back

by _tk_·5y ago·view on hn ↗
Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as well. My bet would be on scenario 1.
3 comments
Having read the release by the attacker, my initial thought is that the immediacy of paying was probably due to the threat of the release of sensitive data, not the ability to restore operations.

I’m sitting here wondering what exactly about the release of their financials and internal procedures prompted them to immediately pay $4-5m in the hopes of preventing it from happening?

If this is the case, then paying the ransom will turn out to be a stupid idea.

If the threat was to release sensitive information, surely the firm would be asking the attackers for details of the sensitive information they claim to have.

If the attackers come back with nothing then it was just a bluff.

However if the attackers come back with real information then paying the ransom is just stupid, as the attacker still have the sensitive information and can repeat the payment demands ad infinitum.

Just spit balling here but they have had several other pipeline shutdowns in recent years. One was blamed on a third party damaging the pipeline but I believe the others were operational issues. Perhaps there's more information on those issues than the company would like the public to know? Just a wild guess.
I am curious what your thoughts are on other commenters making as if it is possible to prevent these types of attacks by just taking security 'more seriously'. My guess is that you know that no matter how much is spent with a large entity and many employees it's near impossible to prevent this type of attack. People make mistakes people are easily fooled people don't follow what they are told to do and so on.

I can't even begin to imagine the amount of people that could cause an issue in the size company you are a CISO at.

It's certainly possible to achieve serious security but probably not practical for most private entities. I've spent most of my development career making software for the US intelligence community and their systems were definitely not going to get broken into by a ransomware gang. Security measures include multilevel air gapping plus heavily armed physical security, six foot thick concrete walls set back from the street by other concrete barriers, locating facilities on military installations, disabling USB ports on most devices, banning anything radio enabled from being anywhere near your workstations, jamming radio signals anyway, severely punishing, possibly executing, anyone caught working as an intentional insider threat, requiring multiple persons in the custody and approval chains to move any files from one network to another via write-once media like DVDs, having the transfer media itself in a separate locked cabinet in a separate locked room inside the actual classified vault serving as an office. Installing and running everything in a separately sandboxed staging environment even after it gets through all the walls and air gaps and DVDs and running it through some fairly extensive testing and analysis before putting it anywhere near a production system.

Clearly, you can never make it literally impossible, but to my knowledge, nobody has ever managed to get malicious software onto a classified production system. Information leaks are, of course, another story.

Thank you - this is the closest I have read on this thread as to the real security practises we will need in the future - if you can elaborate more that will be helpful.

Are these (i suspect not) published anywhere as "Three letter agency network security standards"?

You cannot completely eliminate risk but you certainly can reduce it and be prepared for what to do when one of those low probability risks ends up happening.
If there’s a business need, you can secure a wooden box on the sidewalk in a way, that it is almost impossible to break in. It will be very costly, but if profit or IP depends on it, one can find a way. Taking cyber security „seriously“ always depends on who you see as a potential attacker. I don’t think any corporation on the planet has the capacity or willingness to really protect itself against dedicated state actors. This does not include ransomware gangs that are not prosecuted by the Russian Federation or DPRK, but highly specialized forces within the usual intelligence services.

The types of ransomware attacks we see today might not be preventable as well, every company on the planet will get or was already hit. But, the difference between the attacks: the amount of damage. If money is spent on security, that amount will certainly be smaller.

If the attackers had full access, they probably broke into the financial systems, issued the bitcoin transactions and paid themselves directly. I mean, why bother going through the hassle of trying to teach people how to do all of that stuff?
There are other stakeholders involved in a transaction like this, most importantly banks. Payments, especially large ones, are heavily regulated. You cannot hack a finance department and issue a monero transaction of that size without triggering a lot of alarm bells.