It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
No. The security problem is not a lack of effort or laxness, it is a fundamental inability to solve the problem. At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. The absolute best of the best commercial IT systems implemented as envisioned with full support can maybe protect up to the $10M level and I am just extrapolating upwards since I have never had any secu…
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
361–370 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#362Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#363Earlier quoted context omitted.
It's not the company side that matters. It's that it's a lot easier for the criminals to pull a few tricks to obscure their side of things significantly. Bitcoin mixers/tumblers for example so that what comes out the other end can't easily be tracked back to the crime. I'd be extremely surprised if groups making these attacks didn't use that type of thing. If it was all bank wires etc. then law enforcement could trac…
The issue is that a tumbler doesn't make the dirty money go away, quite the opposite; it gives a bunch of other people little bits of dirty money. If I were a non-criminal, or even a smaller-time criminal, it wouldn't be in my best interests to use a tumbler that might give me this dirty money.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#364It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
From my experience, the problem is that most infosec positions are powerless to do anything to increase security at the company, and are primarily there for PR or compliance reasons. The positions seem to be mostly filled with people who wanted to make a career change for the money; experienced people usually leave to work at private security companies, or FAANG sized companies.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#365Earlier quoted context omitted.
If the terrorists and nation states are content with going after random single targets, causing low disruption, and leaving with some money, then good! That's not the scary scenario.
While I'm not directly trying to claim that this hack was the result of a nation-state actor, there's also no reason to assume such an entity wouldn't test the waters with small scale, targeted interference either.
The situation of not being able to tell is pretty good.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#366Earlier quoted context omitted.
Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.
Company: Well this is a painful lesson Me: Only if you learn it. Penetration testing is part of a security program. If you don't have a security program, penetration "testing" isn't useful whether it's painful or not. Haves the careers or investments of anyone significant who brought things to this point been screwed? If not, nothing will change.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#367Earlier quoted context omitted.
Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions
> I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions War.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#368https://www.washingtonpost.com/business/2021/05/12/gas-short...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#369Earlier quoted context omitted.
Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.
I don’t know. Did any of it matter? It was bad when people started hoarding gas. Just a few unfathomably stupid people - as always in this country. If idiots didn’t hoard gas, nothing would really have gone wrong. The preppers are the other side of the same coin. The only thing they seem to never run out of is toilet paper. Who the fuck cares? Pentesters have the same energy. They tell you about what software not to…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#370It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
No. The security problem is not a lack of effort or laxness, it is a fundamental inability to solve the problem. At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. The absolute best of the best commercial IT systems implemented as envisioned with full support can maybe protect up to the $10M level and I am just extrapolating upwards since I have never had any secu…
It’s well, well, well known that working in ICS security as a security engineer means aggressively lower salaries to secure horribly insecure, outdated tech in a low funding environment.
That’s just a known fact.