Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

201–210 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#201
post #173

Earlier quoted context omitted.

I think the threat of a tomahawk missile entering your building is a pretty good incentive to not fuck with US infrastructure but that's just me.

Except you can't do that, which is why the army metaphor doesn't work. (If you want to argue that this is a realistic response, please explain how doing so would not be acts of war, inviting both retaliation and much worse acts then justified by ours.)

Follow the $$$.

If US government authorizes the NSA/CIA to infiltrate/attack all bitcoin exchanges that accept payments from wallet ID with ransomware, the problem likely be solved very quickly.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#202
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

Most of these are private companies, the NSA doesn't really have a role there.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#203
post #174

Let's look at the chain of events. Computing machinery becomes exponentially cheaper, and it gets pushed into all corners of industry. Shared computing becomes a thing, and the need to have a better model of security is realized as a lesson from Viet Nam, and the Capability Based Security model is born. Microprocessors again exponentially decrease the cost of computing, and Capability Based Security isn't required be…

As someone who isn’t a security expert, If you had a magic wand, what does this future look like to you? What is properly implemented security?

If I had a magic wand:

I'm not a "security expert", I have no encyclopedic knowledge of the ways of criminals. Let's agree that is well established.

I do know how computers work, down to the transistor level. I've been playing with them since 1978.

Rules I would impose:

Industrial control systems would be isolated from the internet by a unidirectional network. Data could get out, ONLY. You can have helpers on the inside and outside to handle things like buffering logs, etc.

If you need remote control of something industrial, it has to be on a physically separate network, airgapped from the world.

In Government, I would have NEVER connected the Office of Personnel Management system to the internet, except to allow data INBOUND through a data diode. All outbound queries would require passing through a human with the proper security clearance.

All sensitive or classified systems would be similarly isolated, and only allow ingress of data.

Multilevel secure computing would be required for all government systems. Red Teams would be used to test security periodically, run by the Inspector General.

Capability Based Security would be the norm. Most users wouldn't see much of a difference in their day to day interactions.

Bug bounties would be required for any commercial software vendor, with public disclosure after 1 year of all payouts. Bugs submitted that aren't paid would be disclosed in 6 months.

The NSA would shift roles from spying on everything just because they can, to first making sure nobody can spy on us, and only then spying on everyone else.

Also:

Email would require authentication on send

Null terminated strings would be abolished

Broadband would be nationalized and free to all

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#205
post #140

Earlier quoted context omitted.

Let's say you're the Chairman of the Board of Directors at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell, and they told the CEO about it, but he did nothing. He didn't allow the NSA to come in and fix anything; he also didn't take any action on his own to have people internal to the corporation fix it. What's your obvious response? Fire the CEO and install a new…

What CEOs have ever been fired for security breaches? If the "free market" doesn't care, why would any "I told you so" from the gov't make any difference. He'll have already taken his golden parachute and some poor CSO will take the fall.

There's a running joke in the security community that CSO stands for Chief Sacrificial Officer.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#206
post #174

Let's look at the chain of events. Computing machinery becomes exponentially cheaper, and it gets pushed into all corners of industry. Shared computing becomes a thing, and the need to have a better model of security is realized as a lesson from Viet Nam, and the Capability Based Security model is born. Microprocessors again exponentially decrease the cost of computing, and Capability Based Security isn't required be…

As someone who isn’t a security expert, If you had a magic wand, what does this future look like to you? What is properly implemented security?

Other thread: I don't have a magic wand

Things will continue to get worse. Google's Fuchsia and Genode are two capability based Operating Systems that are likely to be good enough to hack in the next year or so.

I expect 3-5 more years of this before enough experience is gained with Capability Based systems to finally cause mass adoption.

In the meanwhile, it would be nice to have a Raspberry Pi based data diode setup that can buffer all the standard stuff, as well as SCADA.

Also in the meanwhile, there is non-zero danger that Congress will use this as an excuse to purge the nation of general purpose computing available to the masses.

Also, the Military Industrial Complex will push for more funds from this.

Also, many a Startup will sell more security snake-oil.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#207

Before the yacht was launched, before it was first put in the water, there was a big problem with rats entering through the large holes in the bottom of the hull. To remedy the situation, the yacht builders began feeding a large number of cats around the base of the yacht while they finished the furnishings and painted the gold trims. The rat problem was solved and the happy day of launch is near.

They'll just hire a million little Dutch boys with SCUBA to put their fingers where less wholy materials up to ship-building codes belongs. Problem solved!

wholy -> holey? Definitely not wholy. That's partly wholly. Wholly is derived from whole (all/everything/complete) and not relating to a hole.

This is an adjective derived from a noun, so hole -> holey. It could be hole + ly -> holely but it isn't.

Now, we have the word pinned down. How on earth do you pronounce the bloody thing? For me (en_GB): hole-ee. The dash "-" is not a pause, I would run the word hole straight into the ee sound. The ee phoneme is quite short.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#208
post #174

Earlier quoted context omitted.

As someone who isn’t a security expert, If you had a magic wand, what does this future look like to you? What is properly implemented security?

Other thread: I don't have a magic wand Things will continue to get worse. Google's Fuchsia and Genode are two capability based Operating Systems that are likely to be good enough to hack in the next year or so. I expect 3-5 more years of this before enough experience is gained with Capability Based systems to finally cause mass adoption. In the meanwhile, it would be nice to have a Raspberry Pi based data diode setu…

> I expect 3-5 more years of this before enough experience is gained with Capability Based systems to finally cause mass adoption.

And distributed systems, at least for the web, are _finally_ starting to put capabilities in place. Embedded is a different world sadly.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#209
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff.

Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastructure critical to the nations security is getting shut down because of a corporate hack.

If the private sector wants to earn profit from these things they need to show they're competent enough to handle it.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#210
post #71
post #45

Earlier quoted context omitted.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

Sure, but they are up against state-sponsored, highly trained actors, and that's not a fair fight. This requires the resources of the US Government as their bodyguard.

Then it is also time to pay a lot more in taxes and keep less in the bank too

Which is it?

Post reply on HN