Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

411–420 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#411
post #201
post #173

Earlier quoted context omitted.

Except you can't do that, which is why the army metaphor doesn't work. (If you want to argue that this is a realistic response, please explain how doing so would not be acts of war, inviting both retaliation and much worse acts then justified by ours.)

Follow the $$$. If US government authorizes the NSA/CIA to infiltrate/attack all bitcoin exchanges that accept payments from wallet ID with ransomware, the problem likely be solved very quickly.

Not if the hackers use monero.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#412
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

same mentality as dismissing airbags in cars because "people should drive better/pay attention more"

I don't understand. How is blast dismissing something similar to airbags? blast says

>We need many angles of defense against these criminals.

Whatever you're comparing airbags to would be one of the defenses that blast is saying we need.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#413
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

You have a lot of replies but as far as I can see no one made this point, so let me add yet another reply.

Victim blaming is a framing that makes it sound like it's about moral and ethics. But it's about practicality. There is a causal chain leading to a bad outcome and we simply break the weakest link. Sometimes it's easier to lock up the treasure and sometimes it's easier to lock up all the thieves.

Consider the case of computer security. Locking up all the thieves is super duper hard, because they are located in places like Russia and China that wont cooperate with law enforcement.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#417
post #404
post #259

Earlier quoted context omitted.

>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.

Pulling this thread: say the government regulates it - what do they require? Regulations that say you need to be secure enough to not be hacked? That requirement changes daily. Baseline security standards? Sure. But what is the baseline? And how influenced by lobbyists is that baseline? You know the big security companies would love to have their product be a government requirement. Attackers do not have regulations.…

IT can't be looked at as a cost center anymore. The constant pressure of cost reduction is what causes these failures to happen in the first place, because nobody running the infrastructure really cares. If something goes wrong, they're out of a job anyway.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#418
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

It's impossible to build a safe airliner, but we can get pretty damn close. Airline engineers know one cannot create a component or system that cannot fail. So the question then becomes, assume a system fails. Now how does the airplane survive?

With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that from bringing it all down?"

In other words, think in terms of redundancy and isolation between systems.

And the largest piece of hubris and madness in critical systems is allowing over-the-internet updates.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#419
post #191

Earlier quoted context omitted.

And the threat of a Topol-M nuclear missile with a yield of 800 KT detonating over New York is a pretty good incentive not to launch tomahawk missiles at office buildings located in nuclear-armed countries. If you ever wonder why unfriendly countries have nuclear ambitions, rhetoric like this is part of it. How many people are you ready to kill over ransomware ? And weren't we just splitting hairs the other day over…

At this point, with repeated attacks against our infrastructure, we need to get said countries to either help us route said cyber attacks (state sponsored or not). If this continues to happen we are looking at a really bleak future. There is an -insane- amount of money at stake here. How many meat/farm futures got affected by just taking out the meat industry this time? How much money can these people get not just by…

How do you get countries to cooperate that have no incentive to cooperate?

Cyber warfare, whether ransomware or espionage, is largely asymmetric. Why would these other countries want to play ball when they have everything to gain?

The answer tends to be that you make them cooperate by attaching additional costs to the actions, in order to make them less attractive. These costs come in two major forms, which we might want to categorize as passive and aggressive.

Passive costs might include: - Sanctions - Investigation/Arrests

Aggressive costs might include: - Offensive hacks - Military response

The issue here seems to be that the passive responses aren't likely to be strong enough to dissuade the other actors, while the aggressive responses are too costly. Aggressive counter hacks might just normalize cyber hacking and espionage, and the US is on the wrong side of that asymmetric gamble. Normalizing the behavior would be likely to make it worse than it already is!

Military responses go too far. You can't reaaalllly militarily respond to another nuclear power. Not directly. The potential outcomes there are almost uniformly bad. If you want to play the longer game maybe you do some poking and prodding by supporting third party combatants (IE: Soviet support of Vietnam against the Americans) or political opponents. But there aren't really that many great options on that front today for Russia or China.

So that leaves trying to increase the cost of the passive responses. This is kind of troublesome with China, since they'll just throw identical costs right back at you. It's a bit more possible with Russia, but Europe's entanglement with their power sector screws everything up. And it's not like we're lacking on Russian sanctions as it is.

You can try to play a strong defense, but that's kind of like putting a bandaid on a gunshot wound at this point.

Yadda yadda yaddad, I don't know what to do but I think it's an interesting problem!

Edit: Maybe I shouldn't say European entanglement with Russian power sector. I suppose it's more appropriate to say gas sector?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#420

Earlier quoted context omitted.

> "running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing" running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing

Texas? Winterization that wasn’t done and wasn’t required, and thereby those generators who didn’t had a more competitive edge? The similarities write themselves.

Thanks, that explains it.
Post reply on HN