Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

251–260 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#251
post #162

Earlier quoted context omitted.

This is where the threat of retaliation comes in as a deterrent, and the country should be equipped to do so. But publicly subsidizing private cybersecurity is both impractical (how would that work exactly?) and would encourage underspending even further. Why do you think China or Russia prefer to hack foreign private competitors rather than sending a bunch of missiles on their infrastructure?

We publicly subsidize every other kind of security to some degree already. A company might have security guards, but police are certainly going to be there to provide a baseline policing the neighborhood, respond to calls, etc. And security via threat of retaliation does not sound like a practical or effective solution either: we already have plenty of capabilities in that area, and it didn't stop east coast oil & ga…

Then how about nationalizing that infrastructure, if it is so crucial for national security and the private sector is unwilling to spend enough to protect itself against threats? Let's not kid ourselves: this is first and foremost a matter of incentives and consequences rather than a lack of capabilities.

I don't see what the public could do better than private entities, besides absorbing their costs. The only way I can see it practically working is if the private sectors would allow government entities full access to their IT infrastructure, submit themselves to random controls, audits and checks, and bear sizeable fines if they're found to be negligent.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#252
post #244

“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.” That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#253
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

The HN crowd can sometimes have an issue with pragmatism. Sure, I'd love to live in a world where everyone follows best security practices 100% of the time, but this ain't it. Arguing how your imaginary perfect world should be gets us nowhere.

How much of these hacks would be prevented by adoption of simple preventions like Yubikeys for login, backing up data and images regularly, and encrypting data by default?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#255
post #244

“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.” That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.

If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#256

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#257

US Constitution empowers Congress to issue "Letters of Marque and Reprisal" - to wit grant permission for private entities (people, companies) to wage war on other private entities. Enacted to help shipping companies deal with pirates, applies today for the likes of ransomware perpetrators.

Seems like a reasonable solution - if Russia won't arrest Russians who extort Americans, why should America arrest Americans who extort Russians?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#258
post #190
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

What exactly do you expect the NSA to do? This is entirely preventable. Something as simple as an offsite tape backup completely thwarts the attack. Do you want the NSA to send agents out to every Fortune 500 with a blank check so taxpayers can pay for a sane backup strategy to stop a problem we solved 30 years ago?

"Something as simple as an offsite tape backup completely thwarts the attack."

Not true when they are also blackmailing companies to not release their internal data.

Even something as simple as a companies customer base and contracts with them can do a huge amount of damage to the company if it's publicly released. So paying a 2 million dollar ransom is the more profitable choice for the company.

Even if the company isn't doing anything illegal or that it's ashamed of.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#259
post #236

Earlier quoted context omitted.

nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…

The market doesn’t incentivize security until it is too late. A pipeline operator that passes security costs onto consumers will lose to one with lower security and lower costs. Serious, significant attacks might occur at year 5, when the company becomes a big enough target to make it worthwhile to attack. By this time, the company who did not invest as heavily in security has captured the market while the one that i…

>The market doesn’t incentivize security until it is too late.

That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#260

Earlier quoted context omitted.

Difference is if corporations and funds can't hold bitcoin/crypto - you're back to $1/BTC. The whole value proposition of BTC hype bubble bursts if it's illegal in a major market like USA. Don't doubt some cyberpunk nuts will keep playing with it.

Monero is banned by nearly every US exchange, and hard to buy with USD as a US National. It still maintains value and has seen growth. While BTC may burst, it wouldn't go to $1/BTC. it would go to a small percentage of what it is now, but still retain some value.

How is it hard to buy with USD as a US national?

I haven't bought any Monero, but I saw this website the other day: https://localmonero.co/

If that's legitimate, it seems pretty easy.

Post reply on HN