Earlier quoted context omitted.
That assumes all cyber threats can be averted by private corporations. It's difficult for a company to play effective defense against nation-state levels of cyber attack R&D. Yes, companies need better security than they have now, but they cant do it without help.
The feds can’t even secure all their own systems. We had the OPM hack which resulted in the personal information of federal employees exfultrated who knows where. Also the federal government were still using passwords that were exposed in the breach 3 years after https://www.forbes.com/sites/leemathews/2018/11/15/office-of... . Tbh I trust the FAANG companies to run better security. Government is incompetent in this…
U.S. to give ransomware hacks similar priority as terrorism, official says
271–280 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#272Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#273“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.” That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.
If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#274“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.” That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.
If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?
Every ransom paid just funds and encourages the next hack. The social damage is deserving of a large fine (i.e. 10x the ransom).
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#275I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#276I really hope this copies the principal of not negotiating with terrorists. Everytime we pay out ransomware it just encourages more ransomware.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#277Earlier quoted context omitted.
All that takes is the adversary bringing one person within the firewall (that is, within the country).
1) All security has weaknesses or work-arounds. That doesn't mean that all security is worthless. Forcing adversaries to take more risks and expend more effort is kind of the whole point, and that's exactly what you're talking about. 2) Are you arguing that the actual Great Firewall, a real thing we see actually working on a massive scale, does not make it much harder for foreigners to cyber-attack China? 3) See my o…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#278Earlier quoted context omitted.
We publicly subsidize every other kind of security to some degree already. A company might have security guards, but police are certainly going to be there to provide a baseline policing the neighborhood, respond to calls, etc. And security via threat of retaliation does not sound like a practical or effective solution either: we already have plenty of capabilities in that area, and it didn't stop east coast oil & ga…
Then how about nationalizing that infrastructure, if it is so crucial for national security and the private sector is unwilling to spend enough to protect itself against threats? Let's not kid ourselves: this is first and foremost a matter of incentives and consequences rather than a lack of capabilities. I don't see what the public could do better than private entities, besides absorbing their costs. The only way I…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#279Earlier quoted context omitted.
Sometimes simple preventative measures aren't as simple as they might sound. How would you go about integrating yubikeys for login into multi-decade-old SCADA hardware systems? I'm a security specialist and I honestly wouldn't know where to begin.
Is that the case with all of these hacks? How many would be prevented, is what I'm wondering? My mother's hospital was hacked this week and now they can't even clock in but they're not running SCADA
You ask a very wise question. Unfortunately, I think it's unknownable. The best we know is that the answer is more than none and less than all. The more you get towards "all" the more prevention measures cost to implement. For instance, managing a mature backup and imaging operation at scale may be conceptually simple but is both complex in practice and far from free.
Hospitals in particular are the scene of some interesting conflicts between security and usability. There are a lot of stories about health staff doing things like jamming open medication dispensing machines so that they could get on with the job instead of dealing with security measures they experienced largely as obstacles.
Can you imagine throwing yubikeys into a scenario like that, where people already have an adversarial relationship with IT and security measures? What do you think is going to happen when someone forgets their key and can't send an x-ray to the remote radiology center? I have my guesses.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#280Earlier quoted context omitted.
If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?
The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping f…
They can publish best practices, research vulnerabilities, provide educational support, and generally do all the kinds of things governments do to encourage the right behaviors. We have some of this, but at some point, switched to the sexier "the best defense is a good offense". Likely because defense is hard.