Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

361–370 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#361
post #142

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

No. The security problem is not a lack of effort or laxness, it is a fundamental inability to solve the problem. At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. The absolute best of the best commercial IT systems implemented as envisioned with full support can maybe protect up to the $10M level and I am just extrapolating upwards since I have never had any secu…

Lol as if majority of those hacks aren’t just some misconfigured s3 permissions or creds that got submitted to Github or an unpatched windows machine. Those are essentially script kiddie hacks 2.0 except they now can get payed thanks to crypto (at least it’s useful for something)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#363
post #287

Earlier quoted context omitted.

It's not the company side that matters. It's that it's a lot easier for the criminals to pull a few tricks to obscure their side of things significantly. Bitcoin mixers/tumblers for example so that what comes out the other end can't easily be tracked back to the crime. I'd be extremely surprised if groups making these attacks didn't use that type of thing. If it was all bank wires etc. then law enforcement could trac…

The issue is that a tumbler doesn't make the dirty money go away, quite the opposite; it gives a bunch of other people little bits of dirty money. If I were a non-criminal, or even a smaller-time criminal, it wouldn't be in my best interests to use a tumbler that might give me this dirty money.

It doesn't matter if they're all criminals using the mixer-- we want to track these particular ransomware hackers, and that's made extremely difficult when all we see is their lump sum enter the mixer with countless other transactions, and countless disaggregated transactions come out the other end no longer tied to the hackers, making it much harder to track down the people that brought down most of the East Coast's pipeline infrastructure. Anything like that stunt is pretty difficult to accomplish using traditional banking institutions when we know where the money is going and can track it each step of the way, or just freeze it.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#364
post #80

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

From my experience, the problem is that most infosec positions are powerless to do anything to increase security at the company, and are primarily there for PR or compliance reasons. The positions seem to be mostly filled with people who wanted to make a career change for the money; experienced people usually leave to work at private security companies, or FAANG sized companies.

This. A million times this. I can’t tell you how many netsec roles are staffed by people that are content being a butt in a seat and have zero effect on the overall security of a corporation.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#365

Earlier quoted context omitted.

If the terrorists and nation states are content with going after random single targets, causing low disruption, and leaving with some money, then good! That's not the scary scenario.

While I'm not directly trying to claim that this hack was the result of a nation-state actor, there's also no reason to assume such an entity wouldn't test the waters with small scale, targeted interference either.

Okay, but in a way that doesn't really affect whether the attack has positive/negative effects.

The situation of not being able to tell is pretty good.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#366

Earlier quoted context omitted.

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

Company: Well this is a painful lesson Me: Only if you learn it. Penetration testing is part of a security program. If you don't have a security program, penetration "testing" isn't useful whether it's painful or not. Haves the careers or investments of anyone significant who brought things to this point been screwed? If not, nothing will change.

I think ransomware gangs will be emboldened and more will go after bigger targets. I also think ransom demands will grow and insurance premiums will continue to grow as well. I'm hoping there is some attainable point where it makes financial sense to practice good security.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#367

Earlier quoted context omitted.

Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions

> I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions War.

continuing the unfortunate trend of the public spending to protect private profit.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#369

Earlier quoted context omitted.

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

I don’t know. Did any of it matter? It was bad when people started hoarding gas. Just a few unfathomably stupid people - as always in this country. If idiots didn’t hoard gas, nothing would really have gone wrong. The preppers are the other side of the same coin. The only thing they seem to never run out of is toilet paper. Who the fuck cares? Pentesters have the same energy. They tell you about what software not to…

I doubt companies care about anything besides profit and that they could care less about gas hoarders. Also, this was just a little taste of havoc that could be done to the economy and society. I'm hoping they lost enough money to knock some sense into them to practice better security and hopefully it makes others think twice about practicing sloppy security. I'm also guessing in the wake of this that ransom attacks will increase in frequency, ransom demands will increase in value, and insurance premiums will increase as well and insurance providers may be forced to do better due diligence about policies that they sell to large corporations to ensure that they don't practice sloppy security. I'm hoping there is some tipping point where it makes financial sense for these large corporations to practice better security. Right now, they gamble that they won't be attacked and so don't invest in security and for the most part they have been rewarded.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#370
post #142

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

No. The security problem is not a lack of effort or laxness, it is a fundamental inability to solve the problem. At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. The absolute best of the best commercial IT systems implemented as envisioned with full support can maybe protect up to the $10M level and I am just extrapolating upwards since I have never had any secu…

Yeah this is sort of nonsensical. As someone else commented, Apple manages.

It’s well, well, well known that working in ICS security as a security engineer means aggressively lower salaries to secure horribly insecure, outdated tech in a low funding environment.

That’s just a known fact.

Post reply on HN