Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

501–510 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#501

Earlier quoted context omitted.

A price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.

Addressing legitimate problems of hardship can be dealt with from the other end, by channeling resources to those people. In the mean time, higher prices mean that supply isn't interrupted, and for the vast majority of people that means that you don't fill up your car and your wife's car and your lawnmower and a 55gal drum, because it's not worth it. You just skip a few trips and let your gas tank get below half a ta…

What crazypants world do you live in where the vast majority of people have all that excess, but the poor are in the minority?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#502
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

It certainly will fund them to go stronger in the future. (And now invents bad behavior even more) The challenge is this isn’t this Colonial’s problem. It’s the next one. At some point it will wake up the authorities to go after them more seriously too.

Hardly, they regularly take much more than this. This is an organized criminal enterprise, I just read through a chatlog where they got $12 million and this is just one of many.

$5m was 100% a lowball because of the geopolitical implications of this attack.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#504

Earlier quoted context omitted.

But the pipeline has been closed: https://abc11.com/business/theres-plenty-of-gas-in-the-us-th... And the toilet paper shortage was not purely panic-driven. People did shit at work before the pandemic, and that part of demand switched to a different supply chain. The panic-induced bullwhip was probably stronger than the original demand spike, but the whole thing wasn't just memed into existence.

The pipeline was shut down as a preventive measure (we're being told) just in case the attackers had made their way into the control systems. Trucking of gas has been increased to compensate for the closure of the pipeline, and there was emergency legislation passed in Congress to lift regulations that would have prevented these higher levels of trucking. The gas supply has been just fine here in the Northeast; the i…

Preventive measures shouldn't be creating third-world-level shortages in basic supplies; those things are dangerous themselves. I'm not sure where the Northeast ends for you, but DC seems to have had serious shortages as late as 2 days ago: https://twitter.com/GasBuddyGuy/status/1392467605898907652

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#505
post #473

Earlier quoted context omitted.

I really want to be supportive of pipelines as a better option than trains or trucks, but it's really hard to do when things like this don't result in enormous payouts against these companies. The US legal system is not capable enough to allow for large pipelines. Also, this and coal are the sort of stuff that nuclear replaces...

It's also the sort of stuff that renewables and EVs and batteries (EVs = mobile batteries) replace. Nuclear is fine for baseload, but no good for anything else, costs a fortune, has huge externalized waste processing costs, and is inherently not fail-safe using actual deployed designs.

I agree that this is something that EVs and batteries could replace, but if your baseload is coming from oil, all you've done is transfer the combustion to a more efficient central site and then sent the power through the grid.

Regarding base load, my suspicion is that SMRs inherently accommodate transients better because leakage becomes a bigger factor and starts to compete with poisoning effectively, so maybe you get more bang for your buck out of influencing the moderator. Regardless, even if it's only ever good for base load, that's a lot of ground nuclear could still cover in the US.

Finally, the cost of nuclear comes mostly from the aggressive safety standards. There's space to fix some of that (enormous cost to the fact that radiation workers typically experience less exposure than aircrews) and also space to acknowledge that we're lowballing standards in fossil fuels, with pipeline leaks and ransomware compromise being easy examples. That's before you talk about the pollution released by fossil fuels, including the radioactive contamination released by mining and burning coal.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#506
post #31

> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…

It could be something as simple as decrypting some files with PGP or some open source tool

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#507

Earlier quoted context omitted.

Yeah, but now there is also a massive bounty out for these hackers. Money needs to get out at some point and that's when they'll get nailed.

Unfortunately these types of breaches don't net the culprits nearly as expeditiously as we'd all like. Given that they're likely based in a country that could care less or may be adversarial to the US this may even be lauded. In the grand scheme of things it's very low likelihood we'll see any level of prosecution for this incident in the next year or two, if ever. And even then it will likely only result in attribut…

Check front page of HN :)

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#508
post #81
post #40

Earlier quoted context omitted.

What about when the cost of having the data exposed to the public is higher than that of recovery

Yeah, I was pushing that all under "recovery." Say it all sums to $C. Arguably the bigger problem is you don't know that the ransomer will actually give you a valid key, but suppose you guess a likelihood P that they do. Now you have some scenarios: 1. Don't pay. We're out $C. 2. Do pay, and get a valid key. We're out $R. 3. Do pay, and get no key. We're out $R + $C. So the limit is at scenario 1 being equal to the c…

I mean them publishing your data not you getting it back

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#509
post #308

I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…

This might work for your personal system, but in the corporate environment, what's to keep someone with legitimate system access from emptying the wallets periodically and blaming an advanced persistent threat? It would be better to do the same system with standard bank transactions, and just provide a promise to not prosecute people who make contact after pwning your company.

Well, presumably the rest of the team would push for increased monitoring and access control until coworker was no longer confident they could steal the bonus without getting caught, at which point your systems have been hardened and risk from outside attackers is also probably reduced. But, I'm definitely getting into 'hand wavy' territory here.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#510

Earlier quoted context omitted.

>> Me: Only if you learn it. As someone with a lot of friends and co-workers who are on the info-sec side, the stories I repeatedly hear of how many times they visit the same company year/year and little if anything is done to harden their networks, and impose stricter security on their users is way more common than it should be. Most, if not all of these networks should be taken offline and siloed, but you know that…

1. Any system can be hacked. We don't know enough to judge Colonial's infosec posture. 2. Agree that paying leads to bad outcomes. But I also suspect the feds put some pressure on Colonial. Voters remember gas lines and the pump prices.

>> But I also suspect the feds put some pressure on Colonial

This was my thought was as well. I thought they were in on this before it hit the public media. For me, it was like in the movies when the feds are trying to tap the line and the person is trying to keep the bad guy on the line as long as possible so they can trace the call?

My theory is the feds encouraged Colonial to string it out in order for them to get as much information on the hacking team as possible. From what we're seeing now (bitcoin seized, servers seized) it sounds like the Feds have them nailed pretty good and their gamble paid off.

Post reply on HN