Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

311–320 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#313
> a cyber criminal group... penetrated a pipeline operator on the U.S. East Coast, locking its systems and demanding a ransom. The hack caused a shutdown lasting several days...

I expect more precise language than this from Reuters. This makes it sound like the ransomware was responsible for shutting down the pipeline. The billing system was compromised. Colonial shut the pipeline down themselves so they wouldn't have billing inaccuracies.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#314

Earlier quoted context omitted.

> These cyber attacks are all but literally one bored kid and a computer. Are you sure about that? A lot of this stuff is way more than just some bored kid. For the company I work for, there is almost certainly a group of well paid people who sit around every day trying to figure out new ways run scams using our site. When there is financial motivation, people go through great efforts to get that $$$. "Security" isn'…

Right, security is definitely not a box you can check but American business have decided that if they run Qualys to get that PCI-DSS everything is good. Nobody is out there seriously talking about the fact that the Linux kernel is written in fucking C. Well it's 2% faster than if we wrote it in an actual language with, I don't know, bounds checking , and we'd rather use the 2% for dividends, thanks very much. We need…

> run Qualys to get that PCI-DSS

I feel this deeply within my soul.

I think it's actually harmful, because people that don't know any better thinks a Qualys scan means something.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#315
This is just DOJ, so far. If ransomware gets defined as terrorism for the US anti-terrorism community, it could become very dangerous to be in the ransomware business.

The US has a huge anti-terrorism operation in being, and it's not that busy. Islamic terrorism against the US has been confined to minor local nuts since the US wiped out Bin Laden. And, before that, being "#2 in Al Queda" meant having a rather short life expectancy.

Now, all those people in northern Virginia and southern Maryland may be getting new targets.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#316
Would a nationalized bug bounty program help here? Along with some compliance enforcement that the bounty is actually addressed, fulfilled, and payed by the vulnerable entity or the government (funded through some form of corporate tax). I haven't really thought out the details, but likely some kind of practical and effective threshold exists where a business entity in the US enters into mandatory participation.

Genuinely curious, would love to see others' thoughts.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#317

US Constitution empowers Congress to issue "Letters of Marque and Reprisal" - to wit grant permission for private entities (people, companies) to wage war on other private entities. Enacted to help shipping companies deal with pirates, applies today for the likes of ransomware perpetrators.

Letters of Marque! I like this way option way better than that other commentator who wanted to start a nuclear war.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#319

Earlier quoted context omitted.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping f…

> most fragrant violations

I love the smell of marginally improved security practices in the morning.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#320

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…

Many of the most serious recent incidents don't involve theft of end user data or impacting end users in any real way, unless you consider the "end users" of gas stations and ferry boats to be the victims of these attacks. That's not incorrect in a way, but also seems like a pointlessly wide net.

The thing I'm a bit tired of is IT people in these threads taking every incident that comes along as an opportunity to elevate their pet cause. These more serious incidents have more in common with mafia extortion rackets than computer security.

Post reply on HN