Earlier quoted context omitted.
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
> These ransoms are net good...There are a lot of infrastructure teams taking security more seriously. Nonsense. This is not an academic exercise. Our country is being attacked by "nation states" (do more research) and we need to respond accordingly, treating it as the national security threat it is and making the perpetrators pay a heavy price. If they'd bombed our critical infrastructure, no one would be sitting ar…
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
391–400 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#392Earlier quoted context omitted.
I don’t know. Did any of it matter? It was bad when people started hoarding gas. Just a few unfathomably stupid people - as always in this country. If idiots didn’t hoard gas, nothing would really have gone wrong. The preppers are the other side of the same coin. The only thing they seem to never run out of is toilet paper. Who the fuck cares? Pentesters have the same energy. They tell you about what software not to…
You know what's way more effective at stopping gas hoarding so it's available for someone who really wants/needs it? Doubling the price per gallon. Anti-price gouging laws caused the shortage, just like with toilet paper and PPE last year.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#393What would it look like if the US, and for that matter a number of other frequently targeted countries, reciprocated?
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#394Earlier quoted context omitted.
It absolutely does affect backups. If you stand to gain $5M from an attack you can also target the backup systems and still easily end up profitable. Only if you stand to gain less than $100k does the budget actually start to get tight. As for how you attack the backup system it depends. If it push based you send your payload during the push. If it is pull based you craft your payload in the data that will be backed…
It seems appropriate to regurgitate the one about the bear and the hikers.... Two friends are in the woods, having a picnic. They spot a bear running at them. One friend gets up and starts running away from the bear. The other friend opens his backpack, takes out his running shoes, changes out of his hiking boots, and starts stretching. “Are you crazy?” the first friend shouts, looking over his shoulder as the bear c…
No, reality is more like the story of the dodo. A vast quantity of delicious prey that nobody was eating because nobody knew about them. Then they were discovered and some predators showed up but there were not enough to eat all of them. But then more and more predators showed up to exploit the vast untapped resource until they were all eaten.
We are still in the middle of that process which is borne out by the fact that the frequency of attacks has been increasing on the order of >100% per year and average demands per attack have been doing something similar. That is an utterly ferocious rate of growth that will soon be enough to attack not just the juiciest targets, but every profitable target in a few years.
Being slightly faster or slightly less delicious will not help when there are finally enough bears to eat everybody.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#395In past times (not to my knowledge anymore), countries at war would provide letters of marque to private ship captains, authorizing them to attack enemy shipping and keep the proceeds. That is exactly what Russia has done. What would it look like if the US, and for that matter a number of other frequently targeted countries, reciprocated?
(1) Someone crosses a red line, like cutting the electricity to New York City for days on end, prompting a proportionate response, or economic sanctions, or
(2) Diplomacy takes over and countries reach a quick agreement to curtail their activities, like during the Cuban missile crisis.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#396Earlier quoted context omitted.
You know what's way more effective at stopping gas hoarding so it's available for someone who really wants/needs it? Doubling the price per gallon. Anti-price gouging laws caused the shortage, just like with toilet paper and PPE last year.
A price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.
We shouldn't have widespread shortages for the sake of theoretical people whose existences are structured around 5 gallon commutes and razor thin margins tied with no lines of credit to float a week of double gas expenses.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#397Earlier quoted context omitted.
> These ransoms are net good...There are a lot of infrastructure teams taking security more seriously. Nonsense. This is not an academic exercise. Our country is being attacked by "nation states" (do more research) and we need to respond accordingly, treating it as the national security threat it is and making the perpetrators pay a heavy price. If they'd bombed our critical infrastructure, no one would be sitting ar…
Can they unbomb it for $5 million? Cause that would be cool.
Yes, we could "unbomb" it for some amount of money. But, we generally use the term "repair".
But, that's a great point: as long as we can undo the damage for some amount of money (via repair or paying extortion), we should let foreign adversaries dictate the terms on which they'll allow us to operate our infrastructure.
Still, do let us know when you think we should be concerned. 2 more pipelines? 3 more hospitals? 4 more police stations?
$5 trillion ransoms? Maybe? No? Perhaps when infrastructure outages and other attacks cause deaths?
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#398Earlier quoted context omitted.
Which option maximizes the long-term rate of growth of your wealth depends on how much money you already have. The Kelly Criterion takes this into account and handles a wide range of situations including this one. Example: Say you have $10⁵, and you have the option to play game 1, which offers a 95% chance of a $5×10⁶ prize, or game 2, which offers a 50% chance of a $5×10⁷ prize. By the Kelly Criterion, the value of…
Great example. It is worth emphasising your model will capture the game from the ransom attackers perspective since for them it is repeated many times. It won't give the EV for the attacked as their number of ransom incidents will hopefully be very small rather than tend to infinity. Which likely means the EV will be based on their own personal utility function.
• pay for security that prevents attacks = lg[company value – cost of security]
• don’t pay for security = attack probability × lg[company value – cost of dealing with attack] + (1 – attack probability) × lg[company value]
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#399The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#400Earlier quoted context omitted.
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.