Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

521–524 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#521
post #103
post #89

Earlier quoted context omitted.

I don't think people here are considering all forms of ransoms, but you hit on an interesting aspect of it all the same. It's why, I think, such a law wouldn't pass Constitutional review. If your person is threatened with imminent danger, you have a right to self-defense, we'll even let you commit intentional homicide if the threat is serious enough. And self-defense also covers your property and livelihood to a less…

The US Constitution contains no explicit right to self defense. There are a variety of state and federal laws covering justifiable use of force but none of them are even remotely applicable to paying ransoms. If you disagree then please cite a specific legal case. https://www.natlawreview.com/article/us-government-warns-com...

US law derived from common law, which recognized a right to self defense. All 50 states, DC, and federal jurisdictions then codified that right as law. While the 2A is not directly about self-defense, it plainly guarantees an individual right to maintain the means for self-defense, which implies a right to self-defense.

There are cases covering a justifiable use of force because intentionally killing or harming a person is illegal, and self-defense is a defense against those charges.

It's normally perfectly legal to pay someone whatever you want. You don't need a defense against something that's not a crime. There's no conflict in paying a ransom, so there's no case law.

Regarding OFAC, as your link points out:

> One issue is that victim organizations are required to check the list of sanctioned entities; however, many times the true identity of the cybercriminals are not known.

I'm guessing there's no case law regarding paying ransoms to SDNs because nobody has an identity they can check.

But do we need case law when OFAC says:

> OFAC will consider a company’s self-initiated, timely and complete report of a ransomware attack to law enforcement to be a significant mitigating factor in determining the enforcement outcome if the situation is determined to have a sanctions nexus.

If someone wanted to make a law against paying ransom, it would be quite novel and courts would have to look for applicable doctrine. I think the doctrine of self-defense would be a roadblock.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#522

Earlier quoted context omitted.

It certainly will fund them to go stronger in the future. (And now invents bad behavior even more) The challenge is this isn’t this Colonial’s problem. It’s the next one. At some point it will wake up the authorities to go after them more seriously too.

Hardly, they regularly take much more than this. This is an organized criminal enterprise, I just read through a chatlog where they got $12 million and this is just one of many. $5m was 100% a lowball because of the geopolitical implications of this attack.

Interesting. I hadn’t realized that the quiet payoffs were so high.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#523

Earlier quoted context omitted.

These ransoms are funding the work of enemy nation states trying to cripple western nation states...

$5M is less than coffee money for a nation state

It adds up quickly. For North Korea the revenue from "criminal enterprises", including hacking and ransomware, are a valuable source of foreign currency.

At the very least, $5M seems a good start to fund an ongoing effort at developing cyber attack capabilities.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#524

Earlier quoted context omitted.

Your metaphor works both ways: the ability to fit billions of records in a shoebox means that it’s perfectly manageable to keep another shoebox as a backup, under independent control.

So now there are two shoeboxes. Hasn’t solved exfiltration. In fact, you’ve just doubled the risk. There may not be a solution if the problem is untrustworthy people. The custodians of your ‘independent control’ will eventually get ransomwared themselves. Then what? It’s like cash... If you are a sophisticated criminal, do you waste time burglarizing individuals? Or, do you rob the bank where the individuals keep the…

I thought we were talking about denying access to important files. Data exfiltration is a different threat model than what I was addressing.
Post reply on HN