Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

471–480 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#471

Earlier quoted context omitted.

> Yes, building a safe airplane is doable. It didn't start out that way. It took a long time to figure out how. > But this is not a good comparison. I can't agree with that. I don't see any rationale for either airplanes or software systems being special. > Security in a company is not a single system, An airplane isn't, either. For example, part of airplane safety is the air traffic control system. Part is the weath…

> Yes, building a safe airplane is doable. It didn't start out that way. And now only FAA/EASA etc. certified companies and individuals can build a commercial aircraft. And they can only build the aircraft they are certified to, using the same certified components, and the same certified tools. They cannot change any aspect of the construction without another round with the authorities. Let me know when the CIOs of l…

Certification/regulation is something orthogonal to the design methods used.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#472
post #300
post #259

Earlier quoted context omitted.

>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.

If the goal was to disable the pipeline the attacker could just apply thermite somewhere along one of it's many unguarded miles. The reason that doesn't happen is because retribution for such an act would be striking to say the least. It's impossible to prevent all attacks, physical or cyber, so at some point one needs to either submit to an order where attackers act with impunity, or otherwise invest in retribution.

> If the goal was to disable the pipeline the attacker could just apply thermite somewhere along one of it's many unguarded miles. The reason that doesn't happen is because retribution for such an act would be striking to say the least.

For what it's worth, a couple weeks ago someone (according to a manifesto, an anarchist group) did exactly that in Munich - they set about 50 10 kV electricity cables that were laid bare due to construction works ablaze to strike against a military supplier and cut off about 20.000 households for over 36 hours until the utility managed to restore service: https://www.br.de/nachrichten/bayern/stromausfall-in-muenche...

Sabotage or plain old theft against utilities is pretty common, but it's hard to do something physical that truly disrupts service for longer than a day or two - the networks are designed with reliability against all kinds of issues in mind. An IT-based attack leaves no traces if done well and can have a week to month long impact, simply because back when these networks were designed, IT threats were not existing.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#473
post #404
post #259

Earlier quoted context omitted.

>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.

Pulling this thread: say the government regulates it - what do they require? Regulations that say you need to be secure enough to not be hacked? That requirement changes daily. Baseline security standards? Sure. But what is the baseline? And how influenced by lobbyists is that baseline? You know the big security companies would love to have their product be a government requirement. Attackers do not have regulations.…

The government already has baseline security standards that are created and published by the government, not private entities. NIST 800-53[0] is a good example of this, and it generally applies to critical infrastructure providers:

Regulations should not adopt a private company's baseline security standard; we should lean on the work NIST has already done and standards that already apply to (mostly defense) critical infrastructure.

[0]: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#474
post #279

Earlier quoted context omitted.

SCADA's a good example of systems that are difficult to secure for complex reasons. There are many others. You ask a very wise question. Unfortunately, I think it's unknownable. The best we know is that the answer is more than none and less than all. The more you get towards "all" the more prevention measures cost to implement. For instance, managing a mature backup and imaging operation at scale may be conceptually…

Adversarial relationship with security are very often created by very annoying security requirements which do very little to improve security. Like requiring users to change all passwords ever 2 or 3 months and requiring a new password to have characters from every class (see also [1]). While all you need in the most cases is just minimum length requirement and some guidance how to choose a good password. If user wil…

Leaving a key inserted is still a vast improvement over the current situation. Yubikeys have to be pressed to generate a new code each time (as they expire after each use) and the situation you avoid is remote hacking especially via social engineering.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#475

Earlier quoted context omitted.

... but this was 5 years ago and everyone and their dog knows it by now, the company just didn't bother to change that door. Also, the criminal group doesn't hit doors with cameras, but nobody bothered to install one. --- What you described is a zero day, which is very rarely used - most ransomware simply uses the absolutely low hanging fruit of companies lagging behind years in security updates combined with highly…

Companies generally do not have a sufficient tested backup strategy and plan (though backups have only one part to play). Those same companies have probably never suffered any major consequences as a result - which might explain why it’s so usual for this to be a common gap. Sloppy/incomplete backups can probably wing/firefight the more common ‘single server dies’ ‘single directory needs recovering from accidental de…

The backup thing is really weird, I think only very small non-startup companies care about them a lot because they just cannot afford not having them. In all other places when I bring up the topic everybody seems to be lightly surprised and the sense of urgency just isn't there.

Personally I find this just puzzling, in my home folder I loose files at least once a year and I also lost whole partitions. So having no backup at all is no option for me at home. I cannot understand how no or unmaintained backups can be an option at companies.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#476

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

It's impossible to build a safe airliner, but we can get pretty damn close. Airline engineers know one cannot create a component or system that cannot fail. So the question then becomes, assume a system fails. Now how does the airplane survive? With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that f…

I don't think this is valid comparison. If you are trying to compare software on a plane to application, then airplane software is not attempted to hack into due to it being generally well isolated from outside networks. If you are comparing physical build of systems in a plane to software, then hacking of software is equivalent to bird or drone running into an engine or a laser attack or hijack attempt... Which while we know do not happen often, but lets say if a lot of money were to be made by doing so, I'm sure the frequency would increase.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#478
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

IT security is hard, very hard, and a lot of the commercial products used by most companies are terribly insecure. The fact is our IT infrastructure has grown much faster than the global pool of talent who know how to effectively secure it.

So faced with a deficit of expertise, and a constantly changing IT security landscape, it makes perfect sense for governments to support and co-ordinate cyber security efforts. We need to get maximum benefit from the resources we do have and that mans pooled effort, clear best practices, strong security standards, etc.

Personally I see an additional significant benefit coming out of all of this. If governments and politicians skill up in understanding the seriousness of cyber security at a national level, hopefully they will come to understand the deep folly of insisting on backdoors and secret keys to everyone's systems for security and law enforcement agencies. Politicians keep talking some really dumb crap on this topic, but if we can get them to take the security of businesses and citizens seriously, I'm hopeful this will change.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#479
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Crime is a social problem but the US government is especially bad at fixing crime that originates from other countries. See war on drugs, terrorism, call center scams etc. On the other hand, a good team of security experts is very good at preventing computer systems from getting hacked into.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#480

Earlier quoted context omitted.

The HN crowd can sometimes have an issue with pragmatism. Sure, I'd love to live in a world where everyone follows best security practices 100% of the time, but this ain't it. Arguing how your imaginary perfect world should be gets us nowhere.

How much of these hacks would be prevented by adoption of simple preventions like Yubikeys for login, backing up data and images regularly, and encrypting data by default?

Not many.

Typically, these attacks start by compromising a regular workstation by some office drone via Office macro. Then they start escalating privileges by exploiting Kerberoast, RCEs (think BlueKeep, Eternal Blue, Tomcat servers with the default password, etc.) and other quick wins. When they get a clear text password, password hash or kerberos ticket of a privileged account, there is nothing to stop them. Windows doesn't care if you have MFA at the workstations or at your VPN interface. With the hash or a ticket you can perform network logons to any system where you have local admin permissions. Otherwise, this would destroy the entire single sign on feature that Windows and its users love - logon once, access everything. Kerberos is deeply built into the Active Directory.

Backups are fine, sure, but typically you want to figure out what exactly the attackers did and at what point they started doing it, so you know how far back you have to go with your backups, because you want a backup without back doors. So you need to hire special consultants and they take at least a few days, maybe a few weeks to figure this out.

If you don't have offline backups or took some other special precautions, the attackers might have deleted your backups.

After all that, you still need to apply the backups. A process that probably varies widely in length depending on the quality of the admin team and the size of the organisation.

Post reply on HN