Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

461–470 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#461

Earlier quoted context omitted.

> Yes, building a safe airplane is doable. It didn't start out that way. It took a long time to figure out how. > But this is not a good comparison. I can't agree with that. I don't see any rationale for either airplanes or software systems being special. > Security in a company is not a single system, An airplane isn't, either. For example, part of airplane safety is the air traffic control system. Part is the weath…

Imagine you had airplanes be built the way they wanted, crashing from time to time, not starting and having people work on the wings to fix things in flight. If this was something done for fun and without impact on people then nobody would care. Suddenly, a Monday morning, someone says "woah, this cannot be - you have to fix this". But this is not fixable, you have to build a new plane from scratch, or completely rev…

Um, airplanes are constantly undergoing revision and improvements and bug fixes. Only very serious ones result in grounding. Eventually, they become too expensive to upgrade and Boeing/Airbus designs a ground up replacement.

Just like software.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#462
All this talk about software (in)security within companies reminds me of a typical conclusion after a data leak. When it's a large company, the conclusion is they may, and should, have done better, but it's inherently impossible for a large company to secure everything well enough. When it's a small company, the conclusion is they should have done better, but it's inherently impossible for a small company to, well, do better, they are too small.

Now, I'm all for treating ransomware, and generally all the large scale and/or state-sponsored hacks with a much higher priority, send the drones and whatnot. But this MUST be accompanied by more accountability on the commercial entities.

You're too small to secure sensitive data of hundreds of millions of people? Maybe you shouldn't have amassed this data in the first place. You're too big to secure everything? Well, did you secure ANYTHING? Did you follow reasonable procedures, did you, crazy idea, make sure you can't access critical systems from the internet and/or with a default password, etc.?

And if you fail, and fail you will, there's no perfect system, I believe there should be penalties not for failing, but for not doing enough to prevent it. To refer to all the plane analogies, if your wings are made of cardboard and everybody knew but pretended it's OK, because otherwise it would slightly diminish shareholder value, well, there will be consequences.

In aviation, you could go to jail for signing off on something that you know is not secure, if it causes an accident and people die. Specifically not for accidents, but for neglecting your duty to make sure that you've done all you could. For lying, deceiving, ignoring, faking, for being too lazy or too greedy to do things properly. Sounds familiar?

With large scale infrastructure under constant attacks, people dying because someone couldn't be bothered to do things properly is not an "if" any more. And better hope those autonomous trucks are very, very hard to hack.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#463
post #288

I think this is needed because the security industry seems to be well on the way to adopting paying off these people as a routine cost of business. That is going to lead to an absolute disaster if it is allowed to continue and grow. It needs to be a double edged sword though where companies are just as afraid of facilitating ransomware attacks as they would be of the consequences of facilitating terrorists. In other…

Let's just hope it won't be the same kind of priority as "terrorist" was after 9/11, with useless wars, TSA and all the security theater.

> Let's just hope

Is that the best USians have at this point? Hope? After "useless wars, TSA and all the security theater" the best you have is hope it will not repeat itself?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#464

Earlier quoted context omitted.

Yes, building a safe airplane is doable. But this is not a good comparison. Securing a company is like saying that you have to chnage all of the wiring in a country without impacting power supply. ALL of them - the house wirings, the cables transporting power, everyting. At once. Security in a company is not a single system, it is a messy interaction of unknown dependencies nobody understands. And this mess runs a bu…

> Yes, building a safe airplane is doable. It didn't start out that way. It took a long time to figure out how. > But this is not a good comparison. I can't agree with that. I don't see any rationale for either airplanes or software systems being special. > Security in a company is not a single system, An airplane isn't, either. For example, part of airplane safety is the air traffic control system. Part is the weath…

> Yes, building a safe airplane is doable. It didn't start out that way.

And now only FAA/EASA etc. certified companies and individuals can build a commercial aircraft.

And they can only build the aircraft they are certified to, using the same certified components, and the same certified tools. They cannot change any aspect of the construction without another round with the authorities.

Let me know when the CIOs of listed companies are up for that kind of lifestyle for their email and word processors.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#465

uh... next time when the US targets Iran for example with stuxnet, will that mean they will call themselves terrorists now.... great. i didn't know that

Isn't that by definition terrorism? It's unlawful use of violence in pursuit of political aims. I think we should punish the responsible...

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#466

Earlier quoted context omitted.

I have seen personally, heard first hand accounts, and read many a post-mortem for situations where the primary blame really should be on the "victim". There's another word for this: Negligence. Of course there are always 0days. There are always sophisticated attacks. There is always human error. Then there are people in leadership positions being given accurate information about basic security problems and possible…

And a lot of cases where around the table you have those who say "here is the risk that must be addressed" and then the others who say "if we do that we break production". Both are truthful and full of good will.

"Ok, that means our current business practices are a liability. Gather the process owners to see what can be done".

What you're describing isn't (shouldn't be) the end of discussion. The trick is to get management to explicitly acknowledge the liabilities.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#467

Earlier quoted context omitted.

> But there is a big difference between airline safety and software safety I've worked professionally in both industries; they are not fundamentally different. Software practices can learn a lot from aviation practice, but they seem determined to spend decades rediscovering the methods the bitter, expensive way. For example, software is still stuck in the dark ages where the idea is better training / better programme…

> For example, software is still stuck in the dark ages where the idea is better training / better programmers / more punishment will prevent these sorts of failures. What is your source on this? This goes against what anyone at any company where I have worked at ever believed. No-fault root cause analysis, process improvements, inherently safer practices, languages, libraries is what every place aimed for. I don’t e…

There are many, many programmers, you can see their comments right here, that fit (for many, probably despite their age), into what you could call brogrammer/cowboy coder/lone star/rockstar developer types and that will try to shame developers making mistakes or present certain types of failures as inevitable, "you just need better developers".

You can frequently see them come out in Rust threads, they're generally against it, coming from C/C++, it seems a common attitude amongst low level devs in my experience (there's a thing with "hardware" sounding "hard" which I guess makes them feel more "hardcore").

It's obviously not universal, but it's super easy to find if you search for some programming language discussions.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#468
post #432

Earlier quoted context omitted.

The debate is pretty much divided between people who say "improved security is the solution" and people who say "treating it as crime/terrorism/the-mafia is the solution". I'm in the improve the security camp. I think security can be improved if we impose good standards (meaning enforce inconvenient things like no backdoor updating apps, no critical infrastructure connected to the web). The reason "treating this like…

Your viewpoint is extreme. Saying the increased effort by law enforcement is “useless” is unfounded. Sure, it won’t solve the problem by itself, but it’s entirely possible it will help.

What is the percentage of hacks that are ultimately traced to individual and result in his imprisonment? 0.1%? Are you going to ever get that even over 10%?

If the hack comes from a jurisdiction without extradition, how will you solve that? How foea a country know they are not allowing their citizens to be harrassed with trumped up charges? What if definition of hacking differs in two countries?

It is not just Russia and China, Denmans and Uk have refused to extradite to the US becausw pf concerns over inhumane treatment.

https://www.theguardian.com/world/2019/may/10/dutch-court-bl...

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#469

Earlier quoted context omitted.

I have seen personally, heard first hand accounts, and read many a post-mortem for situations where the primary blame really should be on the "victim". There's another word for this: Negligence. Of course there are always 0days. There are always sophisticated attacks. There is always human error. Then there are people in leadership positions being given accurate information about basic security problems and possible…

And a lot of cases where around the table you have those who say "here is the risk that must be addressed" and then the others who say "if we do that we break production". Both are truthful and full of good will.

"Here is the risk that 737 max will crash because of mcas"

And then others say: " if we do that, we will have to redesign too much of the airligher" i.em break production.

Youve got to have your priorities straight

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#470
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

> I'm a bit tired of the victim blaming with security.

Why? Many of the companies who got hacked had massive IT issues of their own fault, the most common being:

- full access for everything across the whole network, no subnetting with strict firewalls that limits the scope of an intrusion

- outdated software/firmware stacks leading to avenues for compromise

- no/ineffective/outdated virus scanners

- no meaningful backup infrastructure and regular testing if said infrastructure is already working

- lack of 2FA on administrative credentials

- lack of monitoring on central file servers to detect if a compromised machine is encrypting the file server's contents piece by piece

> It's physically impossible to build a house that can't be broken in to

Indeed, but a burglary insurance will likely refuse service or jack up rates if you don't lock your door or not have an alarm system installed.

Post reply on HN