Live data from Hacker News

U.S. Cities Strain to Fight Hackers

wsj.com

61–70 of 119 posts

Re: U.S. Cities Strain to Fight Hackers

#61
post #38

AP style should really push journalists to use the term "cybercriminals" over "hackers". I'm not the first to say it but the issue is growing, and it's only going to make the public more leery of any tech-minded but innocent kid or professional pentesting adult who uses the term "hacker".

I'm not sure I agree. I think 'hacked' is widely enough known with its negative connotation. If Google posted a blog titled 'We got hacked', everyone would immediately click on it and their heart probably skip a beat. And in English it only makes sense that who hacks, but a hacker. Regardless of original meaning, as happens with language, words definitions change based on usage and common understanding. I think the '…

Fwiw, I started reading Hacker News ~8 years ago, fresh out of a CS degree and working in tech, and it was my first exposure to a word sense of hacking other than illegal access. I've used the term pretty differently in the years since, but I think the battle for the mainstream meaning of the word was lost long ago.

Re: U.S. Cities Strain to Fight Hackers

#62
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

Can we partially blame IBM? Every municpality I've worked for runs a majority of their systems on the IBM System i (iSeries, AS/400) IBM is very slow to update any of the tools for Windows that are included with these systems. Ditch the green screens, use the IBM EasyAccess or whatever they call it on Windows, you just saved some $. Now, there are database tools and admin utilities that are also included in this. Mos…

Oh let me rush to defend my favorite platform, the iSeries.

The platform, regardless of which, is not to blame. It is the laziness of most IT shops which either don't have any process in place or only pay it lip service.

iSeries machines (AS/400) serve many different client interaction methods, from green screen, web services, ODBC, NodeJS via Qshell, and more. If employed properly the iSeries has some of the best security in the industry, reason why many are used by banks all over the world, hospitals, the gambling industry, and more. Failure occurs for the same reason it does anywhere else, not having a process in place and following it.

As for currency with what is available today, iSeries access is facilitated through a JAVA based client which works on Windows, OS X, and Linux. It is the same java application throughout and even provides ODBC access through java drivers and for windows you can opt into a subset of windows exe/dlls. There is a full blown web service hooked to it as well that runs on the server as needed. It is up and down fully SSL too.

Re: U.S. Cities Strain to Fight Hackers

#63
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

You just described where I work (small manufacturing company) when I started.

It's taken me 18mths to significantly improve our security posture and I still have a bunch of stuff I need to do (I was hired as a programmer but I couldn't in good conscience leave it as it was).

Re: U.S. Cities Strain to Fight Hackers

#64
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

No need for a new government agency or program. We just need to start holding all organizations, and specifically their leaders, personally liable for security incidents. Once people's freedoms are at stake, everyone fall in line so quickly that we will all be amazed.

Why am I not surprised that the comment saying no need for government intervention is the one comment that's downvoted?

While I typically believe smaller government is the answer, I would personally welcome a regulatory framework that gives me confidence in both my own organization and every other one as well.

It wouldn't ruin my business, it'd just be another line item in my budget.

Re: U.S. Cities Strain to Fight Hackers

#66
There is a big industry starting to spring up around this, data insurance. Go to any big insurance conference and all they are talking about right now is cyber insurance. Construction companies are asking for it for example; they've always had to insure their employees, but now they are seeing things like their offices being hit by cryptolockers and being extorted for bitcoin by Russians. They can't afford to lose productivity over something like that so they are getting insured. Those insurance agencies are working with security consultants to help harden the networks too. So yes, this is definitely a big problem, but the wheels are already moving to start addressing this issue, because there is money to be made.

Re: U.S. Cities Strain to Fight Hackers

#67
I'm surprised no one has mentioned it here on hacker news.

But when CFAA makes all hacking criminal, the only hackers left are criminals.

Ethically motivated hackers should have the same protections as whistle blowers - The day that happens, the world becomes more safe and transparent.

But transparency is not what everyone wants, obviously.

I wish I was more surprised that mainstream media fails to mention this important part of the state of cyber security in the US.

Re: U.S. Cities Strain to Fight Hackers

#68

Earlier quoted context omitted.

I don't know why you got downvoted. I know plenty of companies with modern tech that absolutely suck at security. Security is just hard, and it's not easier just because you're a tech company. By comparison, if you spend billions of dollars on a modern building, I can still probably break into it with just a can of compressed air. I doubt the design plans for the building included "mitigate compressed air attacks", a…

> Security is just hard, and it's not easier just because you're a tech company. We're not talking about everyone having Red Teams here. We're talking about keeping up to date with regards to Patch Tuesday, or even just having an OS that still actually gets patches. That'll get us 80-90% of the way to decent security: > “Almost two months passed between the release of fixes for the EternalBlue vulnerability and when…

Do you know how many versions of how many operating systems across how many different platforms and products my company uses? Hundreds of variations, maybe thousands. Only a few groups have a solid handle on regular patching, and that's because of how hyper-standardized their systems are.

Even if an OS has automatic patching, you can't just immediately apply patches without going through an SDLC and QC process. And not every group even has those processes defined. Even if they do, you still need to address critical business problems before security ones.

Re: U.S. Cities Strain to Fight Hackers

#69
post #27

Could someone suggest recognized and useful certifications, for those interesting getting into cybersecurity? The article has a link to another mentioning CompTIA and CISSP, are they any good?

CompTIA certs are a mixed bag, some are decent, but many are very surface level. CISSP is broad, and more managerial level, but certainly worthwhile. But if you'd like some in the trenches stuff, I'd suggest the OSCP.

Re: U.S. Cities Strain to Fight Hackers

#70

Earlier quoted context omitted.

Can we partially blame IBM? Every municpality I've worked for runs a majority of their systems on the IBM System i (iSeries, AS/400) IBM is very slow to update any of the tools for Windows that are included with these systems. Ditch the green screens, use the IBM EasyAccess or whatever they call it on Windows, you just saved some $. Now, there are database tools and admin utilities that are also included in this. Mos…

Oh let me rush to defend my favorite platform, the iSeries. The platform, regardless of which, is not to blame. It is the laziness of most IT shops which either don't have any process in place or only pay it lip service. iSeries machines (AS/400) serve many different client interaction methods, from green screen, web services, ODBC, NodeJS via Qshell, and more. If employed properly the iSeries has some of the best se…

Simple stuff like copy-paste or saving exported files is broken on 64 bit windows
Post reply on HN