Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

221–230 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#221

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

If you leave your houses front door open and a giant sign that says "please come rob me" then yes you deserve some of the blame. That's the case with a lot of these companies who: a) Have pitiful/non-existent bug bounty programs (or even worst, prosecutes white hat hackers who raise issues) b) Prioritizing exec bonuses instead of investing in InfoSec

> If you leave your houses front door open and a giant sign that says "please come rob me"

Sure, but as much as we might roll our eyes at the state of corporate security, this is a disingenuous metaphor.

It's neglect and incompetence. It's repeatedly forgetting to lock the door even after every neighbor has been robbed.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#222

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

If you leave your houses front door open and a giant sign that says "please come rob me" then yes you deserve some of the blame. That's the case with a lot of these companies who: a) Have pitiful/non-existent bug bounty programs (or even worst, prosecutes white hat hackers who raise issues) b) Prioritizing exec bonuses instead of investing in InfoSec

I'll take Blaming the Victim for $200 Alex.

(AKA: The "What was she wearing?" defense.)

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#223
post #191

Earlier quoted context omitted.

I think the threat of a tomahawk missile entering your building is a pretty good incentive to not fuck with US infrastructure but that's just me.

And the threat of a Topol-M nuclear missile with a yield of 800 KT detonating over New York is a pretty good incentive not to launch tomahawk missiles at office buildings located in nuclear-armed countries. If you ever wonder why unfriendly countries have nuclear ambitions, rhetoric like this is part of it. How many people are you ready to kill over ransomware ? And weren't we just splitting hairs the other day over…

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#224
post #218

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

You have a point, but I also can expect a minimum level of competance and caring about the data you have stewardship over. Sure, given enough time and motivation anyone can probably break into anything, but that isn't an excuse to let the password for the FTP server that pushes out updates be 'password123'. Here's the problem companies have absolutely no incentive to care about Security. Several years back some hacke…

The concept of Moral Hazard is important here, which basically states that there is a lack of incentive to guard against risk where one is protected from its consequences.

In a lot of cases the execs of these companies will continue to collect a large bonus, despite the fact that they utterly failed their customers.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#225
post #198

Earlier quoted context omitted.

I mean, it can be argued that trying to damage our infrastructure by hacking our computers is just as much of an act of war as firing a missile at our infrastructure. In some cases, the effect of the damage is the same. (I admit the 'cleanup' of the Colonial Pipeline problem is much less than it would be if someone blew up the pipeline, but the impact it had on our country was similar.) I don't expect the US to start…

It really depends how that attack is being organized and backed though - in most cases we'll be left with only a strong suspicion of who actually launched the attack and, due to the nature of technology, it's much more likely with a cyber attack for the real perpetrators to frame someone else. Even once that's all decided, we'd need to figure out if war would be a reasonable response. I'd propose that one of the main…

> even if we ignore China's likely response

China is literally the only reason the US tolerates North Korea. And China solely tolerates North Korea because it causes all sorts of irritation for the US. Arguably, it would be better off for everyone living in North Korea if one of those two powers annexed it outright, but geopolitics loves backwater proxy wars.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#226
post #190
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

What exactly do you expect the NSA to do? This is entirely preventable. Something as simple as an offsite tape backup completely thwarts the attack. Do you want the NSA to send agents out to every Fortune 500 with a blank check so taxpayers can pay for a sane backup strategy to stop a problem we solved 30 years ago?

Wasn't NSA involved in finding Osama or Suleimani? Find them, then send In Tom Cruise, drone strike what have you. Israel isnt targeted cuz thats what their response woule be to this type of stuff.

Are Russia or China going to react any different from Iran or Pakistan? They currently think they are untouchable. That needs to change.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#227
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Usually people here want government to stay out of the way of business, or especially not to compete with business. I agree with you, but it isn't necessarily entirely a pure-business perspective.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#228
post #45
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

Corporations pay tax too, if I was an American shareholder of a company that went to the wall due to a 0 day vulnerability that was known by the NSA I would not be happy. Imagine if you found out that the NSA knew about COVID but didn't develop or release a vaccine because they wanted to use it themselves, why is it really and different if corporations are people too?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#229
post #198

Earlier quoted context omitted.

It really depends how that attack is being organized and backed though - in most cases we'll be left with only a strong suspicion of who actually launched the attack and, due to the nature of technology, it's much more likely with a cyber attack for the real perpetrators to frame someone else. Even once that's all decided, we'd need to figure out if war would be a reasonable response. I'd propose that one of the main…

> even if we ignore China's likely response China is literally the only reason the US tolerates North Korea. And China solely tolerates North Korea because it causes all sorts of irritation for the US. Arguably, it would be better off for everyone living in North Korea if one of those two powers annexed it outright, but geopolitics loves backwater proxy wars.

> China is literally the only reason the US tolerates North Korea.

Closer to the active phase of the Korean War, the USSR was also a factor. Today, the US distaste for instability, and naiton-building, and North Korea not having a hoard of oil or something similar to overcome that distaste is also a reason, today.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#230
post #97

Earlier quoted context omitted.

> If we're going to Patriot Act the crud out of ransomware, Bitcoin is gonna be illegal Terrorist financing is illegal. Cash is not.

Try taking $10,001 in cash into the US and tell me that again

> Try taking $10,001 in cash into the US and tell me that again

You have to declare it. You’ll probably get follow up questions on how you got it and why a wire doesn’t work. But otherwise, large quantities of cash transit the U.S. border all the time.

Post reply on HN