Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

331–340 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#331
I wonder how many of these would be stopped by getting rid of SMB file shares. Not that that is really an option, of course, but things like OneDrive and Google Drive scan for malware during upload and often don't sync a file (especially a shared file) to a user's device until they specifically click on it. Seems like it would make it a lot harder to move around if you were malware.

(You can't do this if you want on-prem Active Directory or a good open-source cross-platform file sharing service like Samba, which means 90% of companies can't do this. And there are of course actual security things you can do [like blocking hard mapping of network drives in Windows] instead of the cowards way out I speak of.)

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#333
post #327

Earlier quoted context omitted.

Then it is also time to pay a lot more in taxes and keep less in the bank too Which is it?

Well, obviously.

Oh I think so too, but I really don't think that's obvious too many of the people impacted by all of this.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#334
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is.

Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world.

I despise seeing simple apps with ridiculous dependency trees (package.json with line counts in the 5-6 figures, for example) and other complexity that can't possibly be fully understood by whoever's responsible for operating it. But I suppose things would be in even worse shape if we reinvented the wheel instead of using well-known libraries and so forth.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#335

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…

You have to enforce standards. Good security is expensive. If companies in competition don't have to pay for good security those that do have it will have higher costs and have trouble competing.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#336
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

The problem is our govt money is subsidizing private company security policies instead of more directly helping people. This money should go to healthcare, infrastructure, or even be redistributed before it's used here.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#337
1. Make ransom illegal to pay. 2. Fine the hell out of any company that has not kept up with best practice in security. Require the board and exec staff to resign without payouts. 3. Make minimum jail time for ransomware hackers 100 years. 4. Make any hack that can be attributed to a loss of life (like shutting down a hospital) a death penalty offense. 5. State actors get economic death penalty - no US company or company that does business with a US company is allowed to do business (banking, etc.) with the state actor for 1 year for each offense. 6. Authorize NSA to retaliate in kind vs state actors.

At the height of the Roman Empire a citizen could walk the length of it without fear, because if they where attacked and killed the legion would burn the city / village to the ground that was responsible.

We had the Cold War and not a Hot War because of mutually assured destruction. I fail to see a reason not to bring that balance to hacking by state actors.

Bla, bla, I am a bad person. No, I am suggesting a reasonable measurable set of steps that force the companies to do better while imposing great risk to the criminals and state actors.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#338

1. Make ransom illegal to pay. 2. Fine the hell out of any company that has not kept up with best practice in security. Require the board and exec staff to resign without payouts. 3. Make minimum jail time for ransomware hackers 100 years. 4. Make any hack that can be attributed to a loss of life (like shutting down a hospital) a death penalty offense. 5. State actors get economic death penalty - no US company or com…

Not the minimum jail sentences: The government will then just keep watering down the definition of "ransomware hacker" until all of us are technically eligible for 100 years of prison because of that one time we used an incognito tab to circumvent the NYT subscription nagware.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#339

Earlier quoted context omitted.

That doesn't mean you avoid making laws for the legitimate threats, it means you also keep tabs on how they're used. A system of laws, and a system of oversight for the use of those laws.

Yes, keep tabs on how it's used. But also, when it's being written, try to think about how it's likely to be misused, and write it in a way that it can't be misused like that. (Amusingly, I made a typo, and misused came out mis-sued.) Legislators try to write laws broad enough that they cover everything and can't be weaseled out of, but that leads to them covering more than intended.

Agreed-- lack of oversight for the legal system creates significant potential for abuse even if the laws are well written

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#340

These attacks make me question the security of critical infrastructure. Are people asleep at the wheel or is this overblown?

Given the US response to threats and disasters including COVID-19, global warming, fascism, white nationalism, gross media manipulation, wildfire, drought, opioid crisis, the 2007-8 global financial crisis, housing bubble, Hurricane Katrina, and 9/11 attacks, just to cover the past two decades, I'd say "asleep at the wheel" is standard operating proceedure.

All of those were known threats or repeat instances of similar previous threats.

It's the likely threats for which there've been no earlier parallels that I'm truly terrified of.

Post reply on HN