Earlier quoted context omitted.
You have to enforce standards. Good security is expensive. If companies in competition don't have to pay for good security those that do have it will have higher costs and have trouble competing.
> "running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing" running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing
U.S. to give ransomware hacks similar priority as terrorism, official says
401–410 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#402Earlier quoted context omitted.
Liable in what way? Wouldn't that just kill OSS? Or do you not count programmers who upload swiss-cheese scripts to Github as vendors? What about Linux, openSSH, etc?
OSS licenses include a very broad waiver, after all it is a gift provided as-is. Software that runs critical infrastructure (or could cause injury or death if it malfunctioned) should be required to use formal methods and that certainly would include everything to make it run also used such formal methods. (From the OS to shared libraries and even the compilers)
"Microsoft and the device manufacturer and installer exclude all implied warranties and conditions, including those of merchantability, fitness for a particular purpose, and non-infringement."
You'd have to outlaw that or breed a more discerning consumer. One way to do that would be to blame the company using it, which would make them take more care in what they choose to use.
It just gets broad and vague after a point. Can the software that schedules trains use Linux or MySQL? People could die if it puts two trains on the same track. Note that GP never mentioned safety either. Just being hacked.
But yes I'd hope that anything bespoke should be covered under a contractual agreement with SLAs and penalties.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#403I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#404Earlier quoted context omitted.
The market doesn’t incentivize security until it is too late. A pipeline operator that passes security costs onto consumers will lose to one with lower security and lower costs. Serious, significant attacks might occur at year 5, when the company becomes a big enough target to make it worthwhile to attack. By this time, the company who did not invest as heavily in security has captured the market while the one that i…
>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.
Baseline security standards? Sure. But what is the baseline? And how influenced by lobbyists is that baseline? You know the big security companies would love to have their product be a government requirement. Attackers do not have regulations. They know the regulations and work around them. Makes it more difficult, but eventually they develop new attacks.
So now you’ve got this government body making regulations that needs people who understand security to make the regulations, who then need some way to audit the companies to ensure compliance. The companies then have to focus on the audits and not on emerging threats, or do both, and it increases overhead.
I’m not against government regulations when it is a good fit, but there are a lot of unintended consequences. The government is made up of people, too, and they may not be as close to the work to understand the optimal allocation of resources to minimize security risk.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#405I think this is needed because the security industry seems to be well on the way to adopting paying off these people as a routine cost of business. That is going to lead to an absolute disaster if it is allowed to continue and grow. It needs to be a double edged sword though where companies are just as afraid of facilitating ransomware attacks as they would be of the consequences of facilitating terrorists. In other…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#406Earlier quoted context omitted.
The problem is our govt money is subsidizing private company security policies instead of more directly helping people. This money should go to healthcare, infrastructure, or even be redistributed before it's used here.
We fund the police and military with our tax dollars to prevent bad actors from doing bad things that we don’t want. Why is this different?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#407Earlier quoted context omitted.
Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is. Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world. I despise seeing simple apps with ridiculous dependency trees (package.json with line counts…
Surely you mean lock files not package jsons?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#408I really hope this copies the principal of not negotiating with terrorists. Everytime we pay out ransomware it just encourages more ransomware.
https://en.wikipedia.org/wiki/Government_negotiation_with_te...
https://foreignpolicy.com/2014/06/03/the-u-s-does-negotiate-...
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#409Earlier quoted context omitted.
I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.
If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#410Earlier quoted context omitted.
We publicly subsidize every other kind of security to some degree already. A company might have security guards, but police are certainly going to be there to provide a baseline policing the neighborhood, respond to calls, etc. And security via threat of retaliation does not sound like a practical or effective solution either: we already have plenty of capabilities in that area, and it didn't stop east coast oil & ga…
Then how about nationalizing that infrastructure, if it is so crucial for national security and the private sector is unwilling to spend enough to protect itself against threats? Let's not kid ourselves: this is first and foremost a matter of incentives and consequences rather than a lack of capabilities. I don't see what the public could do better than private entities, besides absorbing their costs. The only way I…
Unlike "real war", cyber defense also gets to design the battlefield, everytime time. There will always be social attacks, but the stupid C and Unix stuff that is the bread & butter today is completely preventable