Earlier quoted context omitted.
Except you can't do that, which is why the army metaphor doesn't work. (If you want to argue that this is a realistic response, please explain how doing so would not be acts of war, inviting both retaliation and much worse acts then justified by ours.)
Follow the $$$. If US government authorizes the NSA/CIA to infiltrate/attack all bitcoin exchanges that accept payments from wallet ID with ransomware, the problem likely be solved very quickly.
U.S. to give ransomware hacks similar priority as terrorism, official says
411–420 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#412I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
same mentality as dismissing airbags in cars because "people should drive better/pay attention more"
>We need many angles of defense against these criminals.
Whatever you're comparing airbags to would be one of the defenses that blast is saying we need.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#413I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
Victim blaming is a framing that makes it sound like it's about moral and ethics. But it's about practicality. There is a causal chain leading to a bad outcome and we simply break the weakest link. Sometimes it's easier to lock up the treasure and sometimes it's easier to lock up all the thieves.
Consider the case of computer security. Locking up all the thieves is super duper hard, because they are located in places like Russia and China that wont cooperate with law enforcement.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#414Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#415Response to terrorist-equivalent cyberattack from Russia: Invade Russia?
I hope not. I don't want World War 3 to be in my lifetime.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#416Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#417Earlier quoted context omitted.
>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.
Pulling this thread: say the government regulates it - what do they require? Regulations that say you need to be secure enough to not be hacked? That requirement changes daily. Baseline security standards? Sure. But what is the baseline? And how influenced by lobbyists is that baseline? You know the big security companies would love to have their product be a government requirement. Attackers do not have regulations.…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#418I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that from bringing it all down?"
In other words, think in terms of redundancy and isolation between systems.
And the largest piece of hubris and madness in critical systems is allowing over-the-internet updates.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#419Earlier quoted context omitted.
And the threat of a Topol-M nuclear missile with a yield of 800 KT detonating over New York is a pretty good incentive not to launch tomahawk missiles at office buildings located in nuclear-armed countries. If you ever wonder why unfriendly countries have nuclear ambitions, rhetoric like this is part of it. How many people are you ready to kill over ransomware ? And weren't we just splitting hairs the other day over…
At this point, with repeated attacks against our infrastructure, we need to get said countries to either help us route said cyber attacks (state sponsored or not). If this continues to happen we are looking at a really bleak future. There is an -insane- amount of money at stake here. How many meat/farm futures got affected by just taking out the meat industry this time? How much money can these people get not just by…
Cyber warfare, whether ransomware or espionage, is largely asymmetric. Why would these other countries want to play ball when they have everything to gain?
The answer tends to be that you make them cooperate by attaching additional costs to the actions, in order to make them less attractive. These costs come in two major forms, which we might want to categorize as passive and aggressive.
Passive costs might include: - Sanctions - Investigation/Arrests
Aggressive costs might include: - Offensive hacks - Military response
The issue here seems to be that the passive responses aren't likely to be strong enough to dissuade the other actors, while the aggressive responses are too costly. Aggressive counter hacks might just normalize cyber hacking and espionage, and the US is on the wrong side of that asymmetric gamble. Normalizing the behavior would be likely to make it worse than it already is!
Military responses go too far. You can't reaaalllly militarily respond to another nuclear power. Not directly. The potential outcomes there are almost uniformly bad. If you want to play the longer game maybe you do some poking and prodding by supporting third party combatants (IE: Soviet support of Vietnam against the Americans) or political opponents. But there aren't really that many great options on that front today for Russia or China.
So that leaves trying to increase the cost of the passive responses. This is kind of troublesome with China, since they'll just throw identical costs right back at you. It's a bit more possible with Russia, but Europe's entanglement with their power sector screws everything up. And it's not like we're lacking on Russian sanctions as it is.
You can try to play a strong defense, but that's kind of like putting a bandaid on a gunshot wound at this point.
Yadda yadda yaddad, I don't know what to do but I think it's an interesting problem!
Edit: Maybe I shouldn't say European entanglement with Russian power sector. I suppose it's more appropriate to say gas sector?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#420Earlier quoted context omitted.
> "running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing" running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing
Texas? Winterization that wasn’t done and wasn’t required, and thereby those generators who didn’t had a more competitive edge? The similarities write themselves.