Earlier quoted context omitted.
> Yes, building a safe airplane is doable. It didn't start out that way. It took a long time to figure out how. > But this is not a good comparison. I can't agree with that. I don't see any rationale for either airplanes or software systems being special. > Security in a company is not a single system, An airplane isn't, either. For example, part of airplane safety is the air traffic control system. Part is the weath…
> Yes, building a safe airplane is doable. It didn't start out that way. And now only FAA/EASA etc. certified companies and individuals can build a commercial aircraft. And they can only build the aircraft they are certified to, using the same certified components, and the same certified tools. They cannot change any aspect of the construction without another round with the authorities. Let me know when the CIOs of l…
U.S. to give ransomware hacks similar priority as terrorism, official says
471–480 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#472Earlier quoted context omitted.
>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.
If the goal was to disable the pipeline the attacker could just apply thermite somewhere along one of it's many unguarded miles. The reason that doesn't happen is because retribution for such an act would be striking to say the least. It's impossible to prevent all attacks, physical or cyber, so at some point one needs to either submit to an order where attackers act with impunity, or otherwise invest in retribution.
For what it's worth, a couple weeks ago someone (according to a manifesto, an anarchist group) did exactly that in Munich - they set about 50 10 kV electricity cables that were laid bare due to construction works ablaze to strike against a military supplier and cut off about 20.000 households for over 36 hours until the utility managed to restore service: https://www.br.de/nachrichten/bayern/stromausfall-in-muenche...
Sabotage or plain old theft against utilities is pretty common, but it's hard to do something physical that truly disrupts service for longer than a day or two - the networks are designed with reliability against all kinds of issues in mind. An IT-based attack leaves no traces if done well and can have a week to month long impact, simply because back when these networks were designed, IT threats were not existing.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#473Earlier quoted context omitted.
>The market doesn’t incentivize security until it is too late. That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.
Pulling this thread: say the government regulates it - what do they require? Regulations that say you need to be secure enough to not be hacked? That requirement changes daily. Baseline security standards? Sure. But what is the baseline? And how influenced by lobbyists is that baseline? You know the big security companies would love to have their product be a government requirement. Attackers do not have regulations.…
Regulations should not adopt a private company's baseline security standard; we should lean on the work NIST has already done and standards that already apply to (mostly defense) critical infrastructure.
[0]: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#474Earlier quoted context omitted.
SCADA's a good example of systems that are difficult to secure for complex reasons. There are many others. You ask a very wise question. Unfortunately, I think it's unknownable. The best we know is that the answer is more than none and less than all. The more you get towards "all" the more prevention measures cost to implement. For instance, managing a mature backup and imaging operation at scale may be conceptually…
Adversarial relationship with security are very often created by very annoying security requirements which do very little to improve security. Like requiring users to change all passwords ever 2 or 3 months and requiring a new password to have characters from every class (see also [1]). While all you need in the most cases is just minimum length requirement and some guidance how to choose a good password. If user wil…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#475Earlier quoted context omitted.
... but this was 5 years ago and everyone and their dog knows it by now, the company just didn't bother to change that door. Also, the criminal group doesn't hit doors with cameras, but nobody bothered to install one. --- What you described is a zero day, which is very rarely used - most ransomware simply uses the absolutely low hanging fruit of companies lagging behind years in security updates combined with highly…
Companies generally do not have a sufficient tested backup strategy and plan (though backups have only one part to play). Those same companies have probably never suffered any major consequences as a result - which might explain why it’s so usual for this to be a common gap. Sloppy/incomplete backups can probably wing/firefight the more common ‘single server dies’ ‘single directory needs recovering from accidental de…
Personally I find this just puzzling, in my home folder I loose files at least once a year and I also lost whole partitions. So having no backup at all is no option for me at home. I cannot understand how no or unmaintained backups can be an option at companies.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#476Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
It's impossible to build a safe airliner, but we can get pretty damn close. Airline engineers know one cannot create a component or system that cannot fail. So the question then becomes, assume a system fails. Now how does the airplane survive? With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that f…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#477Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#478I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
So faced with a deficit of expertise, and a constantly changing IT security landscape, it makes perfect sense for governments to support and co-ordinate cyber security efforts. We need to get maximum benefit from the resources we do have and that mans pooled effort, clear best practices, strong security standards, etc.
Personally I see an additional significant benefit coming out of all of this. If governments and politicians skill up in understanding the seriousness of cyber security at a national level, hopefully they will come to understand the deep folly of insisting on backdoors and secret keys to everyone's systems for security and law enforcement agencies. Politicians keep talking some really dumb crap on this topic, but if we can get them to take the security of businesses and citizens seriously, I'm hopeful this will change.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#479I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#480Earlier quoted context omitted.
The HN crowd can sometimes have an issue with pragmatism. Sure, I'd love to live in a world where everyone follows best security practices 100% of the time, but this ain't it. Arguing how your imaginary perfect world should be gets us nowhere.
How much of these hacks would be prevented by adoption of simple preventions like Yubikeys for login, backing up data and images regularly, and encrypting data by default?
Typically, these attacks start by compromising a regular workstation by some office drone via Office macro. Then they start escalating privileges by exploiting Kerberoast, RCEs (think BlueKeep, Eternal Blue, Tomcat servers with the default password, etc.) and other quick wins. When they get a clear text password, password hash or kerberos ticket of a privileged account, there is nothing to stop them. Windows doesn't care if you have MFA at the workstations or at your VPN interface. With the hash or a ticket you can perform network logons to any system where you have local admin permissions. Otherwise, this would destroy the entire single sign on feature that Windows and its users love - logon once, access everything. Kerberos is deeply built into the Active Directory.
Backups are fine, sure, but typically you want to figure out what exactly the attackers did and at what point they started doing it, so you know how far back you have to go with your backups, because you want a backup without back doors. So you need to hire special consultants and they take at least a few days, maybe a few weeks to figure this out.
If you don't have offline backups or took some other special precautions, the attackers might have deleted your backups.
After all that, you still need to apply the backups. A process that probably varies widely in length depending on the quality of the admin team and the size of the organisation.