Earlier quoted context omitted.
A price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.
Addressing legitimate problems of hardship can be dealt with from the other end, by channeling resources to those people. In the mean time, higher prices mean that supply isn't interrupted, and for the vast majority of people that means that you don't fill up your car and your wife's car and your lawnmower and a 55gal drum, because it's not worth it. You just skip a few trips and let your gas tank get below half a ta…
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
501–510 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#502The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
It certainly will fund them to go stronger in the future. (And now invents bad behavior even more) The challenge is this isn’t this Colonial’s problem. It’s the next one. At some point it will wake up the authorities to go after them more seriously too.
$5m was 100% a lowball because of the geopolitical implications of this attack.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#503Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#504Earlier quoted context omitted.
But the pipeline has been closed: https://abc11.com/business/theres-plenty-of-gas-in-the-us-th... And the toilet paper shortage was not purely panic-driven. People did shit at work before the pandemic, and that part of demand switched to a different supply chain. The panic-induced bullwhip was probably stronger than the original demand spike, but the whole thing wasn't just memed into existence.
The pipeline was shut down as a preventive measure (we're being told) just in case the attackers had made their way into the control systems. Trucking of gas has been increased to compensate for the closure of the pipeline, and there was emergency legislation passed in Congress to lift regulations that would have prevented these higher levels of trucking. The gas supply has been just fine here in the Northeast; the i…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#505Earlier quoted context omitted.
I really want to be supportive of pipelines as a better option than trains or trucks, but it's really hard to do when things like this don't result in enormous payouts against these companies. The US legal system is not capable enough to allow for large pipelines. Also, this and coal are the sort of stuff that nuclear replaces...
It's also the sort of stuff that renewables and EVs and batteries (EVs = mobile batteries) replace. Nuclear is fine for baseload, but no good for anything else, costs a fortune, has huge externalized waste processing costs, and is inherently not fail-safe using actual deployed designs.
Regarding base load, my suspicion is that SMRs inherently accommodate transients better because leakage becomes a bigger factor and starts to compete with poisoning effectively, so maybe you get more bang for your buck out of influencing the moderator. Regardless, even if it's only ever good for base load, that's a lot of ground nuclear could still cover in the US.
Finally, the cost of nuclear comes mostly from the aggressive safety standards. There's space to fix some of that (enormous cost to the fact that radiation workers typically experience less exposure than aircrews) and also space to acknowledge that we're lowballing standards in fossil fuels, with pipeline leaks and ransomware compromise being easy examples. That's before you talk about the pollution released by fossil fuels, including the radioactive contamination released by mining and burning coal.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#506> Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said. I thought the protocol for these attacks was to send the decryption keys, not provide a "decrypting tool." If some kind of softwa…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#507Earlier quoted context omitted.
Yeah, but now there is also a massive bounty out for these hackers. Money needs to get out at some point and that's when they'll get nailed.
Unfortunately these types of breaches don't net the culprits nearly as expeditiously as we'd all like. Given that they're likely based in a country that could care less or may be adversarial to the US this may even be lauded. In the grand scheme of things it's very low likelihood we'll see any level of prosecution for this incident in the next year or two, if ever. And even then it will likely only result in attribut…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#508Earlier quoted context omitted.
What about when the cost of having the data exposed to the public is higher than that of recovery
Yeah, I was pushing that all under "recovery." Say it all sums to $C. Arguably the bigger problem is you don't know that the ransomer will actually give you a valid key, but suppose you guess a likelihood P that they do. Now you have some scenarios: 1. Don't pay. We're out $C. 2. Do pay, and get a valid key. We're out $R. 3. Do pay, and get no key. We're out $R + $C. So the limit is at scenario 1 being equal to the c…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#509I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was" Rotate the keys periodically and sweep all unstolen…
This might work for your personal system, but in the corporate environment, what's to keep someone with legitimate system access from emptying the wallets periodically and blaming an advanced persistent threat? It would be better to do the same system with standard bank transactions, and just provide a promise to not prosecute people who make contact after pwning your company.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#510Earlier quoted context omitted.
>> Me: Only if you learn it. As someone with a lot of friends and co-workers who are on the info-sec side, the stories I repeatedly hear of how many times they visit the same company year/year and little if anything is done to harden their networks, and impose stricter security on their users is way more common than it should be. Most, if not all of these networks should be taken offline and siloed, but you know that…
1. Any system can be hacked. We don't know enough to judge Colonial's infosec posture. 2. Agree that paying leads to bad outcomes. But I also suspect the feds put some pressure on Colonial. Voters remember gas lines and the pump prices.
This was my thought was as well. I thought they were in on this before it hit the public media. For me, it was like in the movies when the feds are trying to tap the line and the person is trying to keep the bad guy on the line as long as possible so they can trace the call?
My theory is the feds encouraged Colonial to string it out in order for them to get as much information on the hacking team as possible. From what we're seeing now (bitcoin seized, servers seized) it sounds like the Feds have them nailed pretty good and their gamble paid off.