Live data from Hacker News

U.S. Cities Strain to Fight Hackers

wsj.com

71–80 of 119 posts

Re: U.S. Cities Strain to Fight Hackers

#71

Earlier quoted context omitted.

Can we partially blame IBM? Every municpality I've worked for runs a majority of their systems on the IBM System i (iSeries, AS/400) IBM is very slow to update any of the tools for Windows that are included with these systems. Ditch the green screens, use the IBM EasyAccess or whatever they call it on Windows, you just saved some $. Now, there are database tools and admin utilities that are also included in this. Mos…

Oh let me rush to defend my favorite platform, the iSeries. The platform, regardless of which, is not to blame. It is the laziness of most IT shops which either don't have any process in place or only pay it lip service. iSeries machines (AS/400) serve many different client interaction methods, from green screen, web services, ODBC, NodeJS via Qshell, and more. If employed properly the iSeries has some of the best se…

>> SSL

Who manages those certificates?

Re: U.S. Cities Strain to Fight Hackers

#72

I'm painting with a broad brush here, but a lot of government employees do as little as possible. They are union protected, so they can stay in their jobs for a very long time. So you get a lot of the thing in IT where someone has 20 years of 1 year experience. I'm sure the budgets aren't great and the rest of the government isn't pushing tech, but you end up with a lot of 'it works fine just leave it as is'

> I'm painting with a broad brush here, but a lot of government employees do as little as possible.

Welcome to humanity. How many people actually devote their lives to the improvement of the human condition, or have a devotion to even the jobs that they are working for? I fear that treating your job with the devotion necessary to do it truly effectively means that you limit yourself and future opportunities, because you must devote time to your own growth.

And how many people are interested in devotion to any cause or personal growth? Personal growth is hard, and devotion to a cause, a serious one especially, is equally painful. Understanding climate change, for instance, is so painful that people reject it in its entirety; it could be because it is a direct refutation to their world view, or because the idea is just so uncomfortable on its face.

I feel as if Ada Palmer had it right when she suggests that the first rule of Utopians must be "I hereby renounce the right to complacency, and vow lifelong to take only what minimum of leisure is necessary to my productivity, viewing health, happiness, rest, and play as means, not ends".

I think that's too much weight for the vast majority of humanity, and understandably so. In America it feels as if the way society is structured is designed to sap willpower (for example: the Atomic Family). I can think of a number of reasons why this might actually be the planned outcome of its current design.

Re: U.S. Cities Strain to Fight Hackers

#73
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

> Then hopefully pillage all the miserable smart people who are currently working at mega corps and agencies who actually want to do positive, meaningful work for a change. Oof, if you think being a smart technical person working at a megacorp is worse than being a smart technical person working for a government agency... I have no idea what your model of the world and labor market is.

The one where he is from the government and is here to help.

Re: U.S. Cities Strain to Fight Hackers

#74

Earlier quoted context omitted.

> Security is just hard, and it's not easier just because you're a tech company. We're not talking about everyone having Red Teams here. We're talking about keeping up to date with regards to Patch Tuesday, or even just having an OS that still actually gets patches. That'll get us 80-90% of the way to decent security: > “Almost two months passed between the release of fixes for the EternalBlue vulnerability and when…

Do you know how many versions of how many operating systems across how many different platforms and products my company uses? Hundreds of variations, maybe thousands. Only a few groups have a solid handle on regular patching, and that's because of how hyper-standardized their systems are. Even if an OS has automatic patching, you can't just immediately apply patches without going through an SDLC and QC process. And n…

> Do you know how many versions of how many operating systems across how many different platforms and products my company uses?

What OSes besides Windows, macOS, Linux, Solaris, AIX, HP-UX, z/OS, mobile (Andriod, iOS)? SCADA stuff perhaps?

And how many of those operating systems are targeted by worms and ransomware?

I know when I used to admin Solaris and IRIX machines we were worried a lot less about attacks than the Windows desktop folks. An nmap of the systems showed SSH open and one or two other services, which meant very few vectors for attack.

The fact of the matter is that by securing desktops, one probably takes care of 80% of a company's attack surface. Next take care of your Windows servers, which is another 10%. Then go after Unix-y servers and things like printers, HVAC, IPMI, etc (which should be VLANed off).

Re: U.S. Cities Strain to Fight Hackers

#75
post #45

Stop posting WSJ paywall articles. This isn’t a paywall advertisement service.

If there's a workaround, it's ok. Users usually post workarounds in the thread. This is in the FAQ at https://news.ycombinator.com/newsfaq.html and there's more explanation here: https://news.ycombinator.com/item?id=10178989 https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...

If there's a workaround and it's not hard for people to find it and paste it into the comments, then it's not hard for people submitting articles to post the non-paywall version in the first place.

Re: U.S. Cities Strain to Fight Hackers

#76
post #15

Earlier quoted context omitted.

> to be able to vote electronically That's one thing we definitely shouldn't want. This case is just the latest proving what a bad idea that is.

I want to be able to vote electronically.

Then you don't understand why it is a terrible idea.

Re: U.S. Cities Strain to Fight Hackers

#77
post #18
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…

> It's such a good idea that the US government decided you were right decades ago.

Perhaps, but it is hardly a universal belief that they have the balance right.

It is hard to pick a starting point to get in to this discussion, because it has been going on for a long time and is really complicated, not to mention largely classified. Perhaps one that dovetails into the encryption debate will be as good as any:

https://www.lawfareblog.com/good-defense-good-offense-nsa-my...

Re: U.S. Cities Strain to Fight Hackers

#78
post #34

Earlier quoted context omitted.

>Convincing companies to update what they see as systems that "work just fine" tends to be a Herculean task even when you can make a business case for taking on the expense and risk. >Telling a company "The government says you have to patch and is offering to do it for you" seems like it might not go over quite as well as you might hope. I think a better idea is to have the new agency play an advisory / supplemental…

A hypothetical regulatory regime to mandate and enforce patching and other good practices? It's worth thinking about. It might also be worth considering if we think there's a good way to get there without doing more harm than good. Congress is not always known for their high-quality technical regulatory work.

Agreed. HIPPA is not exactly a promising precedent.

Regulation would almost certainly lag at least a couple years behind and end up making software and IT maintenance much more expensive without making it that much more secure. I don’t think I like this idea, but imagine if marketers for more robust, secure IT solutions were legally allowed to show you how they can spy on you as a part of an ad. That opens up a huge can of worms that is probably best left closed, but I think it’d act like steroids for getting people to upgrade their insecure stuff.

Re: U.S. Cities Strain to Fight Hackers

#79
post #18

Earlier quoted context omitted.

Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…

>Convincing companies to update what they see as systems that "work just fine" tends to be a Herculean task even when you can make a business case for taking on the expense and risk. >Telling a company "The government says you have to patch and is offering to do it for you" seems like it might not go over quite as well as you might hope. I think a better idea is to have the new agency play an advisory / supplemental…

> The EPA will bring suit to companies polluting illegally. Why shouldn't a government agency bring suit to companies or cities risking a leak of hundreds of millions of social security numbers, for example?

Maybe at first we could try an in-between solution. I hate to water things down but maybe a scheme like a USDA Prime Beef label[0] would be more likely to actually pull off?

If there was a NIST Certified logo on one bank/app/merchant/site that asks for personal info, and not another, I would be much more likely to go with the NIST one. Obviously credit agencies and gov systems need to go first.

>In the United States, the United States Department of Agriculture's (USDA's) Agricultural Marketing Service (AMS) operates a voluntary beef grading program that began in 1917. A meat processor pays for a trained AMS meat grader to grade whole carcasses at the abattoir. Such processors are required to comply with Food Safety and Inspection Service (FSIS) grade labeling procedures. The official USDA grade designation can appear as markings on retail containers, individual bags, or on USDA shield stamps, as well as on legible roller brands appearing on the meat itself.

[0] https://en.wikipedia.org/wiki/Beef_carcass_classification

Re: U.S. Cities Strain to Fight Hackers

#80

Earlier quoted context omitted.

I want to be able to vote electronically.

Then you don't understand why it is a terrible idea.

Instead of such general and frankly unhelpful statements, would you mind explaining to the previous poster why electronic voting is such a bad idea? It may even generate further discussion instead of just downvotes.
Post reply on HN