Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

131–140 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#131
post #106
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

Surely the NSA can tell companies about their vulnerabilities without having to actually log in and fix them? "You have a server on 23.117.25.208:3999 which is vulnerable to CVE-2021-1120, fix it."

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#132

Earlier quoted context omitted.

> What happens when a company is a victim of a ransomware attack and OFAC puts a wallet on an exclusion list? That wallets gets tainted? Its coins become less valuable? Marked wallets have been an obvious thing coming down the pipes.

The risk isn’t just to the person holding the wallet: it’s the risk of OFAC sanctions hitting the exchanges that takes dirty BTC and pays USD. So now, know your customer turns from “be sure I don’t send USD to a specially designated national” to “be sure I never accept crypto from a burnt wallet.”

Except you can't choose whether you accept or not - the transactions sending BTC into your wallet are not at your discretion, you can't 'reject' them.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#133

Earlier quoted context omitted.

Yeah, that's what happened with drugs. The price of drugs actually dropped to zero and it's now impossible to get LSD.

Difference is if corporations and funds can't hold bitcoin/crypto - you're back to $1/BTC. The whole value proposition of BTC hype bubble bursts if it's illegal in a major market like USA. Don't doubt some cyberpunk nuts will keep playing with it.

Monero is banned by nearly every US exchange, and hard to buy with USD as a US National. It still maintains value and has seen growth.

While BTC may burst, it wouldn't go to $1/BTC. it would go to a small percentage of what it is now, but still retain some value.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#134
post #131
post #106

Earlier quoted context omitted.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

Surely the NSA can tell companies about their vulnerabilities without having to actually log in and fix them? "You have a server on 23.117.25.208:3999 which is vulnerable to CVE-2021-1120, fix it."

Sure!

Realistically, I find it not credible to believe that nobody in big infrastructure companies with IT departments is aware that they have vulnerable systems. I find it far more likely that people are aware and people in positions of leadership making decisions about risk have decided that these risks are acceptable.

Do you think getting an email from the NSA telling IT what they already know is going to change those calculations? My experience with bug bounty programs is that leaders who make risk decisions are more likely to shrug and say "I know, we're OK with that risk".

I realize that this is a personal judgment, and other people may have had wildly different experiences.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#135
post #125

Earlier quoted context omitted.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

Because proper cybersecurity should be treated as a cost of business, unlike the use of force which is an exclusive prerogative of the state. If large companies want the state to step in to absorb some of their costs, they should stop trying to avoid contributing to said state at every step of the way. If said public involvement came at the cost of partial ownership of companies requiring it, with complete disclosure…

public ownership of tech companies is the last thing we need. I'm with you on paying their taxes, but partial public ownership is a bridge too far

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#136
So let's look at the chain of events: companies start to become monopolies, make billions of dollars that way. They become "too big too fail", important "infrastructure" for the US. Then, start to expose their user's data on public networks, and don't follow proper security procedures. Now, the public has to pay for the government to secure the magacorp networks! It's a non-stop scam, where they fail their (already small) responsibilities and use public funds to increase their monopolies!

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#137

Earlier quoted context omitted.

You won't be seeing 30%+ gains when they're throwing people in prison for it. Most drug users are never prosecuted. But the threat of prosecution does very little to affect the quality of their purchase, relative to what it would do to BTC market as a whole.

Yeah, illegal things definitely don't end being sold above market price.

If you can't exchange BTC for dollars other than in person, and if you can't use it to purchase goods online other than via TOR, that is not going to increase the price. It's going to crash it.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#138
post #106
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

> They offer to patch your systems for you.

That is certainly not how it works. See the links others posted for context. NSA is more likely to inform you of the vulnerabilities and associated mitigations.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#140
post #106
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

Let's say you're the Chairman of the Board of Directors at Big Pipeline Co. One day your phone rings. It's the NSA.

They say your systems are vulnerable as hell, and they told the CEO about it, but he did nothing. He didn't allow the NSA to come in and fix anything; he also didn't take any action on his own to have people internal to the corporation fix it.

What's your obvious response? Fire the CEO and install a new one who will direct the appropriate resources to fixing the problem.

Post reply on HN