Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

271–280 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#271
post #249

Earlier quoted context omitted.

That assumes all cyber threats can be averted by private corporations. It's difficult for a company to play effective defense against nation-state levels of cyber attack R&D. Yes, companies need better security than they have now, but they cant do it without help.

The feds can’t even secure all their own systems. We had the OPM hack which resulted in the personal information of federal employees exfultrated who knows where. Also the federal government were still using passwords that were exposed in the breach 3 years after https://www.forbes.com/sites/leemathews/2018/11/15/office-of... . Tbh I trust the FAANG companies to run better security. Government is incompetent in this…

Many times it's not the government securing their systems, they've outsourced it to places like SolarWinds. Maybe they would do a better job if political pressure didn't push for more and more privatization of critical operations.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#273
post #244

“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.” That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.

If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?

Restore from backup.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#274
post #244

“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.” That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.

If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?

They'd restore from backups, which is already what they did even after paying the ransom. More importantly, would the hack have happened in first place if they knew there was no chance of being paid?

Every ransom paid just funds and encourages the next hack. The social damage is deserving of a large fine (i.e. 10x the ransom).

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#275
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

It's not any different than the war on drugs. The gov't can't really think in a different manner than just black and white. The world is made up of shades of gray, and it's just too difficult to create legislation to handle shades of gray.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#276

I really hope this copies the principal of not negotiating with terrorists. Everytime we pay out ransomware it just encourages more ransomware.

If they treat them as terrorists, then paying a ransom is funding terrorists. Which is how it it should be treated.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#277

Earlier quoted context omitted.

All that takes is the adversary bringing one person within the firewall (that is, within the country).

1) All security has weaknesses or work-arounds. That doesn't mean that all security is worthless. Forcing adversaries to take more risks and expend more effort is kind of the whole point, and that's exactly what you're talking about. 2) Are you arguing that the actual Great Firewall, a real thing we see actually working on a massive scale, does not make it much harder for foreigners to cyber-attack China? 3) See my o…

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#278
post #251

Earlier quoted context omitted.

We publicly subsidize every other kind of security to some degree already. A company might have security guards, but police are certainly going to be there to provide a baseline policing the neighborhood, respond to calls, etc. And security via threat of retaliation does not sound like a practical or effective solution either: we already have plenty of capabilities in that area, and it didn't stop east coast oil & ga…

Then how about nationalizing that infrastructure, if it is so crucial for national security and the private sector is unwilling to spend enough to protect itself against threats? Let's not kid ourselves: this is first and foremost a matter of incentives and consequences rather than a lack of capabilities. I don't see what the public could do better than private entities, besides absorbing their costs. The only way I…

The government could set & enforce standards for levels of security and disaster recovery, especially if critical systems. It could not just research but also pass on knowledge of vulnerabilities. I don't expect the government to actually run the security. I expect the government to provide the framework and tools so that everyone doesn't have to figure it out on their own.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#279
post #262

Earlier quoted context omitted.

Sometimes simple preventative measures aren't as simple as they might sound. How would you go about integrating yubikeys for login into multi-decade-old SCADA hardware systems? I'm a security specialist and I honestly wouldn't know where to begin.

Is that the case with all of these hacks? How many would be prevented, is what I'm wondering? My mother's hospital was hacked this week and now they can't even clock in but they're not running SCADA

SCADA's a good example of systems that are difficult to secure for complex reasons. There are many others.

You ask a very wise question. Unfortunately, I think it's unknownable. The best we know is that the answer is more than none and less than all. The more you get towards "all" the more prevention measures cost to implement. For instance, managing a mature backup and imaging operation at scale may be conceptually simple but is both complex in practice and far from free.

Hospitals in particular are the scene of some interesting conflicts between security and usability. There are a lot of stories about health staff doing things like jamming open medication dispensing machines so that they could get on with the job instead of dealing with security measures they experienced largely as obstacles.

Can you imagine throwing yubikeys into a scenario like that, where people already have an adversarial relationship with IT and security measures? What do you think is going to happen when someone forgets their key and can't send an x-ray to the remote radiology center? I have my guesses.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#280

Earlier quoted context omitted.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping f…

> The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo?

They can publish best practices, research vulnerabilities, provide educational support, and generally do all the kinds of things governments do to encourage the right behaviors. We have some of this, but at some point, switched to the sexier "the best defense is a good offense". Likely because defense is hard.

Post reply on HN