Earlier quoted context omitted.
got anything from the past 50 years?
Well, a lot of the turmoil in the Middle East is at least partially (I'd argue mostly) to blame because of the US. Al Qaeda was trained by the CIA. I think it's relatively accepted that there were no WMDs in Iraq, so that entire invasion/war could be classified as terrorism. There are countless drone strikes with civilian casualties around the world. Whether or not you agree with why we did it, the CIA is credited wi…
FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
131–140 of 357 posts
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#132If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…
If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#133Earlier quoted context omitted.
True. The United States is the largest state sponsor of terrorism in the world (School of the Americas, Bay of Pigs, Iranian-Contra, Operation AJAX, COINTELPRO, Operation Mockingbird, United Fruit...)
Do you actually think that this comment adds to the conversation at hand or are you just using this as an opportunity to wedge in the 'but America does it too!' trope?
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#134This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.
>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#135Earlier quoted context omitted.
got anything from the past 50 years?
Well, a lot of the turmoil in the Middle East is at least partially (I'd argue mostly) to blame because of the US. Al Qaeda was trained by the CIA. I think it's relatively accepted that there were no WMDs in Iraq, so that entire invasion/war could be classified as terrorism. There are countless drone strikes with civilian casualties around the world. Whether or not you agree with why we did it, the CIA is credited wi…
However, it's hard to avoid there being some undesired casualties in war, especially when the the fighters on the opposing side are using guerilla tactics and hiding within the civilian population, such as deliberately fighting, sniping, or using mortars from within what are otherwise civilian compounds, or even mosques, forcing the US to either ignore the attacks (unacceptable) or respond and attack mosques and civilian compounds.
All of our soldiers are unformed, with a flag, and follow rules of engagement that involve not attacking anyone except positively identified targets (i.e. observed holding weapons). Terrorist groups operating in the middle east wear no uniform and exploit our rules of engagement by attacking, dropping their weapons before the coalition can respond, then pretending to be civilians. Even though they're the only men-of-age in an area from which an attack just took place, since they stashed their weapons somewhere, the rules of engagement mean that our troops can't do much if they didn't observe a person holding a weapon.
Uniformed soldiers fighting other uniformed soldiers is different than terrorists that attack civilians or soldiers and then hide, pretending to be civilians.
The Iraq war was started on pretenses that we now know are false, but let's not conflate that with groups that deliberately target civilians (with suicide bombs in shopping centers), or conduct attacks even on military facilities and then pretend to be civilians when pursued for a counter-attack.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#136Earlier quoted context omitted.
>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.
There have been ransomware attacks that are covers for outright attacks, iirc some where the payment and decryption mechanism didn't even function. On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. But it seems a lot of the big gangs are suspected state-sponsored, which is less terrorism and more cyber warfare
Hard to see how they are terrorists? What are they pushing to accomplish with their terror campaign.
Anyways, my health care system constantly assures me security is its "top" priority and "state of the art".
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#137Earlier quoted context omitted.
Of course; it happens all the time. False flags (in the form of routed connections and much more) are extremely common in cyberwar and among cybercriminals, naturally. But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? It may have happened, and I wouldn't be shocked, but I haven't actually seen a publicized case…
> But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? Absence of evidence is not evidence of absence.
Everyone should be subject to due process. If some organized crime ring in Ukraine is blamed for some particular ransomware attack and they get tricked into traveling somewhere that lets them be extradited and tried in a US court, the prosecution still needs to prove beyond a reasonable doubt at trial that they're the responsible party. Things get more complicated when an entire nation-state government is accused of launching ransomware attacks, but so far I think only North Korea has faced that (someone please correct me if I'm wrong), and they're kind of an outlier among all the other countries.
We should always be skeptical any time any government accuses any entity of a crime, of course. There should always be a presumption of innocence. But that's what the legal system and due process are for. The onus is on the government to prove their case.
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#138Earlier quoted context omitted.
There have been ransomware attacks that are covers for outright attacks, iirc some where the payment and decryption mechanism didn't even function. On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. But it seems a lot of the big gangs are suspected state-sponsored, which is less terrorism and more cyber warfare
And plenty just want to get paid - it's actually pretty impressive how many take down / don't share if they are paid or actually come through with the decryption keys. Hard to see how they are terrorists? What are they pushing to accomplish with their terror campaign. Anyways, my health care system constantly assures me security is its "top" priority and "state of the art".
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#139This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.
Not that that is any way a defense, and I'm sure there was as much a self-interested motivation of "We are going to be hit hard if we ransom a hospital _now_" as much as "doing the right thing"...
Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
#140Earlier quoted context omitted.
At some point we will sit down and recognize that calling programmers "engineers" was a mistake. True engineers make guarantees within clearly specified limits and take on liability for those guarantees. Modern technology companies claim many things while owning little, if any, responsibility.
This is what I was thinking with my comment. I don't like the idea of being liable for software I make. I love that the MIT license has a clause saying whatever happens to your computer is not my fault. It's comforting when you're just trying to share something. But.. there are certain classes of software that I think should be written differently. I feel like we made a lot of bad decisions. There should be a complet…
Because for better or worse people make their choices and who are you to tell them what to run.
Infrastructural software - sure there should be some kind of security certification. this probably will not help much. Switches and routers are not running Windows and are still being attacked and crippled. Or consider the Stuxnet.