Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

401–410 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#401

Earlier quoted context omitted.

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

I might agree if I had any faith that the people who paid this ransom would do any more than the bare minimum to close this one specific vulnerability and nothing else.

So they'll be out of business sooner or later then and a company that follows security best practices will take over ideally.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#402

Earlier quoted context omitted.

>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…

“Too big to fail” and investors do not get hurt. The problem does not fix itself until the investors start truly losing money, the care, unlike the Equifax case. Until the portfolio value cannot go down 90% there is not going to be a change in corporate actionism.

They are starting to lose money, it's 5M$ today, who knows what it'll be tomorrow or how often it's going to happen.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#403
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

Someone mentioned that these could be terrorists posing as hackers. So, why not both?

I’m wondering if in the grand scheme of things this could be one more reason to speed up development of solar/wind + distributed energy production.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#404
post #83

In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…

> Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely target. This reminds me of the old saying about locking your bicycle on the street. It won't 100% prevent yours from being stolen, but if the other bikes around yours has less secure means of locking, then the thief will likely take those bikes instead of yours.

Another form: you don’t need to outrun the lion, just the guy next to you.

This also gets taken in dark directions: you don’t even need to run faster than the guy next to you, you just need to trip him up.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#405

Earlier quoted context omitted.

The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…

> The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Oh come on. It is just an excuse. Look up what FAANG pays for those jobs ( t…

That’s a pretty silly way to look at it. There are a lot of reasons, but the most obvious is that you just moved people around, you didn’t get any new ones. It’s zero sum in the short term, because there are many many years of latency to correct the talent pipeline on something like security.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#406

Earlier quoted context omitted.

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

Someone mentioned that these could be terrorists posing as hackers. So, why not both? I’m wondering if in the grand scheme of things this could be one more reason to speed up development of solar/wind + distributed energy production.

why would solar or wind have any better security, if the incentives for better security isn't really there in the first place?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#407
post #86

Earlier quoted context omitted.

The issue is less about people unwilling to take those wages, and more about a lack of people whose breath can even fog a security mirror so to speak. I work in security and have been involved with hiring at several “brand name” companies including FAANGs in hot tech markets, and it’s always been a talent pipeline issue more than anything. Given how difficult it is for the biggest players to keep security staffed up,…

The problem I see is that there are tradeoffs between security and usability, and again between developing security vs developing features. Security doesn't make money next quarter, while features and ease of use do. Any software engineer can do security if they spend time learning and working on it. But executives don't seem to care about it.

Weird to see this downvoted, it’s completely accurate and pretty basic economics. Security is a cost center, product development is a revenue multiplier. Investing in the latter as much as you can get away with is the most rational way to allocate resources.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#408
post #83

In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…

> Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely target. This reminds me of the old saying about locking your bicycle on the street. It won't 100% prevent yours from being stolen, but if the other bikes around yours has less secure means of locking, then the thief will likely take those bikes instead of yours.

[deleted]

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#409

Dumb question: why can’t crypto currencies and exchanges place the ransom tokens on some kind of blocklist, thereby forever tainting those coins? As I understand, the rise of “privacy wallets” has greatly increased the anonymity of such transactions. But, at the end of the day, don’t we always have a ledger of the coin ids? I’m curious how the coins actually get laundered back into cash.

Dumb question 2: How do you taint tokens when a "coin" is divided arbitrarily? As in, there are no minimum unit of a "coin"?

Since it’s a ledger, the coins can’t be poisoned, but you can poison the addresses (in traceable blockchains like Bitcoin, at least). At the bluntest level, refuse to transact with addresses that have received money from poisoned addresses, transitively. In practice you probably want to apply somewhat more nuanced rules, or the poison is far too likely to spread to the innocent. It could even be weaponised, by a poisoned address deliberately sending small amounts to addresses that it wishes to poison, since you can’t refuse to receive a transaction.

(Incidentally also, there is a minimum unit, at least in all currencies that I know of; Bitcoin, for example, goes to eight decimal places. But yeah, each unit doesn’t have physical identity like bank notes do. Infinite divisibility is bad for efficiency as it means your data types have unbounded memory usage, so you’d need to put together a bunch of rules about how far you actually can divide things, and it’s just not worth it.)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#410

Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…

And yet Scripps healthcare in California is going on more than a week of all of their IT systems being down for the same reason and it’s disrupting operations enough that they’re diverting a incoming patients to other providers and a lot of their patients have no way of finding out whether their already-schedules procedures will still happen.

Since healthcare is so heavily regulated it’ll be interesting to see what repercussions come of this. The company has been mostly silent on the matter despite it being severe enough that you can’t even get to their website.

Post reply on HN