Earlier quoted context omitted.
I agree. I’d give 60% odds that there is at least one significant attack (ransomware plus shutdown) on US power grids in the next 18 months.
Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
411–420 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#412Earlier quoted context omitted.
Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.
I don’t know. Did any of it matter? It was bad when people started hoarding gas. Just a few unfathomably stupid people - as always in this country. If idiots didn’t hoard gas, nothing would really have gone wrong. The preppers are the other side of the same coin. The only thing they seem to never run out of is toilet paper. Who the fuck cares? Pentesters have the same energy. They tell you about what software not to…
Maybe. But, I tend to lay the blame with the foreign criminals/adversaries who attacked us rather than a panicky handful of my fellow country people.
Not sure why some here are blaming the victims while giving the criminals a pass, and even thanking them as if unsolicited, live pentesting on critical infrastructure with a side order of extortion is a good thing.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#413Earlier quoted context omitted.
Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions
The government seems to have no problem with utilities doing this or worse to their own customers (PG&E, Texas power grid, Flint Michigan). But I guess if they could blame a foreign power that's an opportunity for a profitable war.
The “utility" acting in Flint was state and state-imposed local government officials, 9 of whom have been criminally indicted for their role, so manifestly the government has something of a problem with it.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#414The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
The fact they caved so quickly tells me they are years away from a reasonable security posture.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#415Earlier quoted context omitted.
>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…
Agree. The govt need not provide the teams as they must compete for talent like anyone else and don't have much to spare. The govt only has a relative abundance of talent [largely interspersed with its contractors] in highly regulated activites like making nuclear weapons, where private entities don't participate.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#416The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#417Earlier quoted context omitted.
I might agree if I had any faith that the people who paid this ransom would do any more than the bare minimum to close this one specific vulnerability and nothing else.
So they'll be out of business sooner or later then and a company that follows security best practices will take over ideally.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#418Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#419Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…
Having read the release by the attacker, my initial thought is that the immediacy of paying was probably due to the threat of the release of sensitive data, not the ability to restore operations. I’m sitting here wondering what exactly about the release of their financials and internal procedures prompted them to immediately pay $4-5m in the hopes of preventing it from happening?
If the threat was to release sensitive information, surely the firm would be asking the attackers for details of the sensitive information they claim to have.
If the attackers come back with nothing then it was just a bluff.
However if the attackers come back with real information then paying the ransom is just stupid, as the attacker still have the sensitive information and can repeat the payment demands ad infinitum.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#420Earlier quoted context omitted.
A price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.
Addressing legitimate problems of hardship can be dealt with from the other end, by channeling resources to those people. In the mean time, higher prices mean that supply isn't interrupted, and for the vast majority of people that means that you don't fill up your car and your wife's car and your lawnmower and a 55gal drum, because it's not worth it. You just skip a few trips and let your gas tank get below half a ta…