I find it wild that the "run government like a business" crowd now wants government to run business. No one in this thread is really discussing what, if anything, the government can really do. Meanwhile, business is more than happy to be a toddler wielding a gun of computer security literacy, or to take the money of such companies and not truly helping.
As others are pointing out it various ways in this thread, to put it bluntly, this viewpoint treats it as a 100% computer science theoretical question, there are many many angles to making this more painful, even just via signalling. Ex. the pipeline hackers backing off and creating a code of conduct for themselves, then disappearing altogether
U.S. to give ransomware hacks similar priority as terrorism, official says
431–440 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#432Earlier quoted context omitted.
Many of the most serious recent incidents don't involve theft of end user data or impacting end users in any real way, unless you consider the "end users" of gas stations and ferry boats to be the victims of these attacks. That's not incorrect in a way, but also seems like a pointlessly wide net. The thing I'm a bit tired of is IT people in these threads taking every incident that comes along as an opportunity to ele…
The debate is pretty much divided between people who say "improved security is the solution" and people who say "treating it as crime/terrorism/the-mafia is the solution". I'm in the improve the security camp. I think security can be improved if we impose good standards (meaning enforce inconvenient things like no backdoor updating apps, no critical infrastructure connected to the web). The reason "treating this like…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#433Earlier quoted context omitted.
You have to enforce standards. Good security is expensive. If companies in competition don't have to pay for good security those that do have it will have higher costs and have trouble competing.
Why I said you have to actually force the standards down people's throat, with laws or liability. Restaurants don't like health standards either.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#434Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
It's impossible to build a safe airliner, but we can get pretty damn close. Airline engineers know one cannot create a component or system that cannot fail. So the question then becomes, assume a system fails. Now how does the airplane survive? With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that f…
Securing a company is like saying that you have to chnage all of the wiring in a country without impacting power supply. ALL of them - the house wirings, the cables transporting power, everyting. At once.
Security in a company is not a single system, it is a messy interaction of unknown dependencies nobody understands. And this mess runs a business.
Of course, there are plenty of things one can do but even for simple tasks such as "let's reset all the 100,000 accounts to make sure they are long/complex/whatever". This is asking for apocalypse.
How it is difficult is visible when you work in information security and have to balance the "we MUST NOT be hacked" and "we MUST NOT impact the business".
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#435Earlier quoted context omitted.
I don’t think that’s a fair comparison. I think a fair comparison would be 80,000 companies buy the same vault door from supplier X. But suddenly one criminal group has found a universal key to the vault that no one else knows about, and can now access all 80,000 vaults nearly simultaneously and clandestinely even though they still look closed and secure from outside observers.
... but this was 5 years ago and everyone and their dog knows it by now, the company just didn't bother to change that door. Also, the criminal group doesn't hit doors with cameras, but nobody bothered to install one. --- What you described is a zero day, which is very rarely used - most ransomware simply uses the absolutely low hanging fruit of companies lagging behind years in security updates combined with highly…
In the same way companies do not have sufficient HA for their critical systems or processes. HA means being actively resistant to events impacting availability by having (typically automated) redundancy to remove SPoFs. It doesn’t mean HA owing to luck the server hasn’t died in 10 years owing to lack of/poor maintenance. But both with HA and backups companies can dodge bullets (until a real emergency) and maybe never even have a major incident.
Ransomware kind of exploits this lack of organisation level sufficient backing up of all critical information assets.
It really is as you say, low hanging fruit.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#436Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#437Earlier quoted context omitted.
I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…
There are many standards out there such as SOC-2. But that’s not particularly meaningful against dedicated professional hackers. It’s a totally asymmetric game.
These standards (and PCI-DSS, and ISO, and NIST (and this one is by far the best)) have plenty of blah blah that never gets implemented. They rely on some magical risk assessment exercices with a nice risk grid that gives you answers.
The reality is that the top 5-10-whatever risks are very simple to assess and very difficult to address. Unfortunately such concerns do not exist for the writes of standards.
I have been doing information security for 25 years in huge companies. The more relevant the risk is, the more painful it is to implement.
Even the ones such as "awareness" that theoretically should be useful assume that people care or think. I get emails from people who went though 10 awareness sessions who wonder why someone wants to enlarge their penis. And yes, the awareness sessions wera like in the ads: short, to the point, entertaining, relevant, magical.
So now imagine rising a risk that endangers the key legacy system that cannot be isolated.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#438Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
I have seen personally, heard first hand accounts, and read many a post-mortem for situations where the primary blame really should be on the "victim". There's another word for this: Negligence. Of course there are always 0days. There are always sophisticated attacks. There is always human error. Then there are people in leadership positions being given accurate information about basic security problems and possible…
Both are truthful and full of good will.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#439Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is. Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world. I despise seeing simple apps with ridiculous dependency trees (package.json with line counts…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#440Earlier quoted context omitted.
Backups are no longer sufficient - as the hackers now threaten to disclose stolen data to the public.
Which only works because they’re paying the ransom. The second the government introduces criminal penalties against the executives and boards for paying ransom, it will stop.
Making it a criminal offence to pay a ransom would eventually stop criminals ransoming the data they take to the company they took it from, but it wouldn't stop attacks and data breaches if there's some other way to profit. For example, attackers could sell the databases they steal. Or they could ransom individual's data directly to the individual. Or they short the stock of the company and then release the stolen database publicly to make the share price fall.
It's important not to over-simplify the problem. There is no single, simple solution as long as there are many ways to profit from data thefts.