Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

461–470 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#461
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

It is a scientific fact that there will be more of it. It's called operant conditioning. If you reward behavior, you get more of it.

If you think it's about the ransom though, think bigger. Can you even imagine how many billions of dollars silicon valley is going to make off it? They just paid Microsoft dozens of billions for some AR glasses.

How much for some software to prevent cyber terrorism? How much did TSA get to secure planes? $8 Billion/yr.

$18 Billion for border protection.

How much for cyber border protection? $100 Billion? Where will it go? Google? Microsoft? Palantir? Facebook? Twitter? Amazon?

Trillions.

They haven't even gotten started. $5 Million is pennies. Rounding error.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#462

Earlier quoted context omitted.

You know what's way more effective at stopping gas hoarding so it's available for someone who really wants/needs it? Doubling the price per gallon. Anti-price gouging laws caused the shortage, just like with toilet paper and PPE last year.

Price of gold and silver is at its peak and people are buying it more than ever convinced it will somehow become extinct. The people who have money to hoard gas are also the people who have the money to hoard gas at double the price. These are not individuals with any knowledge of economics - theyre not doing it for trade, they're doing it out of belief.

> The people who have money to hoard gas are also the people who have the money to hoard gas at double the price.

But then the outcome would not have changed, the people who hoard will be worse off, the people who produce a valuable commodity will be better off and there is incentive for people to contingency plan and have gas reserves for when things get tight.

That is a strict improvement. Plus, you're probably being overly pessimistic - people will stop hoarding once the price gets high enough. The shelves would not be bare.

> These are not individuals with any knowledge of economics - theyre not doing it for trade, they're doing it out of belief.

The people with knowledge of economics don't have much of an advantage though, do they? When has an official body ever been banging the drum before a major crisis issuing panicked warnings? Every crisis it turns out all the people held up as experts had grossly misread the situation.

People with knowledge of economics often get bowled under by people with a knowledge of politics or of statistics when it comes to trading.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#463

Earlier quoted context omitted.

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

I don’t know. Did any of it matter? It was bad when people started hoarding gas. Just a few unfathomably stupid people - as always in this country. If idiots didn’t hoard gas, nothing would really have gone wrong. The preppers are the other side of the same coin. The only thing they seem to never run out of is toilet paper. Who the fuck cares? Pentesters have the same energy. They tell you about what software not to…

>I don’t know. Did any of it matter

I bet a lot of companies, including Colonial, are investing more in security, including hiring more people for security.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#464
post #50

Earlier quoted context omitted.

I am curious what your thoughts are on other commenters making as if it is possible to prevent these types of attacks by just taking security 'more seriously'. My guess is that you know that no matter how much is spent with a large entity and many employees it's near impossible to prevent this type of attack. People make mistakes people are easily fooled people don't follow what they are told to do and so on. I can't…

It's certainly possible to achieve serious security but probably not practical for most private entities. I've spent most of my development career making software for the US intelligence community and their systems were definitely not going to get broken into by a ransomware gang. Security measures include multilevel air gapping plus heavily armed physical security, six foot thick concrete walls set back from the str…

Thank you - this is the closest I have read on this thread as to the real security practises we will need in the future - if you can elaborate more that will be helpful.

Are these (i suspect not) published anywhere as "Three letter agency network security standards"?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#465

Earlier quoted context omitted.

> I think you're kidding yourself if you think a company that gets "hacked" by off the shelf cryptoware is going to step up their game enough Still, this might lead to their first solid security hire that can bring about change in the form of zero-trust principles, security in depth, etc. > to have any chance of stopping a targeted state actor. Given unlimited resources, interest and budget, no participant in the mod…

No single participant has a significant chance, but if each target becomes more expensive on average, then state actors can only afford less targets, which makes the society as a whole more resilient. And if one target is so critical that it could take out a society, perhaps it would be better to either 1. Make it so minimalistic that it can be fully audited and secured or 2. Broken into smaller pieces and decentrali…

Also, making society and individuals more prepared and ready to deal with no-more-oil for a while, situations.

E.g. warm blankets at home, and food that doesn't need to be boiled, if cannot heat the house because the oil and electricity system is broken for a while?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#466
post #25

Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…

If the attackers had full access, they probably broke into the financial systems, issued the bitcoin transactions and paid themselves directly. I mean, why bother going through the hassle of trying to teach people how to do all of that stuff?

There are other stakeholders involved in a transaction like this, most importantly banks. Payments, especially large ones, are heavily regulated. You cannot hack a finance department and issue a monero transaction of that size without triggering a lot of alarm bells.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#468
post #50
post #25

Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…

I am curious what your thoughts are on other commenters making as if it is possible to prevent these types of attacks by just taking security 'more seriously'. My guess is that you know that no matter how much is spent with a large entity and many employees it's near impossible to prevent this type of attack. People make mistakes people are easily fooled people don't follow what they are told to do and so on. I can't…

If there’s a business need, you can secure a wooden box on the sidewalk in a way, that it is almost impossible to break in. It will be very costly, but if profit or IP depends on it, one can find a way. Taking cyber security „seriously“ always depends on who you see as a potential attacker. I don’t think any corporation on the planet has the capacity or willingness to really protect itself against dedicated state actors. This does not include ransomware gangs that are not prosecuted by the Russian Federation or DPRK, but highly specialized forces within the usual intelligence services.

The types of ransomware attacks we see today might not be preventable as well, every company on the planet will get or was already hit. But, the difference between the attacks: the amount of damage. If money is spent on security, that amount will certainly be smaller.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#469

Earlier quoted context omitted.

Re. this group doing its research: one of my past employers got hit by a patent troll C&D demand, threatening to sue. It was clearly bogus but also clearly enough of a hassle that the company didn’t want to pick the fight if one could be avoided. Our clients were actually throwing their support behind us fighting it, offering their legal resources. But at the end of the day what the higher ups told us is that this pa…

When I was young my father had a new company in a industry that was known for lawsuits. The first came came in and I looked at it and said settle. He said no F’ing way. We won. Even with winning the legal fees, the cost in manhours was more then settling. Then the next one hit. Did not settle and won……and so on. After about 3 years no more lawsuits. His reputation was never settle and the trolls moved on. Never negot…

You're correct

This lesson should have been learned at school. If you give in to the bully you get exploited more.

Sure it's more work to fight. But it makes sure you're not abused so much.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#470

Earlier quoted context omitted.

Are there enough Infosec people to fill every open job for it in the USA? I would imagine that it is like software development, where the unemployed software devs are the kind that can't figure out git.

I doubt there are enough infosec people which means in theory that compensation should rise which will then attract more people into the field. Until they're trained and experienced, whoever provides the best place to work (compensation and intangibles that lead to satisfaction) would get the help they need while others would be more vulnerable to attack. But from what I've seen, this isn't happening. There's lots of…

What would be the solution to this?

If I’m a leader in a company with a culture and intangibles not yet optimized for the people working in the infosec roles, how would I aproach changing the environment for the better?

Is it viable to cooperate with other companies to share best practices? Wouldn’t they hesitate to share?

Would doing deep interviews with potential employees get me the right information?

Would some hr consultancy provide this info? Arent’t they too old-fashioned for this field yet?

Post reply on HN