Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

161–170 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#161

So let's look at the chain of events: companies start to become monopolies, make billions of dollars that way. They become "too big too fail", important "infrastructure" for the US. Then, start to expose their user's data on public networks, and don't follow proper security procedures. Now, the public has to pay for the government to secure the magacorp networks! It's a non-stop scam, where they fail their (already s…

It is good, but it still does not beat JIT. First MBAs various JIT acolytes did everything to make sure there is nothing on hand or manufactured in US just in case it ate into the profits and then when the 'everything shortage' happened, they had the balls to run to the government asking for bailou.. sorry.. incentives to move manufacturing to US. It is fascinating to watch, because it is done with a very straight fa…

It is all another chapter of the US war against its own people. All the money is going to scammers, I mean, mega corps.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#162
post #125

Earlier quoted context omitted.

Because proper cybersecurity should be treated as a cost of business, unlike the use of force which is an exclusive prerogative of the state. If large companies want the state to step in to absorb some of their costs, they should stop trying to avoid contributing to said state at every step of the way. If said public involvement came at the cost of partial ownership of companies requiring it, with complete disclosure…

That assumes all cyber threats can be averted by private corporations. It's difficult for a company to play effective defense against nation-state levels of cyber attack R&D. Yes, companies need better security than they have now, but they cant do it without help.

This is where the threat of retaliation comes in as a deterrent, and the country should be equipped to do so. But publicly subsidizing private cybersecurity is both impractical (how would that work exactly?) and would encourage underspending even further.

Why do you think China or Russia prefer to hack foreign private competitors rather than sending a bunch of missiles on their infrastructure?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#163

Earlier quoted context omitted.

> If we're going to Patriot Act the crud out of ransomware, Bitcoin is gonna be illegal Terrorist financing is illegal. Cash is not.

The majority of the uses of cash are legal. The majority of uses of Bitcoin are criminal. And bear in mind, Bitcoin hasn't just been a boon to ransomware, it's been a strategy to evade financial sanctions by countries like Iran: https://www.reuters.com/technology/iran-uses-crypto-mining-l... So there's a lot of reasons the US government just may find themselves happier without it.

Criminal? Maybe in 2013 Silk Road days.

There's a ridiculous amount of volume on Bitcoin and it's mostly moving to and from exchanges. There's no way a majority of those are illegal.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#164

So let's look at the chain of events: companies start to become monopolies, make billions of dollars that way. They become "too big too fail", important "infrastructure" for the US. Then, start to expose their user's data on public networks, and don't follow proper security procedures. Now, the public has to pay for the government to secure the magacorp networks! It's a non-stop scam, where they fail their (already s…

Nailed it in the first try!

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#165
Let's look at the chain of events. Computing machinery becomes exponentially cheaper, and it gets pushed into all corners of industry.

Shared computing becomes a thing, and the need to have a better model of security is realized as a lesson from Viet Nam, and the Capability Based Security model is born.

Microprocessors again exponentially decrease the cost of computing, and Capability Based Security isn't required because all of the installations tend to have one or a handful of users.

The internet is born, and the cost of networking becomes exponentially cheaper, now all of those low security end users are connected together.

Systems become more powerful with the continuing drop in the cost of processor, memory and storage, so they become more complex. Nobody writes their own software any more, almost all coding is outsourced in some fashion. Security is only a concern if it trickles back to the original source as a problem.

A culture of "move fast and break things" pervades Silicon Valley, and the internet, and thus newer is always seen as better.

The lack of a security model at the base of all these systems is exploited for financial gain. Band-aid layers are added to try to patch the obviously inferior operating systems that pervade the land.

Because the lessons of capability based security were ignored for decades, and not taught, the common consensus is that computers can never be made secure, and your best hope is to hire the smartest people in the world, at less than the average market rate, to secure your systems.

And we repeatedly blame criminals, corporations, programmers, users, and now other countries, instead of solving the problem by properly implementing security.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#166
post #144
post #134

Earlier quoted context omitted.

Sure! Realistically, I find it not credible to believe that nobody in big infrastructure companies with IT departments is aware that they have vulnerable systems. I find it far more likely that people are aware and people in positions of leadership making decisions about risk have decided that these risks are acceptable. Do you think getting an email from the NSA telling IT what they already know is going to change t…

> an email from the NSA telling IT what they already know No, that's not what the email from NSA would say. It would not say "there is a risk of your systems being compromised by cyberattack" in general terms, which is what IT already knows. It would say "your systems are vulnerable to these specific attacks", which IT does not know. So yes, getting this new information should change the risk-benefit calculation dram…

I've been on the receiving end of various emails like that. They have details on specific systems and specific attacks. They're occasionally useful, but often not. Knowing that a particular app is vulnerable to XSS might be useful, if I have staff that can fix it and they have the spare cycles.

For example, a hospital IT department might get an email telling them that their MRI is exposing remote desktop to the internet with default credentials. They know that. They don't change it because if they do, their vendor will drop support. This is a real thing that real medical hardware has to deal with, and it's only slowly getting better.

A big industrial company might easily have it worse than a hospital. Fixing the specific CVE on a specific port on a specific machine might mean having to retire a whole series of obscure, niche bits of SCADA hardware that don't support anything modern. It's like all those IoT gadgets that don't support 5GHz, writ large.

https://en.wikipedia.org/wiki/SCADA#Security_issues

Somewhere between those two, you have your well-run Windows network. It's probably a month to several months of patching behind. IT has a whole process to test any new patches for stability and compatibility with line-of-business software to ensure that nothing breaks. Knowing that their systems are vulnerable to the CVE that's fixed by a patch they're testing - or tested and found broke something important - might not always help them very much.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#167
The title is a bit misleading. It is the U.S. Department of Justice that is promising to give the prosecution of these hacks a similar priority to terrorism. Not the entire United States government. Please keep this in mind before speculating about military actions or SEC regulation or new lays being passed or the intelligence community getting involved. This is about DoJ priorities.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#168
post #45
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

Not all corps are mega corps. Some might be mom and pop, your corner grocery, mechanics shop, tailor, dog groomer, etc.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#169
Every business owner is either ignorant (default), has made the wilful calculation that risk A valley company that takes security seriously will: Hire experts. Scope attack surface/risks. Implement direct mitigations. Implement policy. Implement defense in depth. Develop a system capable of discovering indicators of compromise (IOC's). Verify security via bug bounty and pen testing, both internal and external.

Clearly most of these things are not "features" and therefore are a cost. Furthermore, since every company must impeliment these, the cost of security for society at large is an O(N) problem.

We must set up a system that mitigates the unpayable O(N) cost of security.

Pen testing/Bug Bounty/verification is probably the most easily scalable problem to solve. Whether you unleash hackers on companies by indemnifying them or specifically pay for Project Zero like entities or turn our own nation-state attackers against US companies with the weight of the US government behind it, it seems quite feasible to create scaled cybersecurity monitoring which can then better inform both technical solutions and policy solutions.

Once companies know they have poor security and once a business can see being breached as a certainty rather than a potential risk, I think the free market can probably solve the problem.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#170
post #160

So let's look at the chain of events: companies start to become monopolies, make billions of dollars that way. They become "too big too fail", important "infrastructure" for the US. Then, start to expose their user's data on public networks, and don't follow proper security procedures. Now, the public has to pay for the government to secure the magacorp networks! It's a non-stop scam, where they fail their (already s…

I too dislike megacorps, but you could say the same thing about a business being robbed - they most likely could have done something to prevent it but police will still respond and not charge them for it.

Sure, the cops will also say your a dumbfuck for transporting hundreds of millions of dollars on an open bed truck in the middle of Detroit.
Post reply on HN