Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

291–300 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#291
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Would it be reasonable to demand every company hire a team of armed guards? No? So why is it reasonable to demand they each hire a cybersecurity team?

It’s reasonable to tell companies to lock the doors. It’s reasonable to tell them to follow accepted best practices in tech too, but not that they be experts prepared for everything.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#292
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

> It's physically impossible to build a house that can't be broken in to

Obviously you're correct because impossible is a tall order, but it's possible to get close assuming the aspiring intruders don't have dynamite or artillery[1].

[1] https://en.wikipedia.org/wiki/Bastle_house

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#293
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

> and even harder for computer systems

Things are actually getting better in some ways. Modern OSs with automatic updates are more secure than OSs have ever been. The days where clicking a link on an email or plugging in a USB could infect your computer are almost gone outside of rare zerodays which get patched for everyone pretty quick.

Things are getting even better with hypervisors, SELinux and secure languages rolling in. Significant portions of Android and in the future linux, will and are being rewritten in rust which wipes out entire classes of the worst bugs we are being faced with.

The problem is that the attackers are also getting more sophisticated and the targets are becoming more valuable with more and more getting put online.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#294
post #191

Earlier quoted context omitted.

I think the threat of a tomahawk missile entering your building is a pretty good incentive to not fuck with US infrastructure but that's just me.

And the threat of a Topol-M nuclear missile with a yield of 800 KT detonating over New York is a pretty good incentive not to launch tomahawk missiles at office buildings located in nuclear-armed countries. If you ever wonder why unfriendly countries have nuclear ambitions, rhetoric like this is part of it. How many people are you ready to kill over ransomware ? And weren't we just splitting hairs the other day over…

At this point, with repeated attacks against our infrastructure, we need to get said countries to either help us route said cyber attacks (state sponsored or not).

If this continues to happen we are looking at a really bleak future. There is an -insane- amount of money at stake here. How many meat/farm futures got affected by just taking out the meat industry this time? How much money can these people get not just by the ransomware attack, but by also knowing how fucked an industry is about to be and cashing out.

When they can do this shit with impunity it's a problem. And there's potentially a lot of money available.

This is all just ignoring the fact that some of this might be state sponsored.

I think it's time to start getting some sort of cooperation from said nation states and allowing us to help take out some of their trash.

Because the other option is to treat this like state sponsored attacks on our infrastructure and no one is going to like that.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#295
post #262

Earlier quoted context omitted.

How much of these hacks would be prevented by adoption of simple preventions like Yubikeys for login, backing up data and images regularly, and encrypting data by default?

Sometimes simple preventative measures aren't as simple as they might sound. How would you go about integrating yubikeys for login into multi-decade-old SCADA hardware systems? I'm a security specialist and I honestly wouldn't know where to begin.

We first start by moving all the non legacy stuff to MFA. There are so many easy targets in security that we can look in to first before declaring it impossible because of a handful of legacy apps.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#296
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Anytime you can let a group of criminals get away with impunity it's going to run out of control until we get... the current situation.

It's getting close to having China and Russia either start cooperating with us to flush these guys out, or we start having "fleet exercises" in their seas again. I think it would be prudent of said nation states to wash their hands of these folks.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#297
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

  > We need preventative care and treatment and everything in between.
Not to mention the fact that the cybercriminals who do these attacks also get involved with state-sponsored offensives. The ransomware stuff might just be "training wheels" or resume bullet-points for something far worse in the future.

If we're going to get serious about stopping the state-sponsored stuff and even bother to have the "US cyber-command" it makes sense to go after the relatively petty criminal elements as well. If they can't make a dent with these, why should we think that can go up against the FSB?

Corporations can only ever view cybersecurity as yet another compliance exercise (and all the incurious checkbox tickers that entails). The smart ones will play "cops and robbers" (red-team/blue-team games) but they can't offensively go after cyber criminals. Unfortunately, that's what needs to be done to get ahead of this stuff.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#298
post #244

“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.” That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.

they made a LOT more than 5m. I would have also been putting bets into the markets much earlier and cashing in on the stupid chaos.

Continuing to let them do this with impunity is going to lead to escalated attacks.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#299

Earlier quoted context omitted.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping f…

When you can drop a bomb into a pickle barrel from 30000 ft, the question is not “how do I make my pickle barrel stronger?” it is “how do I decrease my reliance on this single pickle barrel?”

Spy-craft is notoriously laughable in its effectiveness. InfoOps, on the other hand...

I guess I’m saying comparisons to both Air based warfare and to the propaganda machine are both the most useful analogs, imho.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#300
post #259
post #236

Earlier quoted context omitted.

The market doesn’t incentivize security until it is too late. A pipeline operator that passes security costs onto consumers will lose to one with lower security and lower costs. Serious, significant attacks might occur at year 5, when the company becomes a big enough target to make it worthwhile to attack. By this time, the company who did not invest as heavily in security has captured the market while the one that i…

>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.

If the goal was to disable the pipeline the attacker could just apply thermite somewhere along one of it's many unguarded miles. The reason that doesn't happen is because retribution for such an act would be striking to say the least.

It's impossible to prevent all attacks, physical or cyber, so at some point one needs to either submit to an order where attackers act with impunity, or otherwise invest in retribution.

Post reply on HN