Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

421–430 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#421
post #308

I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…

This might work for your personal system, but in the corporate environment, what's to keep someone with legitimate system access from emptying the wallets periodically and blaming an advanced persistent threat? It would be better to do the same system with standard bank transactions, and just provide a promise to not prosecute people who make contact after pwning your company.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#422
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

Security professionals need to start getting serious about demanding physical write-enable switches to all embedded systems, so malware won't survive a reboot.

Backup media must be append-only unless a physical write-enable switch is pressed.

Physical write-enable switches used to be standard.

I'm not buying the crazy argument that remote update is necessary to remove malware installed using remote update.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#423

Earlier quoted context omitted.

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

> being forced to pay penetration testers

Hardware write-enable switches on the drives are 2 or 3 cents.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#424

Earlier quoted context omitted.

You know what's way more effective at stopping gas hoarding so it's available for someone who really wants/needs it? Doubling the price per gallon. Anti-price gouging laws caused the shortage, just like with toilet paper and PPE last year.

A price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.

You can't buy gas that isn't there. Anti-gouging laws simply result in no gas available.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#425

Earlier quoted context omitted.

Is being a "good" security person really more involved than: * making sure you have all your ports locked down * limit connectivity between all instances to only the bare minimum * any public access is via protocols such as ssh which have zero-to-none vulnerabilities * any 3rd party software you dont know is secure should never be public * routinely run employee training on how not to let themselves get hacked via so…

I'm sorry, but this just doesn't work in the real-world. As the "security guy", you're seen as the troll under the bridge. Someone to get past via any means necessary, including lying. But lets say you get your way. "making sure you have all your ports locked down" You can't imagine how much work this actually is on a network with 1,000+ servers running at least 10,000 distinct pieces of software. Most of which don't…

Thanks for the great response! Very informative. I assumed I was way simplifying the problem. It seems like what works for my small remote only startup is not even close to what you need for a large in-person org running who-knows-what software.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#426

Earlier quoted context omitted.

Is being a "good" security person really more involved than: * making sure you have all your ports locked down * limit connectivity between all instances to only the bare minimum * any public access is via protocols such as ssh which have zero-to-none vulnerabilities * any 3rd party software you dont know is secure should never be public * routinely run employee training on how not to let themselves get hacked via so…

Yes, it is a lot more involved. In particular, "routinely run training" might reduce the probability of a breach due to social engineering, but it probably won't. You also didn't really cover client machine security, which is how compromises often happen. Your awesome security isn't worth much if the admin's machine is compromised. Your employees need to use computers to do their job. As part of that, they will need…

Thanks for the great response! Very informative. I assumed I was way simplifying the problem. It seems like what works for my small remote only startup is not even close to what you need for a large in-person org running who-knows-what software.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#427

Earlier quoted context omitted.

>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…

Do corporations defend their factories with their own weapons?

Well, they can. Interesting thought.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#428

Earlier quoted context omitted.

So they'll be out of business sooner or later then and a company that follows security best practices will take over ideally.

Yes, "ideally" that's what would happen. Do you really expect that to happen in practice?

Well, fines are a fixed cost, the risk can be calculated and offset against a bonus. A ransom has an unknown downside. I'd imagine most ransoms would be priced to likely get paid, but ransomers don't really know the biz inside and out, so they might guess a painful or fatal price. but that's a one time cost. the lost revenue is the killer.

I'd expect there will be some serious talks about how much to pay to prevent things like this. 5 million, once? Meh, why bother taking security seriously? I suspect the lost revenue is tougher to swallow.

I dunno. you gotta pay every month forever, for protection against maybe something bad happening someday? It's an insurance premium, but you don't get made whole.

I guess, I'd expect companies to start paying a little for infrastructure so they can buy good insurance policies. backups would get you a lot.

It'll be interesting.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#429
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

I’m on the fence. I definitely see your point, it’s solid. But I also think this (even only 5 million) incentivizes more of the same. It’s no stretch to see we’re in for an increasing amount of this.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#430
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

We have been in a less than ideal evolutionary equilibrium with respect to security: in the short term, companies that don't fund security can outcompete the prices of companies that do fund security, but they leave themselves vulnerable long-term to attackers.

This is analogous to overspecialization in an ecological niche where there was no predation.

As ransomware becomes more widespread, it becomes more and more detrimental to companies to pursue short-term security savings. That's good for everyone.

Post reply on HN