Live data from Hacker News

U.S. Cities Strain to Fight Hackers

wsj.com

21–30 of 119 posts

Re: U.S. Cities Strain to Fight Hackers

#21

AP style should really push journalists to use the term "cybercriminals" over "hackers". I'm not the first to say it but the issue is growing, and it's only going to make the public more leery of any tech-minded but innocent kid or professional pentesting adult who uses the term "hacker".

Everyone in the industry thinks that anything with "cyber" in the word is either a joke, or is made up by government types that don't really understand computers.

Re: U.S. Cities Strain to Fight Hackers

#22
post #18
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…

>Convincing companies to update what they see as systems that "work just fine" tends to be a Herculean task even when you can make a business case for taking on the expense and risk.

>Telling a company "The government says you have to patch and is offering to do it for you" seems like it might not go over quite as well as you might hope.

I think a better idea is to have the new agency play an advisory / supplemental role but otherwise place the burden of fix on the company itself. It just needs teeth for entities unwilling to adequately resolve their IT failures.

The EPA will bring suit to companies polluting illegally. Why shouldn't a government agency bring suit to companies or cities risking a leak of hundreds of millions of social security numbers, for example?

Re: U.S. Cities Strain to Fight Hackers

#23
post #12

Earlier quoted context omitted.

Journalists aren't that bright, they get confused at the difference.

Some are brilliant (e.g., Ronan Farrow), but the real point is that they’re speaking to an audience which they’re essentially trying to coddle because the audience isn’t comprised of experts.

You're on to something but it's a tiny bit more complicated than that.

Take general assignment reporters for example. They have to learn how to learn.

What I mean is, they're experts on digesting new information. Because they have to write about ANYTHING at a moment's notice, and can't be expected to be experts on everything. THEN they have to write about that topic using only 500 words (or so) to an audience who also probably knows nothing about the topic.

That's a tall order and you shouldn't be surprised reporters get it wrong sometimes.

Re: U.S. Cities Strain to Fight Hackers

#24
post #21

AP style should really push journalists to use the term "cybercriminals" over "hackers". I'm not the first to say it but the issue is growing, and it's only going to make the public more leery of any tech-minded but innocent kid or professional pentesting adult who uses the term "hacker".

Everyone in the industry thinks that anything with "cyber" in the word is either a joke, or is made up by government types that don't really understand computers.

I wonder how William Gibson feels about coining "cyberspace" only to live in a world where "cyber" has been reduced to chat room banter and low-brow humor.

Re: U.S. Cities Strain to Fight Hackers

#25
post #10
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

"any organization that is not tech first" - thats pretty optimistic looking at a number of the tech first companies that have being breached.

I don't know why you got downvoted. I know plenty of companies with modern tech that absolutely suck at security. Security is just hard, and it's not easier just because you're a tech company.

By comparison, if you spend billions of dollars on a modern building, I can still probably break into it with just a can of compressed air. I doubt the design plans for the building included "mitigate compressed air attacks", and it's the same with every other kind of organization.

Re: U.S. Cities Strain to Fight Hackers

#26
These type of organizations probably need to be running all chromebooks with a G Suite enterprise account (configured to require all employees to use 2FA). Something that has way less attack surface than what they have now.

Re: U.S. Cities Strain to Fight Hackers

#28
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

This will only be a solution if it addresses the "business critical application, vendor has gone out of business, no source code available" case.

Which ultimately comes down to "Who's going to pay for a more secure replacement?" & "Who's going to assess heavy-enough fines to force the replacement risk scales in favor of doing something?"

Re: U.S. Cities Strain to Fight Hackers

#29
post #15
post #7

Earlier quoted context omitted.

On the other hand, we want digital public services, to be able to pay taxes electronically, to be able to vote electronically etc. I don't think the "don't put sensitive information on the Internet" idea really holds any water unless we expect our public services to be done with pen and paper for evermore, while everything else goes digital. (Yes, machines could be disconnected from the network and so on... but that'…

> to be able to vote electronically That's one thing we definitely shouldn't want. This case is just the latest proving what a bad idea that is.

I want to be able to vote electronically.

Re: U.S. Cities Strain to Fight Hackers

#30
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

No need for a new government agency or program.

We just need to start holding all organizations, and specifically their leaders, personally liable for security incidents.

Once people's freedoms are at stake, everyone fall in line so quickly that we will all be amazed.

Post reply on HN