Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

241–250 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#241
post #233
post #106

Earlier quoted context omitted.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

Let's say that you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They have a report with a list of vulnerabilities. If you don't fix them to your satisfaction, you will be fined in 2 months, 2 months after that you get fined and publicly reported as negligent, and 2 months after that you get fined again and your outstanding vulnerabilities will be published for everyone to take advantage of. Ho…

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#242
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

The HN crowd can sometimes have an issue with pragmatism. Sure, I'd love to live in a world where everyone follows best security practices 100% of the time, but this ain't it. Arguing how your imaginary perfect world should be gets us nowhere.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#243
post #240
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

> the way that the pipeline-company ransomware hackers beat a hasty retreat was noticeably unusual, and already seemed to telegraph that the state was getting involved more...actively. Uh, there was no retreat - the company paid the ransom the day after the hack. https://www.theguardian.com/technology/2021/may/19/colonial-...

I think they meant the folks providing the ransomware as-a-service, who basically said "yeah we provide criminal services but we don't endorse their use for crimes that big, so we'll be more careful who we sell to."

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#244
“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.”

That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#245
post #142

Earlier quoted context omitted.

This is well within the scope of what the government should be doing--just as a country's navy protects merchant ships from pirates and the police protect shopkeepers from burglary. If a foreign military were launching physical attacks on your business we'd expect any government in the world to intervene. Realistically even with government support, effective cybersecurity is going to require significant private effor…

Should our society collectively pay for walls, doors and locks for every company in the country? How about paying for private security on every site? How about paying for personal bodyguards for every CEO? How about we all chip in to buy a password manager subscription for every private employee in the country? We should regulate and punish, not subsidize. The same way we have dealth with corporate recklessness for d…

I'm not sure what specifically is being proposed here. I gave some specific examples of government actions to protect its citizens engaging in commerce going back hundreds if not thousands of years. I'm not aware of any government which has paid for doors, locks, or walls for every company in their country, I suspect any action taken by the NSA would be guided by similar restraint.

As the parent comment said, I'd like to see the NSA working to get zero day vulnerabilities fixed as opposed to hoarding them for future exploitation. At least this is my perception, to be honest aside from a few examples I've heard of I don't actually know whether I've correctly characterized their activities, they may already be doing this.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#246
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

The HN crowd can sometimes have an issue with pragmatism. Sure, I'd love to live in a world where everyone follows best security practices 100% of the time, but this ain't it. Arguing how your imaginary perfect world should be gets us nowhere.

Something about security in particular brings out the puritanical streak many engineers have.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#247
post #23

Earlier quoted context omitted.

They still need research on Elerium-115

How are we going to have enough turns to intercept all of these flying white TicTacs? No really, if we don't even have anything fast enough to keep-up with whatever the heck these are (if they're real). (Just don't equip your army with only nuke missiles because they destroy all of the good stuff and psy attacks would cross the streams.)

I think that's what they're referring to. Elerium-115 seems to be the current name* for Element-115, which is said to have antigravity properties and so is how UFOs are able to do their impossible maneuvers.

*Back when I was obsessed with this in the early 2000s I'd never heard of Elerium-115, it was always Element-115. Looks like the origin of the name is actually a game in 1994, but may not have become common until around 2013/2014.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#248
post #140

Earlier quoted context omitted.

Let's say you're the Chairman of the Board of Directors at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell, and they told the CEO about it, but he did nothing. He didn't allow the NSA to come in and fix anything; he also didn't take any action on his own to have people internal to the corporation fix it. What's your obvious response? Fire the CEO and install a new…

What CEOs have ever been fired for security breaches? If the "free market" doesn't care, why would any "I told you so" from the gov't make any difference. He'll have already taken his golden parachute and some poor CSO will take the fall.

> What CEOs have ever been fired for security breaches?

None. That's part of my point: the root problem is not actually security by itself, it's bad corporate governance. CEOs should be fired for such things, but they're not.

> If the "free market" doesn't care

Corporate governance is not a free market nowadays. It was more of one in the past (although an argument can be made that there were important non-free market forces even then), when most stock ownership was in the hands of individuals who at least had some incentive to hold boards of directors accountable for long-term stewardship, since they were investing with a long time horizon for their own retirement.

But now most stock ownership is in the hands of large mutual funds (since that's where most people's retirement funds are now), which don't care about long-term stewardship; they only care about short-term earnings. So corporations have a positive incentive to overlook things that, to be fixed, will require sacrificing short-term earnings for long-term stewardship. Individual investors never even see this; all they see is the overall rate of return of their mutual funds. So they don't realize the long-term consequences of what is going on and aren't able to apply free market incentives to correct things.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#249
post #125

Earlier quoted context omitted.

Because proper cybersecurity should be treated as a cost of business, unlike the use of force which is an exclusive prerogative of the state. If large companies want the state to step in to absorb some of their costs, they should stop trying to avoid contributing to said state at every step of the way. If said public involvement came at the cost of partial ownership of companies requiring it, with complete disclosure…

That assumes all cyber threats can be averted by private corporations. It's difficult for a company to play effective defense against nation-state levels of cyber attack R&D. Yes, companies need better security than they have now, but they cant do it without help.

The feds can’t even secure all their own systems. We had the OPM hack which resulted in the personal information of federal employees exfultrated who knows where. Also the federal government were still using passwords that were exposed in the breach 3 years after https://www.forbes.com/sites/leemathews/2018/11/15/office-of....

Tbh I trust the FAANG companies to run better security. Government is incompetent in this area.

Post reply on HN