It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
You don't need infosec staff to know that you should have backups of the data on your important computers/servers. Being hit by ransomware is not an indicator of total IT incompetence. Having no good options but to pay the ransom absolutely is. All ransomware is doing is exposing the existing hope-based DR plans (that is to say, lack thereof) in the industry.
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
481–490 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#482Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#483Earlier quoted context omitted.
From my experience. They will hire you but they won't pay your invoice until net-270
You're the second person who mentioned net-270 in this thread. What's the context?
Basically the large oil firms know they hold all the cards so they regularly delay payment as long as possible.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#484Earlier quoted context omitted.
Dumb question 2: How do you taint tokens when a "coin" is divided arbitrarily? As in, there are no minimum unit of a "coin"?
Since it’s a ledger, the coins can’t be poisoned, but you can poison the addresses (in traceable blockchains like Bitcoin, at least). At the bluntest level, refuse to transact with addresses that have received money from poisoned addresses, transitively. In practice you probably want to apply somewhat more nuanced rules, or the poison is far too likely to spread to the innocent. It could even be weaponised, by a pois…
Yeah I think this break your hypothesis.
Every single major account will just end up poisoned. Easily done by finding the addresses with most coins and sending them fractions of coins from tainted account. Tesla will be the first.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#485Earlier quoted context omitted.
Since it’s a ledger, the coins can’t be poisoned, but you can poison the addresses (in traceable blockchains like Bitcoin, at least). At the bluntest level, refuse to transact with addresses that have received money from poisoned addresses, transitively. In practice you probably want to apply somewhat more nuanced rules, or the poison is far too likely to spread to the innocent. It could even be weaponised, by a pois…
> since you can’t refuse to receive a transaction. Yeah I think this break your hypothesis. Every single major account will just end up poisoned. Easily done by finding the addresses with most coins and sending them fractions of coins from tainted account. Tesla will be the first.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#486I think this company was stupid in their security and unethical in their payoff practices.
Interesting to see if there will be a shareholder’s lawsuit because of the clear dollar amount of their error.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#487I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…
This might work for your personal system, but in the corporate environment, what's to keep someone with legitimate system access from emptying the wallets periodically and blaming an advanced persistent threat? It would be better to do the same system with standard bank transactions, and just provide a promise to not prosecute people who make contact after pwning your company.
Also make the dollar amounts relatively low so an insider is unlikely to risk their position. $1000 is a lot to someone who doesn’t care but is foolish for someone who passed a security check to get access.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#488Earlier quoted context omitted.
In 2019, ProPublica wrote how paying ransoms benefit insurance companies. They called this: "The extortion economy: How insurance companies are fueling a rise in ransomware attacks. Even when public agencies and companies hit by ransomware could recover their files on their own, insurers prefer to pay the ransom. Why? The attacks are good for business." [0] [0]: https://www.propublica.org/article/the-extortion-econom…
For such a long article it's (IMHO) a fairly naive view. Sure insurance companies make some profit, specially in the beginning but, eventually, the price gets higher and higher and the cost to secure becomes less than the cost of insurance. We had a similar issue with builder's insurance down here in Australia. It's was (and still is) cheaper to get insurance than build a quality building. Eventually that caught up w…
Hmm, so if buying a house, it can be good to first find out if this house is the only one the construction company has built
> insurance companies make some profit, specially in the beginning
I've gotten the impression that CEOs often don't plan much longer than any bonus program periods?
And, later when getting too expensive, can't they just then start telling the companies to use their backups instead.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#489Earlier quoted context omitted.
Price of gold and silver is at its peak and people are buying it more than ever convinced it will somehow become extinct. The people who have money to hoard gas are also the people who have the money to hoard gas at double the price. These are not individuals with any knowledge of economics - theyre not doing it for trade, they're doing it out of belief.
We have to wait and see if future results justify current actions, when the action is preparation for some future event. It is only in hindsight that we can truly point out if someone's risk/reward calculation for the future was flawed. I'm not buying gold, but the odd thing is that Russian and Chinese central banks are. I would assume those people know a thing or two about economics. I'm curious to see what the futu…
They’re already the #3 and #1 producing countries world-wide.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#490Earlier quoted context omitted.
Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.
> being forced to pay penetration testers Hardware write-enable switches on the drives are 2 or 3 cents.