Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

481–490 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#481
post #66

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

You don't need infosec staff to know that you should have backups of the data on your important computers/servers. Being hit by ransomware is not an indicator of total IT incompetence. Having no good options but to pay the ransom absolutely is. All ransomware is doing is exposing the existing hope-based DR plans (that is to say, lack thereof) in the industry.

Note that the attackers can also threaten to release data. Backups are no protection against that. They could also corrupt data and not tell you which part was corrupted and when, so even if you have backups you don't know which ones are corrupted unless you have some way of verifying all the data. One example of this would be to plant a backdoor, leave it in place and unused for months, then trigger the ransomeware encryption. The company decides not to pay, they restore from backup, and the attackers use the backdoor to encrypt it all again and demand even more. They could also use access to destroy hardware, say on a timer that triggers after the payment deadline. Backups won't protect against that if you can't get all your systems offline fast enough, or if taking them offline triggers the destruction.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#483
post #298

Earlier quoted context omitted.

From my experience. They will hire you but they won't pay your invoice until net-270

You're the second person who mentioned net-270 in this thread. What's the context?

It means you invoice and they pay after 270 days of receiving the invoice.

Basically the large oil firms know they hold all the cards so they regularly delay payment as long as possible.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#484

Earlier quoted context omitted.

Dumb question 2: How do you taint tokens when a "coin" is divided arbitrarily? As in, there are no minimum unit of a "coin"?

Since it’s a ledger, the coins can’t be poisoned, but you can poison the addresses (in traceable blockchains like Bitcoin, at least). At the bluntest level, refuse to transact with addresses that have received money from poisoned addresses, transitively. In practice you probably want to apply somewhat more nuanced rules, or the poison is far too likely to spread to the innocent. It could even be weaponised, by a pois…

> since you can’t refuse to receive a transaction.

Yeah I think this break your hypothesis.

Every single major account will just end up poisoned. Easily done by finding the addresses with most coins and sending them fractions of coins from tainted account. Tesla will be the first.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#485

Earlier quoted context omitted.

Since it’s a ledger, the coins can’t be poisoned, but you can poison the addresses (in traceable blockchains like Bitcoin, at least). At the bluntest level, refuse to transact with addresses that have received money from poisoned addresses, transitively. In practice you probably want to apply somewhat more nuanced rules, or the poison is far too likely to spread to the innocent. It could even be weaponised, by a pois…

> since you can’t refuse to receive a transaction. Yeah I think this break your hypothesis. Every single major account will just end up poisoned. Easily done by finding the addresses with most coins and sending them fractions of coins from tainted account. Tesla will be the first.

It doesn’t break the concept of poisoning, just the naive, trivial implementation of it. Major players in any sort of payment systems will absolutely be doing things like this, just with more complex rules and supporting analysis.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#486
We need a Foreign Corrupt Practices Act-style law against this. This payoff is going to fund so many more attacks.

I think this company was stupid in their security and unethical in their payoff practices.

Interesting to see if there will be a shareholder’s lawsuit because of the clear dollar amount of their error.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#487
post #308

I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…

This might work for your personal system, but in the corporate environment, what's to keep someone with legitimate system access from emptying the wallets periodically and blaming an advanced persistent threat? It would be better to do the same system with standard bank transactions, and just provide a promise to not prosecute people who make contact after pwning your company.

Since the wallets are canaries the rooted hosts will have to be rebuilt.

Also make the dollar amounts relatively low so an insider is unlikely to risk their position. $1000 is a lot to someone who doesn’t care but is foolish for someone who passed a security check to get access.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#488
post #349
post #334

Earlier quoted context omitted.

In 2019, ProPublica wrote how paying ransoms benefit insurance companies. They called this: "The extortion economy: How insurance companies are fueling a rise in ransomware attacks. Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom. Why? The attacks are good for business." [0] [0]: https://www.propublica.org/article/the-extortion-econom…

For such a long article it's (IMHO) a fairly naive view. Sure insurance companies make some profit, specially in the beginning but, eventually, the price gets higher and higher and the cost to secure becomes less than the cost of insurance. We had a similar issue with builder's insurance down here in Australia. It's was (and still is) cheaper to get insurance than build a quality building. Eventually that caught up w…

> a seperate corporate entity for each building

Hmm, so if buying a house, it can be good to first find out if this house is the only one the construction company has built

> insurance companies make some profit, specially in the beginning

I've gotten the impression that CEOs often don't plan much longer than any bonus program periods?

And, later when getting too expensive, can't they just then start telling the companies to use their backups instead.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#489

Earlier quoted context omitted.

Price of gold and silver is at its peak and people are buying it more than ever convinced it will somehow become extinct. The people who have money to hoard gas are also the people who have the money to hoard gas at double the price. These are not individuals with any knowledge of economics - theyre not doing it for trade, they're doing it out of belief.

We have to wait and see if future results justify current actions, when the action is preparation for some future event. It is only in hindsight that we can truly point out if someone's risk/reward calculation for the future was flawed. I'm not buying gold, but the odd thing is that Russian and Chinese central banks are. I would assume those people know a thing or two about economics. I'm curious to see what the futu…

Why would Russia and China central banks buy gold?

They’re already the #3 and #1 producing countries world-wide.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#490

Earlier quoted context omitted.

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

> being forced to pay penetration testers Hardware write-enable switches on the drives are 2 or 3 cents.

I remember wiring up firmware lock switches on paytv receivers. That brings me back.
Post reply on HN