Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

191–200 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#191

Earlier quoted context omitted.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

I think the threat of a tomahawk missile entering your building is a pretty good incentive to not fuck with US infrastructure but that's just me.

And the threat of a Topol-M nuclear missile with a yield of 800 KT detonating over New York is a pretty good incentive not to launch tomahawk missiles at office buildings located in nuclear-armed countries. If you ever wonder why unfriendly countries have nuclear ambitions, rhetoric like this is part of it.

How many people are you ready to kill over ransomware?

And weren't we just splitting hairs the other day over whether or not Belarus forcing an airplane flying over Belarus to land is excessive use of force? Apparently, ballistic missiles targeted at office buildings aren't?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#192
post #174

Let's look at the chain of events. Computing machinery becomes exponentially cheaper, and it gets pushed into all corners of industry. Shared computing becomes a thing, and the need to have a better model of security is realized as a lesson from Viet Nam, and the Capability Based Security model is born. Microprocessors again exponentially decrease the cost of computing, and Capability Based Security isn't required be…

As someone who isn’t a security expert, If you had a magic wand, what does this future look like to you? What is properly implemented security?

If under "proper security" the author means something that is impenetrable then such thing does not and will never exist in general. We can approach some reasonable level but with the current explosion of software, its complexity, insane degree of dependency, every button of your shirt becoming "smart" gizmo connected to Amazon and whatnot I believe the situation for now will only get worse.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#193

Earlier quoted context omitted.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

Because that analogy doesn’t hold. These cyber attacks are all but literally one bored kid and a computer. If the Russians sent one bored kid over here to blow up Hoover Dam, and that actually worked, we’d blame the people who put up the dam. The fact is that the correct and secure working of computer systems and networks has been severely neglected by companies in favor of their profit. If we are to have state respo…

These cyberattacks are all but literally boiler rooms full of bored Russian men wearing balaklavas and holding flashlights under their chins while they type.

https://www.google.com/search?q=holland+russian+hackers

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#194
post #140
post #106

Earlier quoted context omitted.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

Let's say you're the Chairman of the Board of Directors at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell, and they told the CEO about it, but he did nothing. He didn't allow the NSA to come in and fix anything; he also didn't take any action on his own to have people internal to the corporation fix it. What's your obvious response? Fire the CEO and install a new…

What CEOs have ever been fired for security breaches? If the "free market" doesn't care, why would any "I told you so" from the gov't make any difference. He'll have already taken his golden parachute and some poor CSO will take the fall.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#195
post #190
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

What exactly do you expect the NSA to do? This is entirely preventable. Something as simple as an offsite tape backup completely thwarts the attack. Do you want the NSA to send agents out to every Fortune 500 with a blank check so taxpayers can pay for a sane backup strategy to stop a problem we solved 30 years ago?

Backup Act of 2021

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#196
post #167

The title is a bit misleading. It is the U.S. Department of Justice that is promising to give the prosecution of these hacks a similar priority to terrorism. Not the entire United States government. Please keep this in mind before speculating about military actions or SEC regulation or new lays being passed or the intelligence community getting involved. This is about DoJ priorities.

“Relax, it’s only the Department of Justice” is not exactly reassuring. USAs have a 99+% conviction rate for a reason.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#197
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Well put.

It is an absurd argument up to the point of "reasonableness" that it's the responsibility of the company to defend against 100% of theoretical security vulnerabilities, in my opinion.

There will always be a vulnerability, unless some truly secure-by-design technology exists .. airgap, not vulnerable to social engineering .. ?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#198
post #173

Earlier quoted context omitted.

Except you can't do that, which is why the army metaphor doesn't work. (If you want to argue that this is a realistic response, please explain how doing so would not be acts of war, inviting both retaliation and much worse acts then justified by ours.)

I mean, it can be argued that trying to damage our infrastructure by hacking our computers is just as much of an act of war as firing a missile at our infrastructure. In some cases, the effect of the damage is the same. (I admit the 'cleanup' of the Colonial Pipeline problem is much less than it would be if someone blew up the pipeline, but the impact it had on our country was similar.) I don't expect the US to start…

It really depends how that attack is being organized and backed though - in most cases we'll be left with only a strong suspicion of who actually launched the attack and, due to the nature of technology, it's much more likely with a cyber attack for the real perpetrators to frame someone else.

Even once that's all decided, we'd need to figure out if war would be a reasonable response. I'd propose that one of the main reasons the US hasn't ever escalated the situation with North Korea, even if we ignore China's likely response, is that actually subduing the populace and occupying the country would likely be extremely difficult. It's unlikely that a thoroughly bombed North Korea would be any more stable and friendly than the current North Korea.

War is extremely inefficient at bettering the lives in any of the countries involved - there are times when it is necessary, but it should be avoided whenever possible.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#199
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#200
post #174

Let's look at the chain of events. Computing machinery becomes exponentially cheaper, and it gets pushed into all corners of industry. Shared computing becomes a thing, and the need to have a better model of security is realized as a lesson from Viet Nam, and the Capability Based Security model is born. Microprocessors again exponentially decrease the cost of computing, and Capability Based Security isn't required be…

As someone who isn’t a security expert, If you had a magic wand, what does this future look like to you? What is properly implemented security?

> Because the lessons of capability based security were ignored for decades, and not taught, the common consensus is that computers can never be made secure, and your best hope is to hire the smartest people in the world, at less than the average market rate, to secure your systems.

I presume the OP is a fan of capability-security and while I'm not an expert on capabilities, I agree they can go a _long_ way to mitigating risk. Unfortunately, none of the mainstream OSs even offer a smidge of a way of actually working with capabilities. Google's recently laughed Fuschia _does_ support capabilities out of the box, but they have a long way to go before they're regarded as mainstream.

Post reply on HN