Earlier quoted context omitted.
The downward trend in bug bounty payouts and frustration from researchers might also sweeten that deal for more experienced persons.
Companies which fall victim to such attacks aren't normally the kind which have bug bounties or engage with security researchers.
U.S. to give ransomware hacks similar priority as terrorism, official says
111–120 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#112What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.
Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#113Curious if this will result in extraterritorial enforcement. For example, it's clear Moscow is either unwilling or unable to prosecute cyber criminals within its border.
I'm sure the Russians are as interested in these crooks as the Americans, as it would be attractive to seize their assets. They will not extradite them, but they might wish they had been.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#114That's not the case for terrorism.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#115They fucked up by targeting infrastructure. If they stuck with small companies they could keep doing it till the cows came home. But now they have governments against them so now they will be hunted down.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#116What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.
Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#117What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.
Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#118Earlier quoted context omitted.
Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…
The NSA’s mission-statement in domestic civic cybersecurity is to ensure the flow of commerce, i.e. to protect GDP. They aren’t going to patch things in a way that makes them not do their jobs any more. That’d be an “attack on commerce” just as much as exploiting the vuln would be.
The alternatives are a regulatory system for information security or offering advice and hoping companies implement it. There's a lot of advice on offer.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#119Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#120So we are going to launch a trillion dollar war on ransomware which inevitably leads to more ransomware before patting ourselves on the back and saying "mission accomplished"? Are we also going to make ordinary citizens take off their shoes and get probed before using their computer?
[0] https://ourworldindata.org/grapher/fatalities-from-terrorism...