Live data from Hacker News

U.S. Cities Strain to Fight Hackers

wsj.com

31–40 of 119 posts

Re: U.S. Cities Strain to Fight Hackers

#31
post #7

Don't put extremely sensitive information on the internet.

On the other hand, we want digital public services, to be able to pay taxes electronically, to be able to vote electronically etc. I don't think the "don't put sensitive information on the Internet" idea really holds any water unless we expect our public services to be done with pen and paper for evermore, while everything else goes digital. (Yes, machines could be disconnected from the network and so on... but that'…

Well, I would prefer it, but at least at the scale of towns and small cities, I simply don't trust them.

Furthermore, if they do so many things that they need a public-facing website to manage all of the sensitive information they keep on me, I probably don't want to live there.

It's all well and good wanting to access a municipal government's private records through the internet, but try to think of how likely they are to get that right, and adjust your desires accordingly.

Re: U.S. Cities Strain to Fight Hackers

#32
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

“Make sure nobody at state or DHS or justice can subvert this new agency, they need to stand on equal footing with any company or agency.”

That’s going to be a problem. It’s a zero sum with power in dc and if you can solve that you will be fixing more problems than domestic info sec weakness.

Re: U.S. Cities Strain to Fight Hackers

#33
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

That just perpetuates the problem.

Smaller cities don't have the financial wherewithal to competently run internet-facing services. Usually the best administered parts of a city are in police departments where sworn officers are filling IT roles, aided by injections of grant-driven projects done by consultants. That's not a good situation for anyone. The winning move is not to play.

I regularly hire people from cities and school districts due to some unique aspects of my workplace and benefits that makes it a smart move for them. We routinely take folks in senior tech or director roles and drop them into entry level titles -- and they are very happy to get significant raises.

End of the day, the "fix" is to dump money into rolling out modern solutions. Every user-facing city IT function should be delivered on an iPad or Chromebook.

Re: U.S. Cities Strain to Fight Hackers

#34
post #18

Earlier quoted context omitted.

Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…

>Convincing companies to update what they see as systems that "work just fine" tends to be a Herculean task even when you can make a business case for taking on the expense and risk. >Telling a company "The government says you have to patch and is offering to do it for you" seems like it might not go over quite as well as you might hope. I think a better idea is to have the new agency play an advisory / supplemental…

A hypothetical regulatory regime to mandate and enforce patching and other good practices?

It's worth thinking about. It might also be worth considering if we think there's a good way to get there without doing more harm than good. Congress is not always known for their high-quality technical regulatory work.

Re: U.S. Cities Strain to Fight Hackers

#35
post #18

Earlier quoted context omitted.

Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…

>Convincing companies to update what they see as systems that "work just fine" tends to be a Herculean task even when you can make a business case for taking on the expense and risk. >Telling a company "The government says you have to patch and is offering to do it for you" seems like it might not go over quite as well as you might hope. I think a better idea is to have the new agency play an advisory / supplemental…

Because we as a society have yet decided that it's bad. Just like we used to not think environmental pollution was bad, or at least with stunting businesses.

Re: U.S. Cities Strain to Fight Hackers

#36
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

> Make sure nobody at state or DHS or justice can subvert this new agency, they need to stand on equal footing with any company or agency.

Interestingly, a service similar to what you described is already offered through DHS:

https://www.us-cert.gov/resources/ncats https://www.dhs.gov/cisa/cybersecurity-assessments

Re: U.S. Cities Strain to Fight Hackers

#37
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

That just perpetuates the problem. Smaller cities don't have the financial wherewithal to competently run internet-facing services. Usually the best administered parts of a city are in police departments where sworn officers are filling IT roles, aided by injections of grant-driven projects done by consultants. That's not a good situation for anyone. The winning move is not to play. I regularly hire people from citie…

"...dump money into rolling out modern solutions."

Yep. Ongoing maintenance and pro-active replacement is a cost. A cost that needs to be solidified as an ongoing expense. A lot of the people in leadership positions see technology as a one-time cost. ("I still have the computer I bought 10 years ago at home! It works just fine. Why do we need to buy new computers?")

Re: U.S. Cities Strain to Fight Hackers

#38

AP style should really push journalists to use the term "cybercriminals" over "hackers". I'm not the first to say it but the issue is growing, and it's only going to make the public more leery of any tech-minded but innocent kid or professional pentesting adult who uses the term "hacker".

I'm not sure I agree. I think 'hacked' is widely enough known with its negative connotation. If Google posted a blog titled 'We got hacked', everyone would immediately click on it and their heart probably skip a beat. And in English it only makes sense that who hacks, but a hacker.

Regardless of original meaning, as happens with language, words definitions change based on usage and common understanding. I think the 'hacker' battle has been lost, and those examples you listed should use a different term that would be more easily adopted.

Re: U.S. Cities Strain to Fight Hackers

#39
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

"There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so."

Regulation and/or software liability. So far, they can ignore security with it rarely costing them anything. In a few industries, ignoring safety will cost a lot. So, they spend a fraction of that cost on preventing the overall cost. It might also be a requirement of even selling the product. Basic stuff like memory safety, login practices, updates, and so on being a requirement could get the bar way up. It was done before under TCSEC with DO-178C doing it now for safety. A whole market of safe products formed.

Alternatively, people do a strong push in courts to hold companies liable for any time their computers are used to attack a 3rd party. The folks suing and experts testifying focus on the core practices that prevent most problems. The argument is professional negligence. We stay on them until the risk-reward analysis for information security has executives making sure it gets done with specific stuff in the lawsuits addressed. Since that stuff is 80/20, then it solves about 80% of the problems. The new incentives might also make it easier to convince them to partly or wholly use systems like OpenBSD, QubesOS, and Genode.

Although I favor regulation, I think the lawsuit strategy should get a lot of experimentation first. It doesn't require a change in government. Just good lawyers. :)

Re: U.S. Cities Strain to Fight Hackers

#40
post #12

AP style should really push journalists to use the term "cybercriminals" over "hackers". I'm not the first to say it but the issue is growing, and it's only going to make the public more leery of any tech-minded but innocent kid or professional pentesting adult who uses the term "hacker".

Journalists aren't that bright, they get confused at the difference.

[deleted]
Post reply on HN