What, in that they're going to entrap kids into thinking they're doing it?
U.S. to give ransomware hacks similar priority as terrorism, official says
231–240 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#232Earlier quoted context omitted.
That assumes all cyber threats can be averted by private corporations. It's difficult for a company to play effective defense against nation-state levels of cyber attack R&D. Yes, companies need better security than they have now, but they cant do it without help.
This is where the threat of retaliation comes in as a deterrent, and the country should be equipped to do so. But publicly subsidizing private cybersecurity is both impractical (how would that work exactly?) and would encourage underspending even further. Why do you think China or Russia prefer to hack foreign private competitors rather than sending a bunch of missiles on their infrastructure?
And security via threat of retaliation does not sound like a practical or effective solution either: we already have plenty of capabilities in that area, and it didn't stop east coast oil & gas infrastructure from going down or a sizeable portion of the nation's meat processing from going the same way. These attacks are escalating rapidly, and relying in the free market to find a solution doesn't look like it's going to happen fast enough.
This needs to be a national, not (just) a private corporate issue because of the enormous national security implications involved in cyber attacks against infrastructure. When a single company's security failure can cause national chaos, there needs to be a nation-level approach to this.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#233What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.
Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…
They have a report with a list of vulnerabilities. If you don't fix them to your satisfaction, you will be fined in 2 months, 2 months after that you get fined and publicly reported as negligent, and 2 months after that you get fined again and your outstanding vulnerabilities will be published for everyone to take advantage of.
How much effort are you going to put in to securing your infrastructure?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#234They fucked up by targeting infrastructure. If they stuck with small companies they could keep doing it till the cows came home. But now they have governments against them so now they will be hunted down.
These groups aren't really "targeting" anyone. These ransomware attacks are as sophisticated as nigerian prince emails. Send out a lot of spam, wait for someone who clicks on it and is running outdated software and boom. Sooner or later you will encrypt something important enough to pay for.
Over the past few years, threat actors have shifted to much more targeted attacks that net higher Bitcoin payment returns for their efforts.
https://blog.cloudflare.com/targeted-ransomware-attack/
Edit: Commonly mentioned in the same breath:
- the move from just demanding a ransom for the key, to threatening publication of sensitive info
- trawling through the data to look for anything especially sensitive, as well as clues to what number to ask for in financial records
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#235Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#236Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…
Or they invested, but not in the right areas, or there was a new attack through a zero day.
They can be extremely competent in managing oil and gas (and the physical and operational safety that comes with it), but not be competent in Cybersecurity.
It’s real, hard costs today for something that may or may not happen and paying for controls that might prevent an attack. In the best case, as a customer, nothing happens. Whether improving the likelihood that nothing happen is worth a $1 or $3 per barrel premium (or if that $2 is justified) is a hazy mess and hard to make a decision around.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#237I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems.
That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents on. Since, there are no coherent standards now, just liability isn't useful. And the standards should involve actual topology, what kinds of information is allowed in and out at all.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#238Earlier quoted context omitted.
> an email from the NSA telling IT what they already know No, that's not what the email from NSA would say. It would not say "there is a risk of your systems being compromised by cyberattack" in general terms, which is what IT already knows. It would say "your systems are vulnerable to these specific attacks", which IT does not know. So yes, getting this new information should change the risk-benefit calculation dram…
I've been on the receiving end of various emails like that. They have details on specific systems and specific attacks. They're occasionally useful, but often not. Knowing that a particular app is vulnerable to XSS might be useful, if I have staff that can fix it and they have the spare cycles. For example, a hospital IT department might get an email telling them that their MRI is exposing remote desktop to the inter…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#239Earlier quoted context omitted.
I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.
Corporations pay tax too, if I was an American shareholder of a company that went to the wall due to a 0 day vulnerability that was known by the NSA I would not be happy. Imagine if you found out that the NSA knew about COVID but didn't develop or release a vaccine because they wanted to use it themselves, why is it really and different if corporations are people too?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#240I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Uh, there was no retreat - the company paid the ransom the day after the hack.
https://www.theguardian.com/technology/2021/may/19/colonial-...