9 ms·
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy n
by DevX101 5y ago
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with.
There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
- bostonsre 5y agoYea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.
- joe_the_user 5y agoCompany: Well this is a painful lesson Me: Only if you learn it. Penetration testing is part of a security program. If you don't have a security program, penetration "testing" isn't useful whether it's painful or not. Haves the careers or investments of anyone significant who brought things to this point been screwed? If not, nothing will change.
- bostonsre 5y agoI think ransomware gangs will be emboldened and more will go after bigger targets. I also think ransom demands will grow and insurance premiums will continue to grow as well. I'm hoping there is some attainable point where it makes financial sense to practice good security.
- at-fates-hands 5y ago>> Me: Only if you learn it. As someone with a lot of friends and co-workers who are on the info-sec side, the stories I repeatedly hear of how many times they visit the same company year/year and little if anything is done to harden their networks, and impose stricter security on their users is way more common than it should be. Most, if not all of these networks should be taken offline and siloed, but you know that won't happen now, the genie is out of the bottle. If they did, it would create a much smaller attack surface for critical infrastructure. As it sits now? Doubtful we would go back to that world.
- cheese_van 5y ago1. Any system can be hacked. We don't know enough to judge Colonial's infosec posture. 2. Agree that paying leads to bad outcomes. But I also suspect the feds put some pressure on Colonial. Voters remember gas lines and the pump prices.
- at-fates-hands 5y ago>> But I also suspect the feds put some pressure on Colonial This was my thought was as well. I thought they were in on this before it hit the public media. For me, it was like in the movies when the feds are trying to tap the line and the person is trying to keep the bad guy on the line as long as possible so they can trace the call? My theory is the feds encouraged Colonial to string it out in order for them to get as much information on the hacking team as possible. From what we're seeing now (bitcoin seized, servers seized) it sounds like the Feds have them nailed pretty good and their gamble paid off.
- TechBro8615 5y agoMaybe the NSA should hack these companies for free. That would be helpful.
- rcthompson 5y agoI might agree if I had any faith that the people who paid this ransom would do any more than the bare minimum to close this one specific vulnerability and nothing else.
- rawtxapp 5y agoSo they'll be out of business sooner or later then and a company that follows security best practices will take over ideally.
- rcthompson 5y agoYes, "ideally" that's what would happen. Do you really expect that to happen in practice?
- jfoutz 5y agoWell, fines are a fixed cost, the risk can be calculated and offset against a bonus. A ransom has an unknown downside. I'd imagine most ransoms would be priced to likely get paid, but ransomers don't really know the biz inside and out, so they might guess a painful or fatal price. but that's a one time cost. the lost revenue is the killer. I'd expect there will be some serious talks about how much to pay to prevent things like this. 5 million, once? Meh, why bother taking security seriously? I suspect the lost revenue is tougher to swallow. I dunno. you gotta pay every month forever, for protection against maybe something bad happening someday? It's an insurance premium, but you don't get made whole. I guess, I'd expect companies to start paying a little for infrastructure so they can buy good insurance policies. backups would get you a lot. It'll be interesting.
- bostonsre 5y agoYea, it seems like a pretty novel situation where I'm almost happy that these gangs are walking through these companies' unlocked front doors and causing enough havoc to be noticed but not enough to hurt them beyond repair. If it becomes enough of an infectious cesspool with diseases that can't be slept off to the point that these sloppy companies are forced to wear hazmat suits to exist in the environment, maybe that isn't such a bad thing in the long run. Before that tipping point, hopefully we don't just breed a large quantity of super bug diseases/ransomware gangs that laugh at decent security.
- an_opabinia 5y agoI don’t know. Did any of it matter? It was bad when people started hoarding gas. Just a few unfathomably stupid people - as always in this country. If idiots didn’t hoard gas, nothing would really have gone wrong. The preppers are the other side of the same coin. The only thing they seem to never run out of is toilet paper. Who the fuck cares? Pentesters have the same energy. They tell you about what software not to use (anything in their automated suite), followed by a bunch of meaningless bullshit. It is a form of anti preparation, it would not have helped Colonial at all. You talk about crippling, and in the biggest audition for crippling society in the world, time after time it’s the Everyman being an idiot - or a Prepper being too smart for their own good - that is responsible for all the bad.
- bostonsre 5y agoI doubt companies care about anything besides profit and that they could care less about gas hoarders. Also, this was just a little taste of havoc that could be done to the economy and society. I'm hoping they lost enough money to knock some sense into them to practice better security and hopefully it makes others think twice about practicing sloppy security. I'm also guessing in the wake of this that ransom attacks will increase in frequency, ransom demands will increase in value, and insurance premiums will increase as well and insurance providers may be forced to do better due diligence about policies that they sell to large corporations to ensure that they don't practice sloppy security. I'm hoping there is some tipping point where it makes financial sense for these large corporations to practice better security. Right now, they gamble that they won't be attacked and so don't invest in security and for the most part they have been rewarded.
- tbihl 5y agoYou know what's way more effective at stopping gas hoarding so it's available for someone who really wants/needs it? Doubling the price per gallon. Anti-price gouging laws caused the shortage, just like with toilet paper and PPE last year.
- jackson1442 5y agoA price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.
- WalterBright 5y ago> being forced to pay penetration testers Hardware write-enable switches on the drives are 2 or 3 cents.
- Scoundreller 5y agoI remember wiring up firmware lock switches on paytv receivers. That brings me back.
- Guthur 5y agoOf course political terrorists can be negotiated with, they have an agenda and stated goals. You might not like it but they're not actually mad they just use means you are not comfortable being brought to bear so close to home.
- ARandomerDude 5y agoIn 20 years Edward Snowden Jr will reveal to us that it was the Department Of Energy the whole time...
- aledalgrande 5y agoOr a dev testing the chaos monkey...
- kjrose 5y agoI'd agree. But I would be surprised to see that level of action. At least for the next while. Considering the payment time on an invoice is averaging 270 days now. I would be surprised if they moved on this.
- twobitshifter 5y agoI think that would only be true if you thought it possible to obtain perfect security, but we’ve seen that even air-gapped systems are vulnerable to nation states motivated enough, and exploits are always laying in wait. This gets some bugs patched - but it also illustrates US infrastructure weaknesses to others.
- King-Aaron 5y ago> I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states These may be the same thing however.
- Dylan16807 5y agoIf the terrorists and nation states are content with going after random single targets, causing low disruption, and leaving with some money, then good! That's not the scary scenario.
- King-Aaron 5y agoWhile I'm not directly trying to claim that this hack was the result of a nation-state actor, there's also no reason to assume such an entity wouldn't test the waters with small scale, targeted interference either.
- Dylan16807 5y agoOkay, but in a way that doesn't really affect whether the attack has positive/negative effects. The situation of not being able to tell is pretty good.
- deleted 5y ago[deleted]
- unclebucknasty 5y ago>These ransoms are net good...There are a lot of infrastructure teams taking security more seriously. Nonsense. This is not an academic exercise. Our country is being attacked by "nation states" (do more research) and we need to respond accordingly, treating it as the national security threat it is and making the perpetrators pay a heavy price. If they'd bombed our critical infrastructure, no one would be sitting around saying, "oh this is good for improving our defense. Thank you for dropping bombs on us." The idea that they are doing us some kind of service and we should just play a game of defensive cat and mouse, hoping for 100% effectiveness (which we know is impossible) is absurd. Wake up. We're at war.
- hattmall 5y agoCan they unbomb it for $5 million? Cause that would be cool.
- unclebucknasty 5y ago>Can they unbomb it for $5 million? Cause that would be cool Yes, we could "unbomb" it for some amount of money. But, we generally use the term "repair". But, that's a great point: as long as we can undo the damage for some amount of money (via repair or paying extortion), we should let foreign adversaries dictate the terms on which they'll allow us to operate our infrastructure. Still, do let us know when you think we should be concerned. 2 more pipelines? 3 more hospitals? 4 more police stations? $5 trillion ransoms? Maybe? No? Perhaps when infrastructure outages and other attacks cause deaths?
- rswail 5y ago> Wake up. We're at war. With whom? And given that nation states have engaged in this sort of thing for years, and that the US/5-eyes/etc also engage in these activities, do you really want to turn a cyber/cold-war into a hot one? The solution is defense-in-depth, with liability on the providers of software, which will require them to insure, which will raise prices, which will force them to address security as COGS which will force them to reduce their attack surfaces to reduce their insurance premiums.
- andrei_says_ 5y agoSomeone mentioned that these could be terrorists posing as hackers. So, why not both? I’m wondering if in the grand scheme of things this could be one more reason to speed up development of solar/wind + distributed energy production.
- chii 5y agowhy would solar or wind have any better security, if the incentives for better security isn't really there in the first place?
- tw04 5y agoI think you're kidding yourself if you think a company that gets "hacked" by off the shelf cryptoware is going to step up their game enough to have any chance of stopping a targeted state actor. The fact they caved so quickly tells me they are years away from a reasonable security posture.
- jdsalaro 5y ago> I think you're kidding yourself if you think a company that gets "hacked" by off the shelf cryptoware is going to step up their game enough Still, this might lead to their first solid security hire that can bring about change in the form of zero-trust principles, security in depth, etc. > to have any chance of stopping a targeted state actor. Given unlimited resources, interest and budget, no participant in the modern digital landscape has a significant chance of stopping motivated threat actors. > The fact they caved so quickly tells me they are years away from a reasonable security posture. Yes, obviously, but driving change is about incrementally tending to a desired state. Your fatalism is, quite frankly, unnecessary, not that you're not entitled to your opinion, just that disagreeing with GP or stating they are naive because this won't bring about perfect, all-encompassing change is not useful.
- brobdingnagians 5y agoNo single participant has a significant chance, but if each target becomes more expensive on average, then state actors can only afford less targets, which makes the society as a whole more resilient. And if one target is so critical that it could take out a society, perhaps it would be better to either 1. Make it so minimalistic that it can be fully audited and secured or 2. Broken into smaller pieces and decentralised so they can either qualify for #1 or increase the total cost and complexity of compromise.
- cutemonster 5y agoAlso, making society and individuals more prepared and ready to deal with no-more-oil for a while, situations. E.g. warm blankets at home, and food that doesn't need to be boiled, if cannot heat the house because the oil and electricity system is broken for a while?
- jmpman 5y agoI’d rather we pay the $5M in ransom, and then $5T to track the hackers down and eliminate them. Certainly someone died due to the pipeline shutdown. Eliminating the hackers would be fully justified.
- Hammershaft 5y agoIs this intentionally absurd? $5 trillion to kill some hackers?
- spfzero 5y agoI’m on the fence. I definitely see your point, it’s solid. But I also think this (even only 5 million) incentivizes more of the same. It’s no stretch to see we’re in for an increasing amount of this.
- ravel-bar-foo 5y agoWe have been in a less than ideal evolutionary equilibrium with respect to security: in the short term, companies that don't fund security can outcompete the prices of companies that do fund security, but they leave themselves vulnerable long-term to attackers. This is analogous to overspecialization in an ecological niche where there was no predation. As ransomware becomes more widespread, it becomes more and more detrimental to companies to pursue short-term security savings. That's good for everyone.
- bayesian_horse 5y agoThese ransoms are funding the work of enemy nation states trying to cripple western nation states...
- cutemonster 5y ago$5M is less than coffee money for a nation state
- bayesian_horse 5y agoIt adds up quickly. For North Korea the revenue from "criminal enterprises", including hacking and ransomware, are a valuable source of foreign currency. At the very least, $5M seems a good start to fund an ongoing effort at developing cyber attack capabilities.
- DrScump 5y agoThis is not like paying bug bounties to white hats who isolate and report exploits before they are utilized in the wild.