Colonial Pipeline Paid Hackers Nearly $5M in Ransom
471–480 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#472Earlier quoted context omitted.
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
> These ransoms are net good...There are a lot of infrastructure teams taking security more seriously. Nonsense. This is not an academic exercise. Our country is being attacked by "nation states" (do more research) and we need to respond accordingly, treating it as the national security threat it is and making the perpetrators pay a heavy price. If they'd bombed our critical infrastructure, no one would be sitting ar…
With whom? And given that nation states have engaged in this sort of thing for years, and that the US/5-eyes/etc also engage in these activities, do you really want to turn a cyber/cold-war into a hot one?
The solution is defense-in-depth, with liability on the providers of software, which will require them to insure, which will raise prices, which will force them to address security as COGS which will force them to reduce their attack surfaces to reduce their insurance premiums.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#473Reminder that these same clowns have leaked over a million gallons of gasoline into a nature preserve in North Carolina. https://www.eenews.net/stories/1063725961
I really want to be supportive of pipelines as a better option than trains or trucks, but it's really hard to do when things like this don't result in enormous payouts against these companies. The US legal system is not capable enough to allow for large pipelines. Also, this and coal are the sort of stuff that nuclear replaces...
Nuclear is fine for baseload, but no good for anything else, costs a fortune, has huge externalized waste processing costs, and is inherently not fail-safe using actual deployed designs.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#474Earlier quoted context omitted.
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
These ransoms are funding the work of enemy nation states trying to cripple western nation states...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#475Earlier quoted context omitted.
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
I think you're kidding yourself if you think a company that gets "hacked" by off the shelf cryptoware is going to step up their game enough to have any chance of stopping a targeted state actor. The fact they caved so quickly tells me they are years away from a reasonable security posture.
Without widespread ransomware scammers, the risk of getting compromised is just theoretical, not tangible. Companies can get away with ignoring security concerns for a long time and might never be impacted by it.
Thus, companies which are paying a premium for better security might never be able to benefit from the mitigations they are implementing, and could be outcompeted by the companies which simply got lucky enough to avoid being attacked.
Eventually we end up with major too-big-to-fail megacorps like Equifax getting hacked by trivial exploits because nobody took advantage of them when they didn't have such a strong market position.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#476Earlier quoted context omitted.
>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…
Do corporations defend their factories with their own weapons?
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#477Earlier quoted context omitted.
Probably a reporter/reporting issue. No company that just have been hacked would run a binary received from the hackers in order to restore the systems, they cannot be that stupid. But then again, they did pay the ransom and also seemingly can't restore their systems from backups, so who knows how stupid they really are? More charitable reading is that the encryption key was sent over, and they started restoring with…
What? No, the ransomware people truly do send a decryption tool, or the decryption functionality is built into the ransomware. Do you think they are sending people some AES key and then everyone goes off and builds some python tool to decrypt his data? This is a fundamental misunderstanding of the ransomware business. The whole reason people pay up is because the hackers don't run and leave you hanging; if you pay th…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#478Earlier quoted context omitted.
Not if the hacker group is a nation state. Sure, small time hacking is cute and all, but the US isn’t going to just roll over and be all like “oh no, you hit critical infrastructure that had a big impact on peoples life. Carry on”
Even this time too government was aware that Colonial paid the Ransom. The question was asked in the Whitehouse press breifing, it was told that this is essentially a private sector matter, Government will not advice Colonial in this regard. Also they said it was Colonial's prerogative to decide and act. Transcript of Whitehouse Press Briefing: https://www.whitehouse.gov/briefing-room/press-briefings/202...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#479Dumb question: why can’t crypto currencies and exchanges place the ransom tokens on some kind of blocklist, thereby forever tainting those coins? As I understand, the rise of “privacy wallets” has greatly increased the anonymity of such transactions. But, at the end of the day, don’t we always have a ledger of the coin ids? I’m curious how the coins actually get laundered back into cash.
Basically tainting with FIFO.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#480Earlier quoted context omitted.
A price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.
Addressing legitimate problems of hardship can be dealt with from the other end, by channeling resources to those people. In the mean time, higher prices mean that supply isn't interrupted, and for the vast majority of people that means that you don't fill up your car and your wife's car and your lawnmower and a 55gal drum, because it's not worth it. You just skip a few trips and let your gas tank get below half a ta…
The reason, which is likely apparent to both of us and everyone reading this, is that such assistance would likely never be put in place, and the only help ordinary folks will have in the event of such an increase is wishful thinking.