Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

141–150 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#141

Earlier quoted context omitted.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

Because that analogy doesn’t hold. These cyber attacks are all but literally one bored kid and a computer. If the Russians sent one bored kid over here to blow up Hoover Dam, and that actually worked, we’d blame the people who put up the dam. The fact is that the correct and secure working of computer systems and networks has been severely neglected by companies in favor of their profit. If we are to have state respo…

> These cyber attacks are all but literally one bored kid and a computer.

Are you sure about that? A lot of this stuff is way more than just some bored kid. For the company I work for, there is almost certainly a group of well paid people who sit around every day trying to figure out new ways run scams using our site.

When there is financial motivation, people go through great efforts to get that $$$.

"Security" isn't some catch-all box you can check. It's a non stop game of whack-a-mole where your adversary spends each day getting around whatever you put into place.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#142
post #45

Earlier quoted context omitted.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

This is well within the scope of what the government should be doing--just as a country's navy protects merchant ships from pirates and the police protect shopkeepers from burglary. If a foreign military were launching physical attacks on your business we'd expect any government in the world to intervene. Realistically even with government support, effective cybersecurity is going to require significant private effor…

Should our society collectively pay for walls, doors and locks for every company in the country? How about paying for private security on every site? How about paying for personal bodyguards for every CEO? How about we all chip in to buy a password manager subscription for every private employee in the country?

We should regulate and punish, not subsidize. The same way we have dealth with corporate recklessness for decades.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#143
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

I agree, but I also don't mind the idea of drone striking ransomware guys...

Forum spammers too.... they are parasites who cost website owners tons and tons of time.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#144
post #134
post #131

Earlier quoted context omitted.

Surely the NSA can tell companies about their vulnerabilities without having to actually log in and fix them? "You have a server on 23.117.25.208:3999 which is vulnerable to CVE-2021-1120, fix it."

Sure! Realistically, I find it not credible to believe that nobody in big infrastructure companies with IT departments is aware that they have vulnerable systems. I find it far more likely that people are aware and people in positions of leadership making decisions about risk have decided that these risks are acceptable. Do you think getting an email from the NSA telling IT what they already know is going to change t…

> an email from the NSA telling IT what they already know

No, that's not what the email from NSA would say. It would not say "there is a risk of your systems being compromised by cyberattack" in general terms, which is what IT already knows. It would say "your systems are vulnerable to these specific attacks", which IT does not know. So yes, getting this new information should change the risk-benefit calculation dramatically.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#147
post #45
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#148
post #45

Earlier quoted context omitted.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo?

I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping foreign states.

Rather than compare it to armies, I think we should compare it to spies. If this is truly at the army level we could send a couple dozen missiles and the attackers would get the message. But there are reasons we don't do that though. First, we're not always sure who did what. Second, it's a political quagmire. Armies don't come to your house and help secure it from air strikes. Armies understand attack asymmetry and they hit back.

But when it comes to dealing with foreign spies there is a different playbook. The government helps organizations that are critical to national security secure their entry points and resources. They help, but they don't do everything.

This only works if the parties involved are interested in working with the government. Long after Nortel was first told of the Chinese hacking / stealing of their IP they were still woefully insecure. They went from being a third of the Canadian stock index to bankruptcy in a couple of years.

I don't actually think cybersecurity is possible. I've tried very hard to get governments to change, and there is some progress on the most fragrant violations, but the space is growing too fast and the domain is too maneuverable. I don't think it is possible. All we can hope for is some combination of more defence and realignment of incentives of the actors involved limiting the eventual damage.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#149
post #106

Earlier quoted context omitted.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

I’d prefer the NSA put in the hard effort to shed their reputation as spies and start by offering plain security advice in the open that can be verified by independent experts. The best way forward is for the NSA to focus on providing high quality security advice, best practices, and guidance to critical infrastructure. This doesn’t involve handing over the “keys to the kingdom”.

https://www.nsa.gov/What-We-Do/Cybersecurity/Advisories-Tech...

The NSA seems to agree with you. So do the Departments of Energy, Commerce, and Defense, all of which have various efforts to provide independently verifiable high quality security advice, best practices, and guidance. In some cases, they've been doing so for years.

But let's skip the NSA bit. Let's say you, CEO of Big Pipeline Co, have been called up by someone at The Office of Cybersecurity, Energy Security, and Emergency Response within the Department of Energy. They offer you all the advice and guidance you could wish for. Now it's up to you to budget resources. What do you do?

Realistically, you probably hand that advice off to your IT or software staff and hope for the best. Though I realize that reasonable people may differ on this point.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#150

So let's look at the chain of events: companies start to become monopolies, make billions of dollars that way. They become "too big too fail", important "infrastructure" for the US. Then, start to expose their user's data on public networks, and don't follow proper security procedures. Now, the public has to pay for the government to secure the magacorp networks! It's a non-stop scam, where they fail their (already s…

It is good, but it still does not beat JIT. First MBAs various JIT acolytes did everything to make sure there is nothing on hand or manufactured in US just in case it ate into the profits and then when the 'everything shortage' happened, they had the balls to run to the government asking for bailou.. sorry.. incentives to move manufacturing to US. It is fascinating to watch, because it is done with a very straight face and expensive lawyers.
Post reply on HN