Earlier quoted context omitted.
Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…
Let's say that you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They have a report with a list of vulnerabilities. If you don't fix them to your satisfaction, you will be fined in 2 months, 2 months after that you get fined and publicly reported as negligent, and 2 months after that you get fined again and your outstanding vulnerabilities will be published for everyone to take advantage of. Ho…
U.S. to give ransomware hacks similar priority as terrorism, official says
241–250 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#242I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#243I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
> the way that the pipeline-company ransomware hackers beat a hasty retreat was noticeably unusual, and already seemed to telegraph that the state was getting involved more...actively. Uh, there was no retreat - the company paid the ransom the day after the hack. https://www.theguardian.com/technology/2021/may/19/colonial-...
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#244That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#245Earlier quoted context omitted.
This is well within the scope of what the government should be doing--just as a country's navy protects merchant ships from pirates and the police protect shopkeepers from burglary. If a foreign military were launching physical attacks on your business we'd expect any government in the world to intervene. Realistically even with government support, effective cybersecurity is going to require significant private effor…
Should our society collectively pay for walls, doors and locks for every company in the country? How about paying for private security on every site? How about paying for personal bodyguards for every CEO? How about we all chip in to buy a password manager subscription for every private employee in the country? We should regulate and punish, not subsidize. The same way we have dealth with corporate recklessness for d…
As the parent comment said, I'd like to see the NSA working to get zero day vulnerabilities fixed as opposed to hoarding them for future exploitation. At least this is my perception, to be honest aside from a few examples I've heard of I don't actually know whether I've correctly characterized their activities, they may already be doing this.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#246I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
The HN crowd can sometimes have an issue with pragmatism. Sure, I'd love to live in a world where everyone follows best security practices 100% of the time, but this ain't it. Arguing how your imaginary perfect world should be gets us nowhere.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#247Earlier quoted context omitted.
They still need research on Elerium-115
How are we going to have enough turns to intercept all of these flying white TicTacs? No really, if we don't even have anything fast enough to keep-up with whatever the heck these are (if they're real). (Just don't equip your army with only nuke missiles because they destroy all of the good stuff and psy attacks would cross the streams.)
*Back when I was obsessed with this in the early 2000s I'd never heard of Elerium-115, it was always Element-115. Looks like the origin of the name is actually a game in 1994, but may not have become common until around 2013/2014.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#248Earlier quoted context omitted.
Let's say you're the Chairman of the Board of Directors at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell, and they told the CEO about it, but he did nothing. He didn't allow the NSA to come in and fix anything; he also didn't take any action on his own to have people internal to the corporation fix it. What's your obvious response? Fire the CEO and install a new…
What CEOs have ever been fired for security breaches? If the "free market" doesn't care, why would any "I told you so" from the gov't make any difference. He'll have already taken his golden parachute and some poor CSO will take the fall.
None. That's part of my point: the root problem is not actually security by itself, it's bad corporate governance. CEOs should be fired for such things, but they're not.
> If the "free market" doesn't care
Corporate governance is not a free market nowadays. It was more of one in the past (although an argument can be made that there were important non-free market forces even then), when most stock ownership was in the hands of individuals who at least had some incentive to hold boards of directors accountable for long-term stewardship, since they were investing with a long time horizon for their own retirement.
But now most stock ownership is in the hands of large mutual funds (since that's where most people's retirement funds are now), which don't care about long-term stewardship; they only care about short-term earnings. So corporations have a positive incentive to overlook things that, to be fixed, will require sacrificing short-term earnings for long-term stewardship. Individual investors never even see this; all they see is the overall rate of return of their mutual funds. So they don't realize the long-term consequences of what is going on and aren't able to apply free market incentives to correct things.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#249Earlier quoted context omitted.
Because proper cybersecurity should be treated as a cost of business, unlike the use of force which is an exclusive prerogative of the state. If large companies want the state to step in to absorb some of their costs, they should stop trying to avoid contributing to said state at every step of the way. If said public involvement came at the cost of partial ownership of companies requiring it, with complete disclosure…
That assumes all cyber threats can be averted by private corporations. It's difficult for a company to play effective defense against nation-state levels of cyber attack R&D. Yes, companies need better security than they have now, but they cant do it without help.
Tbh I trust the FAANG companies to run better security. Government is incompetent in this area.