Earlier quoted context omitted.
Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.
I might agree if I had any faith that the people who paid this ransom would do any more than the bare minimum to close this one specific vulnerability and nothing else.
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
401–410 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#402Earlier quoted context omitted.
>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…
“Too big to fail” and investors do not get hurt. The problem does not fix itself until the investors start truly losing money, the care, unlike the Equifax case. Until the portfolio value cannot go down 90% there is not going to be a change in corporate actionism.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#403The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
I’m wondering if in the grand scheme of things this could be one more reason to speed up development of solar/wind + distributed energy production.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#404In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…
> Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely target. This reminds me of the old saying about locking your bicycle on the street. It won't 100% prevent yours from being stolen, but if the other bikes around yours has less secure means of locking, then the thief will likely take those bikes instead of yours.
This also gets taken in dark directions: you don’t even need to run faster than the guy next to you, you just need to trip him up.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#405Earlier quoted context omitted.
The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…
> The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Oh come on. It is just an excuse. Look up what FAANG pays for those jobs ( t…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#406Earlier quoted context omitted.
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
Someone mentioned that these could be terrorists posing as hackers. So, why not both? I’m wondering if in the grand scheme of things this could be one more reason to speed up development of solar/wind + distributed energy production.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#407Earlier quoted context omitted.
The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…
The problem I see is that there are tradeoffs between security and usability, and again between developing security vs developing features. Security doesn't make money next quarter, while features and ease of use do. Any software engineer can do security if they spend time learning and working on it. But executives don't seem to care about it.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#408In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…
> Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely target. This reminds me of the old saying about locking your bicycle on the street. It won't 100% prevent yours from being stolen, but if the other bikes around yours has less secure means of locking, then the thief will likely take those bikes instead of yours.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#409Dumb question: why can’t crypto currencies and exchanges place the ransom tokens on some kind of blocklist, thereby forever tainting those coins? As I understand, the rise of “privacy wallets” has greatly increased the anonymity of such transactions. But, at the end of the day, don’t we always have a ledger of the coin ids? I’m curious how the coins actually get laundered back into cash.
Dumb question 2: How do you taint tokens when a "coin" is divided arbitrarily? As in, there are no minimum unit of a "coin"?
(Incidentally also, there is a minimum unit, at least in all currencies that I know of; Bitcoin, for example, goes to eight decimal places. But yeah, each unit doesn’t have physical identity like bank notes do. Infinite divisibility is bad for efficiency as it means your data types have unbounded memory usage, so you’d need to put together a bunch of rules about how far you actually can divide things, and it’s just not worth it.)
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#410Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…
Since healthcare is so heavily regulated it’ll be interesting to see what repercussions come of this. The company has been mostly silent on the matter despite it being severe enough that you can’t even get to their website.