Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

301–310 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#301
post #259
post #236

Earlier quoted context omitted.

The market doesn’t incentivize security until it is too late. A pipeline operator that passes security costs onto consumers will lose to one with lower security and lower costs. Serious, significant attacks might occur at year 5, when the company becomes a big enough target to make it worthwhile to attack. By this time, the company who did not invest as heavily in security has captured the market while the one that i…

>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.

You're imagining what is essentially an impossible scenario, because your setup is factually badly wrong.

The ransomeware attack in question wasn't capable of shuttering the pipeline as a target, whether the hackers wanted money or not. That was a voluntary action by the company, a questionable precaution they chose to take.

The US military isn't directly restrained by that pipeline. They have their own fuel supply lines that do not particularly care about that specific pipeline. And even if they did, they can go to the source, they don't require that pipeline for fueling purposes. They have other means of mobilizing refueling, up to and including anything that is necessary from a transport, manpower and logistics standpoint (including commandeering approximately four zillion private fuel trucks and tankers to get fuel moving for defense purposes).

There is no scenario where that pipeline existing or not existing tomorrow would shut down the US military or prevent its ability to defend against an impossible and amusingly implausible attempted land invasion of the US domestic territory.

So, imagine if that was a nation state (uh, which one?) mobilizing for an invasion that can never happen, an invasion that could never get across the Atlantic or Pacific. No.

Bombs start falling? From where? China? Russia? Russia is doing what, invading the east coast? With what ships? With what air cover? With what magical clandestine capability to hide a massive military as they sneak across the Atlantic on non-existent ships. With what aircraft carriers? And with China, so the US sends bombs back the other direction. The ability to throw a thousand nukes at China isn't restrained by the East Coast pipeline, and they know that, as does every other nation on the planet. Again, your setup is so far outside of reality that it's absurd.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#303
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Imagine if all companies had to individually fight pirates in the heyday of pirate hood!

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#304
post #262

Earlier quoted context omitted.

Sometimes simple preventative measures aren't as simple as they might sound. How would you go about integrating yubikeys for login into multi-decade-old SCADA hardware systems? I'm a security specialist and I honestly wouldn't know where to begin.

We first start by moving all the non legacy stuff to MFA. There are so many easy targets in security that we can look in to first before declaring it impossible because of a handful of legacy apps.

You're absolutely right. There's often no shortage of low hanging fruit.

I'm not suggesting we should declare anything impossible. Far from it! I'm merely trying to suggest that we should appreciate that not all things as easily fixed as they may seem at first blush.

As all of us in software know, complexity can lurk in unexpected places.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#305

Earlier quoted context omitted.

The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping f…

> The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? They can publish best practices, research vulnerabilities, provide educational support, and generally do all the kinds of things governments do to encourage the right behaviors. We have some of this, but at some point, switched to the se…

It makes me wonder there the offense is. Where is the asymmetric response that sends a clear message not to do this again?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#308

Earlier quoted context omitted.

If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?

Restore from backup.

ok let’s say they don’t have one. now what?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#309

Earlier quoted context omitted.

If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?

They'd restore from backups, which is already what they did even after paying the ransom. More importantly, would the hack have happened in first place if they knew there was no chance of being paid? Every ransom paid just funds and encourages the next hack. The social damage is deserving of a large fine (i.e. 10x the ransom).

let’s say they have no backups. do you know what a hypothetical is? fucking moron.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#310

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

> and even harder for computer systems Things are actually getting better in some ways. Modern OSs with automatic updates are more secure than OSs have ever been. The days where clicking a link on an email or plugging in a USB could infect your computer are almost gone outside of rare zerodays which get patched for everyone pretty quick. Things are getting even better with hypervisors, SELinux and secure languages ro…

Yes, but then you read things like https://googleprojectzero.blogspot.com/2021/01/introducing-i..., or look at the payments offered by https://zerodium.com/program.html… the days of clicking a link -> persistence payload with escalated privileges are still here
Post reply on HN