste of money. I could be wrong about my reading of events, but as I said originally, they lacked rapid recovery capabilities, which for something this critical is just as important as having the backups themselves.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#358

Earlier quoted context omitted.

> I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states These may be the same thing however.

If the terrorists and nation states are content with going after random single targets, causing low disruption, and leaving with some money, then good! That's not the scary scenario.

While I'm not directly trying to claim that this hack was the result of a nation-state actor, there's also no reason to assume such an entity wouldn't test the waters with small scale, targeted interference either.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#359

Per the Boston Globe story [0] they were actually in the process of restoring from backups but it was going too slow. Something to remember: when downtime is so critical that key pieces of a country's infrastructure is at stake, backups can't be enough-- there also has to be a rapid recovery plan to actually use them. [0] https://www.bostonglobe.com/2021/05/13/business/colonial-pip...

From the article you linked, it sounds like it was the other way around, but both ways to restore must be slow... “Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said.”

Yes, that also means they had backups since the original outage but they were also going slow. My read of the situation is that the situation was urgent, backups were too slow, so they paid to try to have a quick fix only to have that also be very slow. I could be wrong about that, but as I said originally, they lacked rapid recovery capabilities.
Post reply on HN