Live data from Hacker News

U.S. Cities Strain to Fight Hackers

wsj.com

81–90 of 119 posts

Re: U.S. Cities Strain to Fight Hackers

#81

Earlier quoted context omitted.

Do you know how many versions of how many operating systems across how many different platforms and products my company uses? Hundreds of variations, maybe thousands. Only a few groups have a solid handle on regular patching, and that's because of how hyper-standardized their systems are. Even if an OS has automatic patching, you can't just immediately apply patches without going through an SDLC and QC process. And n…

> Do you know how many versions of how many operating systems across how many different platforms and products my company uses? What OSes besides Windows, macOS, Linux, Solaris, AIX, HP-UX, z/OS, mobile (Andriod, iOS)? SCADA stuff perhaps? And how many of those operating systems are targeted by worms and ransomware? I know when I used to admin Solaris and IRIX machines we were worried a lot less about attacks than th…

Let's imagine just one example of patching a remote hole in a Windows server. First, you have to stage a duplicate of an old server with a new patch, which can take days. A production environment may need significant development effort just to integrate the patch, which takes days. Then run all tests and QC processes against it, which can take days. Then you can deploy it during a maintenance window. This is 1-2 business weeks.

Now multiply that times 1,000 different combinations of versions of Windows, applications, networks, platforms, and so on.

You're not just patching "servers", anyway. You're patching bare metal machines, hypervisors, AMIs, container images, software packages, plugins, network applications, security policies. Often vendor platforms don't even have a patch available so you have to implement a custom workaround, if one exists.

One could write an entire book about this subject. Please believe me, it's not simple.

Re: U.S. Cities Strain to Fight Hackers

#82
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

> government program that accepts responsibility for doing so.

We already have that.[0] But it doesn't do any good, because it's purely advisory, but they need regulatory and enforcement power. We need an SEC for cybersecurity. Obama put Rod Beckstrom in charge of the National Cybersecurity Center, and that was great, but he resigned after a year because there was no funding behind it. It had been limping along since, but Trump deleted the position about a year ago.

The point is, if we want to fix this problem, we need the political will to hold people accountable instead of just telling people to not do stupid things. IT and Legal are cost centers in 99% of organizations, the difference is that if Legal and IT tell the C-suite "We need to do X or else bad things will happen" Legal gets listened to but IT doesn't. This is because if Legal's "do X" fails, the outcome is an expensive lawsuit, but the outcome of IT's "do X" is a blog post about their continuing commitment to the safety and security of their customer's privacy.

[0] https://en.wikipedia.org/wiki/National_Cybersecurity_Center_...

Re: U.S. Cities Strain to Fight Hackers

#84
post #18

Earlier quoted context omitted.

Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…

>Convincing companies to update what they see as systems that "work just fine" tends to be a Herculean task even when you can make a business case for taking on the expense and risk. >Telling a company "The government says you have to patch and is offering to do it for you" seems like it might not go over quite as well as you might hope. I think a better idea is to have the new agency play an advisory / supplemental…

With respect to the EPA, its worth pointing out they'll only punish significant point sources.

For example a sewage treatment plant dumping raw untreated sewage will get punished. However a city with a major homeless problem where many thousands poop on the street will not be punished for a larger release of untreated raw sewage.

Its kinda similar with major organizations and IT. If there's a policy with the correct checkboxes and strong sounding speeches and firmly worded emails were produced by executives, it doesn't matter if there's some individual unpatched Win95 machine running mission critical tasks, even if there's thousands of those supposedly isolated individual case systems.

Re: U.S. Cities Strain to Fight Hackers

#85
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

I'll happily work for Baltimore if I can implement something that will finally put all their corrupt cops and judges on the gallows.

Some distributed logs that can't be deleted would surely help with accountability.

But we all know that will never happen.

Re: U.S. Cities Strain to Fight Hackers

#86
post #7

Earlier quoted context omitted.

On the other hand, we want digital public services, to be able to pay taxes electronically, to be able to vote electronically etc. I don't think the "don't put sensitive information on the Internet" idea really holds any water unless we expect our public services to be done with pen and paper for evermore, while everything else goes digital. (Yes, machines could be disconnected from the network and so on... but that'…

> "we want [...] to be able to vote electronically etc." Speak for yourself. I see no upsides.

Wouldn't increasing voter turnout be an upside? Reducing the loss of productivity of those participating? Voting electronically is dangerous today, but I still see it as something to work towards. However, I imagine that would require incredible innovation towards multiple layers of robust identity verification protocols.

Re: U.S. Cities Strain to Fight Hackers

#87

Earlier quoted context omitted.

>Convincing companies to update what they see as systems that "work just fine" tends to be a Herculean task even when you can make a business case for taking on the expense and risk. >Telling a company "The government says you have to patch and is offering to do it for you" seems like it might not go over quite as well as you might hope. I think a better idea is to have the new agency play an advisory / supplemental…

> The EPA will bring suit to companies polluting illegally. Why shouldn't a government agency bring suit to companies or cities risking a leak of hundreds of millions of social security numbers, for example? Maybe at first we could try an in-between solution. I hate to water things down but maybe a scheme like a USDA Prime Beef label[0] would be more likely to actually pull off? If there was a NIST Certified logo on…

"When a measure becomes a target, it ceases to be a good measure."

This sounds nice, but I can't help but feel like this could end up being abused...somehow.

Re: U.S. Cities Strain to Fight Hackers

#88
post #34

Earlier quoted context omitted.

A hypothetical regulatory regime to mandate and enforce patching and other good practices? It's worth thinking about. It might also be worth considering if we think there's a good way to get there without doing more harm than good. Congress is not always known for their high-quality technical regulatory work.

Agreed. HIPPA is not exactly a promising precedent. Regulation would almost certainly lag at least a couple years behind and end up making software and IT maintenance much more expensive without making it that much more secure. I don’t think I like this idea, but imagine if marketers for more robust, secure IT solutions were legally allowed to show you how they can spy on you as a part of an ad. That opens up a huge…

What is your concern with HIPAA? There have been occasional breaches in covered entities, but overall the rules have significantly improved security and privacy in healthcare.

Re: U.S. Cities Strain to Fight Hackers

#89
post #45

Earlier quoted context omitted.

If there's a workaround, it's ok. Users usually post workarounds in the thread. This is in the FAQ at https://news.ycombinator.com/newsfaq.html and there's more explanation here: https://news.ycombinator.com/item?id=10178989 https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...

If there's a workaround and it's not hard for people to find it and paste it into the comments, then it's not hard for people submitting articles to post the non-paywall version in the first place.

It's important that the original URL be used so that readers can see what the domain is. It's for that same reason that HN doesn't allow link shorteners.

Re: U.S. Cities Strain to Fight Hackers

#90

Earlier quoted context omitted.

> Security is just hard, and it's not easier just because you're a tech company. We're not talking about everyone having Red Teams here. We're talking about keeping up to date with regards to Patch Tuesday, or even just having an OS that still actually gets patches. That'll get us 80-90% of the way to decent security: > “Almost two months passed between the release of fixes for the EternalBlue vulnerability and when…

Do you know how many versions of how many operating systems across how many different platforms and products my company uses? Hundreds of variations, maybe thousands. Only a few groups have a solid handle on regular patching, and that's because of how hyper-standardized their systems are. Even if an OS has automatic patching, you can't just immediately apply patches without going through an SDLC and QC process. And n…

That approach might have made sense 10 years ago but it's no longer tenable now that the threat environment has escalated. Organizations will now have to roll out patches immediately even at the risk of disrupting mission critical operations.
Post reply on HN