How many $40K ransoms would an org have to pay before it was cheaper to have a security team? The demands might be small to make it cheaper in the short term to pay instead of try to fix the problem. Obviously there are large costs external to the ransom payment, but you don't have to get those funded via political process. Also, in my experience working for state government, engineers were considered a waste of mone…
Just as there's no time to do it right, only time to do it over, there's never money to do it now, only later.
U.S. Cities Strain to Fight Hackers
101–110 of 119 posts
Re: U.S. Cities Strain to Fight Hackers
#102Earlier quoted context omitted.
> The EPA will bring suit to companies polluting illegally. Why shouldn't a government agency bring suit to companies or cities risking a leak of hundreds of millions of social security numbers, for example? Maybe at first we could try an in-between solution. I hate to water things down but maybe a scheme like a USDA Prime Beef label[0] would be more likely to actually pull off? If there was a NIST Certified logo on…
"When a measure becomes a target, it ceases to be a good measure." This sounds nice, but I can't help but feel like this could end up being abused... somehow .
Re: U.S. Cities Strain to Fight Hackers
#103Earlier quoted context omitted.
Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…
>Convincing companies to update what they see as systems that "work just fine" tends to be a Herculean task even when you can make a business case for taking on the expense and risk. >Telling a company "The government says you have to patch and is offering to do it for you" seems like it might not go over quite as well as you might hope. I think a better idea is to have the new agency play an advisory / supplemental…
Re: U.S. Cities Strain to Fight Hackers
#104Earlier quoted context omitted.
Let's imagine just one example of patching a remote hole in a Windows server. First, you have to stage a duplicate of an old server with a new patch, which can take days. A production environment may need significant development effort just to integrate the patch, which takes days. Then run all tests and QC processes against it, which can take days. Then you can deploy it during a maintenance window. This is 1-2 busi…
Perhaps the city of Baltimore should have considered this before deploying thousands of different server configurations.
Re: U.S. Cities Strain to Fight Hackers
#105Earlier quoted context omitted.
I spent years as a infosec consultant specialized in major healthcare companies, and my experience is completely the opposite. It is absurdly easy to be 'compliant' with the HIPAA security rule yet still have abysmal security. The biggest issue IMO with the HIPAA SR is that it is first and foremost a legal matter that involves legal teams, and is not very good at being a technology matter that effectively prescribes…
There will always be some organizations that do the minimum necessary to check some sort of "compliance" checkbox. However you can't deny that overall the healthcare industry as a whole has better security and security controls than they would if HIPAA had never been enacted.
If hospitals faced zero consequences for losing customer data, then yeah, things would probably be worse. But HIPPA is two things: a set of mandatory requirements and a grounds for suing hospitals that lose/misuse data. I think the latter thing is effective, but the former is not.
Re: U.S. Cities Strain to Fight Hackers
#106Earlier quoted context omitted.
> "we want [...] to be able to vote electronically etc." Speak for yourself. I see no upsides.
Wouldn't increasing voter turnout be an upside? Reducing the loss of productivity of those participating? Voting electronically is dangerous today, but I still see it as something to work towards. However, I imagine that would require incredible innovation towards multiple layers of robust identity verification protocols.
There are better, less drastic, ways of making voting more accessible. Washington state's system of mailing everybody a ballot works pretty well. I usually don't even remember when elections are coming up until I get a ballot in the mail, without ever asking for it. In Washington, people who care to vote don't have any trouble finding the time. (Of course many people just don't give a shit, and electronic voting won't change that.)
Re: U.S. Cities Strain to Fight Hackers
#107Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…
I love this assumption that anyone smart or anyone good would automatically be working for another company or at another job. Not only is that just screwy off the top (assumes that smart people automatically can move and relocate to the most desirable job - even geographically) but it also assumes that anyone with any skills would never ever work in that type of situation to begin with. [1] Maybe there are good people that are working there but a government situation like the city of Baltimore is not chock full of the type of money required to actually fix a problem like that or ever Maersk management does not view it as a priority in any way. You know not every job is in a startup that has been VC funded and can afford to lose money ditto for a traditional company such as Maersk. Noting of course that the 'best and the brightest' that work for some of the 'top companies' are kind of screwing up frequently. Not to mention MSFT 'top' designed much of this hackable code at one point.
[1] Attorneys are often like this as well the halo of a top firm means if you are operating out of a storefront you must be stupid in some way otherwise you'd be working at one of the top shiny law firms.
Re: U.S. Cities Strain to Fight Hackers
#108Earlier quoted context omitted.
I spent years as a infosec consultant specialized in major healthcare companies, and my experience is completely the opposite. It is absurdly easy to be 'compliant' with the HIPAA security rule yet still have abysmal security. The biggest issue IMO with the HIPAA SR is that it is first and foremost a legal matter that involves legal teams, and is not very good at being a technology matter that effectively prescribes…
There will always be some organizations that do the minimum necessary to check some sort of "compliance" checkbox. However you can't deny that overall the healthcare industry as a whole has better security and security controls than they would if HIPAA had never been enacted.
Re: U.S. Cities Strain to Fight Hackers
#109Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…
Re: U.S. Cities Strain to Fight Hackers
#110Earlier quoted context omitted.
> Security is just hard, and it's not easier just because you're a tech company. We're not talking about everyone having Red Teams here. We're talking about keeping up to date with regards to Patch Tuesday, or even just having an OS that still actually gets patches. That'll get us 80-90% of the way to decent security: > “Almost two months passed between the release of fixes for the EternalBlue vulnerability and when…
Do you know how many versions of how many operating systems across how many different platforms and products my company uses? Hundreds of variations, maybe thousands. Only a few groups have a solid handle on regular patching, and that's because of how hyper-standardized their systems are. Even if an OS has automatic patching, you can't just immediately apply patches without going through an SDLC and QC process. And n…