Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

501–510 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#501
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Why are you surprised? The terrorism bogeyman led Americans to spend trillions in tax money only to have those funds eaten up by Boeing and Raytheon and the US end up humiliatingly defeated by the Taliban with nothing to show for 20 years of war.

Why would saying the US is going to treat anything like they treated terrorism be a good thing?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#502

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is. Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world. I despise seeing simple apps with ridiculous dependency trees (package.json with line counts…

> the more material you put into your house, the less vulnerable it is

I have a counter example about scale. The more material you put into a city (the more houses you build), the more vulnerable it is (more potential problems, more opportunities for crime, etc).

While the house is less vulnerable than a tent, it can be secured for only as long as the flow of people and material through this house is very well controlled. The bigger squat house is not necessarily more secure. On a city scale free movement of people and goods is essential, and thus any place can be potentially visited (used) by anyone. We want the same urban infrastructure to be re-used by as many people as possible. There is a huge attack surface.

Code is more like a city. We want the same code to be re-used in as many different contexts as possible.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#503
post #400

Earlier quoted context omitted.

Which only works because they’re paying the ransom. The second the government introduces criminal penalties against the executives and boards for paying ransom, it will stop.

Which only works because they’re paying the ransom. The second the government introduces criminal penalties against the executives and boards for paying ransom, it will stop. Making it a criminal offence to pay a ransom would eventually stop criminals ransoming the data they take to the company they took it from, but it wouldn't stop attacks and data breaches if there's some other way to profit. For example, attacker…

>Or they could ransom individual's data directly to the individual. Or they short the stock of the company and then release the stolen database publicly to make the share price fall.

You're listing a bunch of things that are almost assuredly already happening. If a company was dumb enough to keep social security numbers unencrypted in a database or spreadsheet, that data is going onto the dark web whether they paid a ransom or not.

It's a LOT harder to find a buyer of proprietary data that will likely put the buyer in prison for a long time, than it is to get a ransom from one individual trying to keep the whole thing quiet. Once you advertise "I have Apple's top secret next gen laptop details!!" - when someone releases a strikingly similar laptop, or "leaks" the details on an Apple focused fansite, the feds will be all over them.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#504

This is just DOJ, so far. If ransomware gets defined as terrorism for the US anti-terrorism community, it could become very dangerous to be in the ransomware business. The US has a huge anti-terrorism operation in being, and it's not that busy. Islamic terrorism against the US has been confined to minor local nuts since the US wiped out Bin Laden. And, before that, being "#2 in Al Queda" meant having a rather short l…

Islamic terrorism was confined to minor nuts before 9/11. Some of those minor nuts hijacked a few planes and the US paid trillions of dollars to lose to some more minor nuts in the hinterlands of Afghanistan after 20 years of war.

You think terrorism was a huge operation but it never was. The US made it seem huge to deceive the world, erode human rights, fight needless wars, kill millions of civilians, assert dominance, and waste our money.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#505
post #400

Earlier quoted context omitted.

Which only works because they’re paying the ransom. The second the government introduces criminal penalties against the executives and boards for paying ransom, it will stop.

Which only works because they’re paying the ransom. The second the government introduces criminal penalties against the executives and boards for paying ransom, it will stop. Making it a criminal offence to pay a ransom would eventually stop criminals ransoming the data they take to the company they took it from, but it wouldn't stop attacks and data breaches if there's some other way to profit. For example, attacker…

Using stolen data is a crime already (though I don't know all the details of a complex subject that undoubtedly needs more work to fix).

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#507
> penetrated the pipeline operator on the U.S. East Coast, locking its systems and demanding a ransom. The hack caused a shutdown lasting several days

This rings a little disingenuous, since (IIRC) the shutdown wasn't caused by the hack, the interruption of service was a deliberate choice by Colonial because (in brief) they wouldn't be able to charge their customers until they got their accounting systems working again.

The company, providing arguably an essential service, chose to stop the flow instead of estimating / approximating / using past averages to bill their customers. They likely lost much more revenue this way.

Do correct me if I got this story wrong.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#508
post #302
post #119

Earlier quoted context omitted.

Because the more we pay the hackers the more funding they get to launch further attacks

How does taxing crypto increase hacker pay?

I'm not talking a tax to pay off ransoms. I'm talking a tax to pay back affected parts of society for disruptions.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#509

Earlier quoted context omitted.

Cleary it wasn’t that simple or they would have just done that.

Apparently they ended up having to do just that even after paying the ransom: "The decryption software provided by the hacking group DarkSide, notes Bloomberg, was reportedly 'so slow' that Colonial Pipeline 'continued using its own backups to help restore the system.'" Source- https://mashable.com/article/colonial-pipeline-paid-bitcoin-...

I mean if you have backups then sure, don't pay. Every case won't be that simple. It also seems a bit odd that they'd pay if they truly had all the backups they needed.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#510

Earlier quoted context omitted.

If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?

Restore from backup.

Won't always be that simple. Let's say hackers also compromised the backups.
Post reply on HN