Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

321–330 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#321
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

IMO the first step to fixing is to add liability. If a breach happens through a piece of software, then the vendor is liable. Same way cars get recalls. (sometimes)

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#322

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…

The infrastructure wasn’t impacted. It was shut down because the billing system was.

It’s also easy to assume that everyone is incompetent. That doesn’t make it true. Like any hostile situation, a defensive position can always be overcome, you have to have an active offense as well.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#323

Earlier quoted context omitted.

Agree — These ban happy nocoiner rantings about outlawing math are funny if they weren’t so damn authoritarian.

We're not outlawing math. You can still run your little calculations on your machine. You just can't exchange them for dollars. That's what we're proposing here. Currency control. Are you confusing this with the debate around encryption? That wouldn't surprise me coming from someone who uses the phrase "nocoiner".

Sure, the people who aren't proposing to outlaw mathematics are the confused ones...

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#324
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

IMO the first step to fixing is to add liability. If a breach happens through a piece of software, then the vendor is liable. Same way cars get recalls. (sometimes)

Really? I don’t think this is at all similar to a car safety recall. That’s more like trying to issue a recall for a car because people can smash it’s windows and break in.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#325

Earlier quoted context omitted.

> and even harder for computer systems Things are actually getting better in some ways. Modern OSs with automatic updates are more secure than OSs have ever been. The days where clicking a link on an email or plugging in a USB could infect your computer are almost gone outside of rare zerodays which get patched for everyone pretty quick. Things are getting even better with hypervisors, SELinux and secure languages ro…

Yes, but then you read things like https://googleprojectzero.blogspot.com/2021/01/introducing-i... , or look at the payments offered by https://zerodium.com/program.html… the days of clicking a link -> persistence payload with escalated privileges are still here

From what I see on that page. It costs $500,000 to exploit chrome and your attack only lasts for a few days and then google pushes out a fix to all chrome users. This is so much better than the IE era where a teenager with some free time and skill could make something up and there would still be exploitable machines years later for the same bug.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#326

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…

There are many standards out there such as SOC-2. But that’s not particularly meaningful against dedicated professional hackers. It’s a totally asymmetric game.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#327
post #71

Earlier quoted context omitted.

Sure, but they are up against state-sponsored, highly trained actors, and that's not a fair fight. This requires the resources of the US Government as their bodyguard.

Then it is also time to pay a lot more in taxes and keep less in the bank too Which is it?

Well, obviously.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#328

Bruce Schneier, our country needs you! If you—or someone with your mindset—isn’t in authority and we get the technical equivalent of the TSA, we’re in for a world of hurt and trouble.

Of course you get the technical equivalent of the TSA. Even if you had Bruce Schneier setting it up, he won't run it in perpetuity; government in the long run descends to maximum power exercised with minimum intelligence unless prevented by the people governed.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#329
post #45

Earlier quoted context omitted.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

We don’t allow private companies to buy the technology required to protect themselves against a physical army.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#330
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

We have to think of this similar to how any other human or company behavior is monitored. Hold companies responsible and have a market sell ransomware insurance.

(One exception to my solution is poor government and public institutions who run awful software. Not sure what we can do)

If I have a habit of burning down my house by being sloppy with safety, my rates will go up. There should be something similar

Let us take the case with Equifax mismanaging their servers, with running obsolete Java packages resulting in identity theft for millions of Americans.

Credit score is controlled by 3 companies. Credit score determines mortgage rate and hence it literally controls if a US resident can afford to buy a house or get a job (in some states). Don’t the companies need to take some responsibility?

Similarly dozens of companies leaving Elastic search installs and MySQL open to the internet. I mean.. how sloppy can one get?

Fine, be sloppy, just pay $$$$$ to your insurance company. That $$ amount will indirectly decide whether we go to war with Russia or pay software engineers.

Post reply on HN