(You can't do this if you want on-prem Active Directory or a good open-source cross-platform file sharing service like Samba, which means 90% of companies can't do this. And there are of course actual security things you can do [like blocking hard mapping of network drives in Windows] instead of the cowards way out I speak of.)
U.S. to give ransomware hacks similar priority as terrorism, official says
331–340 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#332Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#333Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#334I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world.
I despise seeing simple apps with ridiculous dependency trees (package.json with line counts in the 5-6 figures, for example) and other complexity that can't possibly be fully understood by whoever's responsible for operating it. But I suppose things would be in even worse shape if we reinvented the wheel instead of using well-known libraries and so forth.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#335Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#336I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#337At the height of the Roman Empire a citizen could walk the length of it without fear, because if they where attacked and killed the legion would burn the city / village to the ground that was responsible.
We had the Cold War and not a Hot War because of mutually assured destruction. I fail to see a reason not to bring that balance to hacking by state actors.
Bla, bla, I am a bad person. No, I am suggesting a reasonable measurable set of steps that force the companies to do better while imposing great risk to the criminals and state actors.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#3381. Make ransom illegal to pay. 2. Fine the hell out of any company that has not kept up with best practice in security. Require the board and exec staff to resign without payouts. 3. Make minimum jail time for ransomware hackers 100 years. 4. Make any hack that can be attributed to a loss of life (like shutting down a hospital) a death penalty offense. 5. State actors get economic death penalty - no US company or com…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#339Earlier quoted context omitted.
That doesn't mean you avoid making laws for the legitimate threats, it means you also keep tabs on how they're used. A system of laws, and a system of oversight for the use of those laws.
Yes, keep tabs on how it's used. But also, when it's being written, try to think about how it's likely to be misused, and write it in a way that it can't be misused like that. (Amusingly, I made a typo, and misused came out mis-sued.) Legislators try to write laws broad enough that they cover everything and can't be weaseled out of, but that leads to them covering more than intended.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#340These attacks make me question the security of critical infrastructure. Are people asleep at the wheel or is this overblown?
All of those were known threats or repeat instances of similar previous threats.
It's the likely threats for which there've been no earlier parallels that I'm truly terrified of.