So let's look at the chain of events: companies start to become monopolies, make billions of dollars that way. They become "too big too fail", important "infrastructure" for the US. Then, start to expose their user's data on public networks, and don't follow proper security procedures. Now, the public has to pay for the government to secure the magacorp networks! It's a non-stop scam, where they fail their (already s…
It is good, but it still does not beat JIT. First MBAs various JIT acolytes did everything to make sure there is nothing on hand or manufactured in US just in case it ate into the profits and then when the 'everything shortage' happened, they had the balls to run to the government asking for bailou.. sorry.. incentives to move manufacturing to US. It is fascinating to watch, because it is done with a very straight fa…
U.S. to give ransomware hacks similar priority as terrorism, official says
161–170 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#162Earlier quoted context omitted.
Because proper cybersecurity should be treated as a cost of business, unlike the use of force which is an exclusive prerogative of the state. If large companies want the state to step in to absorb some of their costs, they should stop trying to avoid contributing to said state at every step of the way. If said public involvement came at the cost of partial ownership of companies requiring it, with complete disclosure…
That assumes all cyber threats can be averted by private corporations. It's difficult for a company to play effective defense against nation-state levels of cyber attack R&D. Yes, companies need better security than they have now, but they cant do it without help.
Why do you think China or Russia prefer to hack foreign private competitors rather than sending a bunch of missiles on their infrastructure?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#163Earlier quoted context omitted.
> If we're going to Patriot Act the crud out of ransomware, Bitcoin is gonna be illegal Terrorist financing is illegal. Cash is not.
The majority of the uses of cash are legal. The majority of uses of Bitcoin are criminal. And bear in mind, Bitcoin hasn't just been a boon to ransomware, it's been a strategy to evade financial sanctions by countries like Iran: https://www.reuters.com/technology/iran-uses-crypto-mining-l... So there's a lot of reasons the US government just may find themselves happier without it.
There's a ridiculous amount of volume on Bitcoin and it's mostly moving to and from exchanges. There's no way a majority of those are illegal.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#164So let's look at the chain of events: companies start to become monopolies, make billions of dollars that way. They become "too big too fail", important "infrastructure" for the US. Then, start to expose their user's data on public networks, and don't follow proper security procedures. Now, the public has to pay for the government to secure the magacorp networks! It's a non-stop scam, where they fail their (already s…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#165Shared computing becomes a thing, and the need to have a better model of security is realized as a lesson from Viet Nam, and the Capability Based Security model is born.
Microprocessors again exponentially decrease the cost of computing, and Capability Based Security isn't required because all of the installations tend to have one or a handful of users.
The internet is born, and the cost of networking becomes exponentially cheaper, now all of those low security end users are connected together.
Systems become more powerful with the continuing drop in the cost of processor, memory and storage, so they become more complex. Nobody writes their own software any more, almost all coding is outsourced in some fashion. Security is only a concern if it trickles back to the original source as a problem.
A culture of "move fast and break things" pervades Silicon Valley, and the internet, and thus newer is always seen as better.
The lack of a security model at the base of all these systems is exploited for financial gain. Band-aid layers are added to try to patch the obviously inferior operating systems that pervade the land.
Because the lessons of capability based security were ignored for decades, and not taught, the common consensus is that computers can never be made secure, and your best hope is to hire the smartest people in the world, at less than the average market rate, to secure your systems.
And we repeatedly blame criminals, corporations, programmers, users, and now other countries, instead of solving the problem by properly implementing security.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#166Earlier quoted context omitted.
Sure! Realistically, I find it not credible to believe that nobody in big infrastructure companies with IT departments is aware that they have vulnerable systems. I find it far more likely that people are aware and people in positions of leadership making decisions about risk have decided that these risks are acceptable. Do you think getting an email from the NSA telling IT what they already know is going to change t…
> an email from the NSA telling IT what they already know No, that's not what the email from NSA would say. It would not say "there is a risk of your systems being compromised by cyberattack" in general terms, which is what IT already knows. It would say "your systems are vulnerable to these specific attacks", which IT does not know. So yes, getting this new information should change the risk-benefit calculation dram…
For example, a hospital IT department might get an email telling them that their MRI is exposing remote desktop to the internet with default credentials. They know that. They don't change it because if they do, their vendor will drop support. This is a real thing that real medical hardware has to deal with, and it's only slowly getting better.
A big industrial company might easily have it worse than a hospital. Fixing the specific CVE on a specific port on a specific machine might mean having to retire a whole series of obscure, niche bits of SCADA hardware that don't support anything modern. It's like all those IoT gadgets that don't support 5GHz, writ large.
https://en.wikipedia.org/wiki/SCADA#Security_issues
Somewhere between those two, you have your well-run Windows network. It's probably a month to several months of patching behind. IT has a whole process to test any new patches for stability and compatibility with line-of-business software to ensure that nothing breaks. Knowing that their systems are vulnerable to the CVE that's fixed by a patch they're testing - or tested and found broke something important - might not always help them very much.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#167Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#168What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.
I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#169Clearly most of these things are not "features" and therefore are a cost. Furthermore, since every company must impeliment these, the cost of security for society at large is an O(N) problem.
We must set up a system that mitigates the unpayable O(N) cost of security.
Pen testing/Bug Bounty/verification is probably the most easily scalable problem to solve. Whether you unleash hackers on companies by indemnifying them or specifically pay for Project Zero like entities or turn our own nation-state attackers against US companies with the weight of the US government behind it, it seems quite feasible to create scaled cybersecurity monitoring which can then better inform both technical solutions and policy solutions.
Once companies know they have poor security and once a business can see being breached as a certainty rather than a potential risk, I think the free market can probably solve the problem.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#170So let's look at the chain of events: companies start to become monopolies, make billions of dollars that way. They become "too big too fail", important "infrastructure" for the US. Then, start to expose their user's data on public networks, and don't follow proper security procedures. Now, the public has to pay for the government to secure the magacorp networks! It's a non-stop scam, where they fail their (already s…
I too dislike megacorps, but you could say the same thing about a business being robbed - they most likely could have done something to prevent it but police will still respond and not charge them for it.