Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

451–460 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#451

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is. Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world. I despise seeing simple apps with ridiculous dependency trees (package.json with line counts…

> the more material you put into your house, the less vulnerable it is

I think you have cause and effect backwards.

Yes, if you want to build a more secure house, you will need more material than another house with equivalent functionality. However, a bigger building isn't magically more secure than a smaller building.

If you walk into my house, I will detect and kick you out almost immediately. If you walk into our office building all you need is a hardhat and a confident stride and you can get anywhere you like. Hell, people will probably even help you get there.

Which makes it similar to code. The smallest app in terms of total 'material' builds up its queries with string concatenation. It takes a lot of 'material' to prevent those kind of injection vulnerabilities. And yes, a data access library that helps you with that is also 'material'.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#452

Earlier quoted context omitted.

But there is a big difference between airline safety and software safety. An airliner survives against the environment, it's PvE, a software system has to survive against hackers, it's PvP. If you shoot a rocket at an airliner, the airliner will fail, in that case we blame the person who shot the rocket.

> But there is a big difference between airline safety and software safety I've worked professionally in both industries; they are not fundamentally different. Software practices can learn a lot from aviation practice, but they seem determined to spend decades rediscovering the methods the bitter, expensive way. For example, software is still stuck in the dark ages where the idea is better training / better programme…

> For example, software is still stuck in the dark ages where the idea is better training / better programmers / more punishment will prevent these sorts of failures.

What is your source on this? This goes against what anyone at any company where I have worked at ever believed.

No-fault root cause analysis, process improvements, inherently safer practices, languages, libraries is what every place aimed for. I don’t even know what you might mean by punishment?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#453
post #404
post #259

Earlier quoted context omitted.

>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.

Pulling this thread: say the government regulates it - what do they require? Regulations that say you need to be secure enough to not be hacked? That requirement changes daily. Baseline security standards? Sure. But what is the baseline? And how influenced by lobbyists is that baseline? You know the big security companies would love to have their product be a government requirement. Attackers do not have regulations.…

Money laundering is a similarly difficult problem. Most of the rules are written in a "spirit" manner, instead of a "prescriptive" manner. With AML (anti-money laundering), you often hear the term "red flags". They are signs, but not a source of absolute truth. I could foresee something like AML in the form of corporate computer security coming soon. In the same way that Sarbanes-Oxley forever changed corporate accounting after the Worldcom and Enron accounting scandals of early 2000s (top execs now need to sign-off on yearly account) -- imagine if top execs need to sign-off on corporate computer security. As I see it, CTO-cum-head-of-security will soon be signing yearly audit documents in blood.

And the trick to making AML regulations effective is massive fines -- fines so large that they genuinely affect quarterly earnings and stock prices. The same could be done with corporate computer security regulations.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#454
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

> It's physically impossible to build a house that can't be broken in to

Specially if an entity with a nation's resources is trying to get in.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#455
post #404

Earlier quoted context omitted.

Pulling this thread: say the government regulates it - what do they require? Regulations that say you need to be secure enough to not be hacked? That requirement changes daily. Baseline security standards? Sure. But what is the baseline? And how influenced by lobbyists is that baseline? You know the big security companies would love to have their product be a government requirement. Attackers do not have regulations.…

IT can't be looked at as a cost center anymore. The constant pressure of cost reduction is what causes these failures to happen in the first place, because nobody running the infrastructure really cares. If something goes wrong, they're out of a job anyway.

This is an interesting point. If the relentless drive to reduce cost in IT is the root cause of so many corporate computer security issues, why isn't corporate accounting (which is covered in the US by near-draconian Sarbanes-Oxley rules) not similarly affected? I point to regulations.

Further, would the same be true of giant pharma companies that create drugs that we ingest? ("Oh, skip those tests. If a few people get injured, we'll pay hush money.") Why don't we see it? Simple: Incredibly strong regulations in US/EU/Japan (the "big three" for global drug regulation & approval).

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#456

Earlier quoted context omitted.

The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping f…

I think if you had good attribution it's more like armies. We have been focused on locking our doors, on building better walls, etc. But there is a non-defensive side. In meatspace we expect the government to use kinetic force to stop people from attacking us. Like if I leave my door unlocked and some person comes in to start stealing my stuff, the cops really will respond and come stop that person (I have had a home…

So you have group of 20 somethings in russia that you suspect are behind the hack.

What do you do ? Sending a single missile/drone wont work because Russia has air defense (probably - with them you never know how on top they are, but they will after the 1st one). Sending multiple might work, but Russia might fire back and start a war.

Sending special forces, or whatever would probably work better first few times, until Russia deliberately set's a trap for them.

How about if they are form China, or maybe France or India and you don't relay have prof that would stand in court ?

And then what, it's not like USA doesn't have its own hackers that do shady stuff internationally. Other countries have spacial forces as well.

I am not sure we want to go this way.

In practice that means US doing whatever they want in poor countries (where they already do whatever they want), and not doing much in powerful enough countries where most of those criminals actually are.

Most of the time we don't even know definitively who is behind the hacks, so it's kind of a moot point.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#457
This article reminds me about another published by The Harvard Gazette, Government can't keep up with the technology. The article argues that big techs are keeping larger and larger for government to keep up with the pace. In case of ransomeware, government and the Supreme Court are trying to keep up but in my opinion, it will be long before government and bureaucracy could address the problem. Same happened in case of Bitcoin. Sure now everyone wants regulations around Cryptocurrency but it seems governments are investing in lost causes of catching up with these growing uncertainties.

I don't mean that government shouldn't be engaging in these talks and try to regulate these markets, my only concern is the pace of these two entities. Instead of using the same old frameworks of regulations and same old mentalities, unorthodox approaches can better address these issues.

P.S Link to The Harvard Gazette article: https://news.harvard.edu/gazette/story/2019/02/government-ca...

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#458
post #279

Earlier quoted context omitted.

Is that the case with all of these hacks? How many would be prevented, is what I'm wondering? My mother's hospital was hacked this week and now they can't even clock in but they're not running SCADA

SCADA's a good example of systems that are difficult to secure for complex reasons. There are many others. You ask a very wise question. Unfortunately, I think it's unknownable. The best we know is that the answer is more than none and less than all. The more you get towards "all" the more prevention measures cost to implement. For instance, managing a mature backup and imaging operation at scale may be conceptually…

Adversarial relationship with security are very often created by very annoying security requirements which do very little to improve security. Like requiring users to change all passwords ever 2 or 3 months and requiring a new password to have characters from every class (see also [1]). While all you need in the most cases is just minimum length requirement and some guidance how to choose a good password.

If user will have to enter 16 charter password each time after HW key (like Yubikey) will be connected to a computer to unlock it, then users will leave it always inserted. Or password will be saved in a text file. If HW key will just work once inserted (or will require 4 digit pin) most users will comply. It is already 2nd factor in addition to some other password, it doesn't necessary need a strong password to use it.

[1] https://passwordfromhell.com/

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#459
post #402

Earlier quoted context omitted.

OSS licenses include a very broad waiver, after all it is a gift provided as-is. Software that runs critical infrastructure (or could cause injury or death if it malfunctioned) should be required to use formal methods and that certainly would include everything to make it run also used such formal methods. (From the OS to shared libraries and even the compilers)

A lot of commercial software has similar waivers, too. See Windows 10. "Microsoft and the device manufacturer and installer exclude all implied warranties and conditions, including those of merchantability, fitness for a particular purpose, and non-infringement." You'd have to outlaw that or breed a more discerning consumer. One way to do that would be to blame the company using it, which would make them take more ca…

Signaling is where this is done right.

The software that schedules trains can do what it likes, because there are several, independent safety layers below it: the signaling system itself, and the software and hardware locks within the signaling system, and formal methods usedto prove their integrity.

Any signaling failure will fail safe (all trains stop).

Any trusted actor (controller, train driver, sometimes passengers etc) can also stop part or all of the system. (On many European railways, if the driver sees a problem, like a car crashed into the railway, they press a red button and all trains in that region are halted.)

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#460

Earlier quoted context omitted.

> But there is a big difference between airline safety and software safety I've worked professionally in both industries; they are not fundamentally different. Software practices can learn a lot from aviation practice, but they seem determined to spend decades rediscovering the methods the bitter, expensive way. For example, software is still stuck in the dark ages where the idea is better training / better programme…

> For example, software is still stuck in the dark ages where the idea is better training / better programmers / more punishment will prevent these sorts of failures. What is your source on this? This goes against what anyone at any company where I have worked at ever believed. No-fault root cause analysis, process improvements, inherently safer practices, languages, libraries is what every place aimed for. I don’t e…

> What is your source on this?

See "Trust the programmer" https://beza1e1.tuxen.de/articles/spirit_of_c.html

Also, a general belief among C++ programmers that better training is the answer to programming bugs. This belief is slowly fading, but it's got a long way to go. Scott Meyers' books on Effective C++ represent a lot of effort to educate programmers out of making mistakes. For example, from the table of contents: "Prefer consts, enums, and inlines to #defines". If C++ was an airplane, #define would simply be removed.

> I don’t even know what you might mean by punishment?

There are several calls for punishment in the comments on the article.

Post reply on HN