Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

111–120 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#111
post #93

Earlier quoted context omitted.

The downward trend in bug bounty payouts and frustration from researchers might also sweeten that deal for more experienced persons.

Companies which fall victim to such attacks aren't normally the kind which have bug bounties or engage with security researchers.

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#112
post #106
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

The NSA’s mission-statement in domestic civic cybersecurity is to ensure the flow of commerce, i.e. to protect GDP. They aren’t going to patch things in a way that makes them not do their jobs any more. That’d be an “attack on commerce” just as much as exploiting the vuln would be.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#113

Curious if this will result in extraterritorial enforcement. For example, it's clear Moscow is either unwilling or unable to prosecute cyber criminals within its border.

I'm sure the Russians are as interested in these crooks as the Americans, as it would be attractive to seize their assets. They will not extradite them, but they might wish they had been.

Why? They bring in millions of dollars to the Russian economy.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#115

They fucked up by targeting infrastructure. If they stuck with small companies they could keep doing it till the cows came home. But now they have governments against them so now they will be hunted down.

These groups aren't really "targeting" anyone. These ransomware attacks are as sophisticated as nigerian prince emails. Send out a lot of spam, wait for someone who clicks on it and is running outdated software and boom. Sooner or later you will encrypt something important enough to pay for.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#116
post #106
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

The law should require certain minimums of security for infrastructure deemed vital, like oil pipelines. If entertainment companies and HIPPA can ensure those they work with practice good cybersecurity, why can't the government do the same?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#117
post #106
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

I’d prefer the NSA put in the hard effort to shed their reputation as spies and start by offering plain security advice in the open that can be verified by independent experts. The best way forward is for the NSA to focus on providing high quality security advice, best practices, and guidance to critical infrastructure. This doesn’t involve handing over the “keys to the kingdom”.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#118
post #112
post #106

Earlier quoted context omitted.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

The NSA’s mission-statement in domestic civic cybersecurity is to ensure the flow of commerce, i.e. to protect GDP. They aren’t going to patch things in a way that makes them not do their jobs any more. That’d be an “attack on commerce” just as much as exploiting the vuln would be.

That's true in broad strokes, but I'm trying to portray things from the position of an executive. Having a bunch of outsiders that you have no real influence over in charge of your systems is terrifying.

The alternatives are a regulatory system for information security or offering advice and hoping companies implement it. There's a lot of advice on offer.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#119
post #110
post #78

Earlier quoted context omitted.

Yes, that definitely won't provide an incentive for hacker groups to release more ransomware

Can you explain how so?

Because the more we pay the hackers the more funding they get to launch further attacks

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#120
post #66

So we are going to launch a trillion dollar war on ransomware which inevitably leads to more ransomware before patting ourselves on the back and saying "mission accomplished"? Are we also going to make ordinary citizens take off their shoes and get probed before using their computer?

If the war on terror is anything to go by, then that would indeed be the most likely outcome [0].

[0] https://ourworldindata.org/grapher/fatalities-from-terrorism...

Post reply on HN