Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

431–440 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#431
1. Never negotiate with terrorist 2. Never negotiate with terrorist 3. Life in prison required sentences for those convicted of these crimes 4. Death penalty for those convicted when hack results in a death (like hospital hack) 5. Zero statute of limitations on these crimes 6. State actors engaged in this get economic death penalty - 100% cut off from world banks, markets. 7. No insurance coverage for companies that suffer these hacks. They need to get their stuff sorted.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#432

Earlier quoted context omitted.

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

Company: Well this is a painful lesson Me: Only if you learn it. Penetration testing is part of a security program. If you don't have a security program, penetration "testing" isn't useful whether it's painful or not. Haves the careers or investments of anyone significant who brought things to this point been screwed? If not, nothing will change.

>> Me: Only if you learn it.

As someone with a lot of friends and co-workers who are on the info-sec side, the stories I repeatedly hear of how many times they visit the same company year/year and little if anything is done to harden their networks, and impose stricter security on their users is way more common than it should be.

Most, if not all of these networks should be taken offline and siloed, but you know that won't happen now, the genie is out of the bottle. If they did, it would create a much smaller attack surface for critical infrastructure. As it sits now? Doubtful we would go back to that world.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#433

Earlier quoted context omitted.

A price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.

You can't buy gas that isn't there. Anti-gouging laws simply result in no gas available.

And rationing can address that problem. These complex issues are never so simple.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#434

Earlier quoted context omitted.

You can't buy gas that isn't there. Anti-gouging laws simply result in no gas available.

And rationing can address that problem. These complex issues are never so simple.

Then you get a black market... it's almost a cobra effect.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#435

Earlier quoted context omitted.

You can't buy gas that isn't there. Anti-gouging laws simply result in no gas available.

And rationing can address that problem. These complex issues are never so simple.

Rationing makes simple things complex. For example, rationing assumes that everyone has exactly the same need. Trying to fix that is hopelessly complicated.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#437

Earlier quoted context omitted.

That has nothing to do with this the FBI presumably cannot enforce security on a company. Maybe for some industries they need to start mandating Security Clearances and background checks and no outsourcing of certain critical systems work.

I am not familiar with any details of this hack that could point to employees or contractors. Also, I am not sure what exactly are the roles of FBI and NSA when it comes to protecting US infrastructure, can you clarify?

I am not a Natsec expert - and where does "employees or contractors. " come into this?

I was suggesting that certain industries would have to be stricter in future in who they hire for sensitive roles.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#438

Dumb question: why can’t crypto currencies and exchanges place the ransom tokens on some kind of blocklist, thereby forever tainting those coins? As I understand, the rise of “privacy wallets” has greatly increased the anonymity of such transactions. But, at the end of the day, don’t we always have a ledger of the coin ids? I’m curious how the coins actually get laundered back into cash.

Because of fungibility.

Bitcoin is not fungible because the full transaction history of every single bitcoin is available publicly. This means you can discriminate against specific coins because they were at some point involved in undesirable activity. Exchanges already reject these tainted coins. Even using a mixing service for privacy's sake is enough to taint them.

On the other hand, we have fungible coins such as Monero. It's impossible to tell where the coins are coming from so there's no way to discriminate based on the source of the coin. Their only option is to stop trading XMR as a whole.

On the Monero blockchain it's not even possible to find people's wallet addresses. Interestingly, on the US treasury sanctions list a transaction hash appears as if it was an address:

https://www.treasury.gov/ofac/downloads/sdnlist.txt

> Digital Currency Address - XMR 5be5543ff73456ab9f2d207887e2af87322c651ea1a873c5b25b7ffae456c320;

Note the lack of the 0x prefix. Here's the transaction on the block explorer:

https://localmonero.co/blocks/search/5be5543ff73456ab9f2d207...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#439

Earlier quoted context omitted.

The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…

Re. this group doing its research: one of my past employers got hit by a patent troll C&D demand, threatening to sue. It was clearly bogus but also clearly enough of a hassle that the company didn’t want to pick the fight if one could be avoided. Our clients were actually throwing their support behind us fighting it, offering their legal resources. But at the end of the day what the higher ups told us is that this pa…

When I was young my father had a new company in a industry that was known for lawsuits. The first came came in and I looked at it and said settle. He said no F’ing way. We won. Even with winning the legal fees, the cost in manhours was more then settling. Then the next one hit. Did not settle and won……and so on. After about 3 years no more lawsuits. His reputation was never settle and the trolls moved on.

Never negotiate with terrorist. As long as they feel there is a chance they will get paid it never stops. Burn it to the ground, but do not give in.

Post reply on HN