Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

511–520 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#511

Earlier quoted context omitted.

If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?

They'd restore from backups, which is already what they did even after paying the ransom. More importantly, would the hack have happened in first place if they knew there was no chance of being paid? Every ransom paid just funds and encourages the next hack. The social damage is deserving of a large fine (i.e. 10x the ransom).

Theoretically, no, the hack wouldn't happen if they knew there was no chance.

Realistically, yes, the hack would still happen. Because there will never be a world where people don't pay ransoms, especially if they have no other options / backups.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#512

Whelp, that's the end of cryptocurrency... probably should sell your HODLings now. If we're going to Patriot Act the crud out of ransomware, Bitcoin is gonna be illegal.

Yeah, that's what happened with drugs. The price of drugs actually dropped to zero and it's now impossible to get LSD.

What? How? When? What? I don't get the joke.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#513

Earlier quoted context omitted.

> Yes, building a safe airplane is doable. It didn't start out that way. It took a long time to figure out how. > But this is not a good comparison. I can't agree with that. I don't see any rationale for either airplanes or software systems being special. > Security in a company is not a single system, An airplane isn't, either. For example, part of airplane safety is the air traffic control system. Part is the weath…

> Yes, building a safe airplane is doable. It didn't start out that way. And now only FAA/EASA etc. certified companies and individuals can build a commercial aircraft. And they can only build the aircraft they are certified to, using the same certified components, and the same certified tools. They cannot change any aspect of the construction without another round with the authorities. Let me know when the CIOs of l…

> Let me know when the CIOs of listed companies are up for that kind of lifestyle for their email and word processors.

I think you're absolutely right that this kind of rigidity is not part of our tech culture, but maybe it should be if that tech is running power grids, [oil] pipelines, and other critical infrastructure.

In summary - maybe we should spend more money so that we get systems which are reliable and resistant to this kind of attack. (_I_ think that's probably a good investment for power/transit/core network/safety systems)

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#514

Earlier quoted context omitted.

And a lot of cases where around the table you have those who say "here is the risk that must be addressed" and then the others who say "if we do that we break production". Both are truthful and full of good will.

"Here is the risk that 737 max will crash because of mcas" And then others say: " if we do that, we will have to redesign too much of the airligher" i.em break production. Youve got to have your priorities straight

This is why I wrota about the imaginary plane that flies above oceans without people nobody care about. In such a case the priorities are not obvious at all.

If this is a real plane then there are consequences for the company and people (jail). Suddenly it makes sense to fix things.

The software industry is in the former case - new code being diarrhea-ed down without any consequences if it is hacked.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#515

Earlier quoted context omitted.

It's impossible to build a safe airliner, but we can get pretty damn close. Airline engineers know one cannot create a component or system that cannot fail. So the question then becomes, assume a system fails. Now how does the airplane survive? With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that f…

But there is a big difference between airline safety and software safety. An airliner survives against the environment, it's PvE, a software system has to survive against hackers, it's PvP. If you shoot a rocket at an airliner, the airliner will fail, in that case we blame the person who shot the rocket.

Not only that, but we spend billions of dollars on defense to protect those airlines from bad actors. I mean when a person blows up a bomb in an airplane, our response isn't "build bomb-proof airplanes".

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#517

Earlier quoted context omitted.

But there is a big difference between airline safety and software safety. An airliner survives against the environment, it's PvE, a software system has to survive against hackers, it's PvP. If you shoot a rocket at an airliner, the airliner will fail, in that case we blame the person who shot the rocket.

Not only that, but we spend billions of dollars on defense to protect those airlines from bad actors. I mean when a person blows up a bomb in an airplane, our response isn't "build bomb-proof airplanes".

You're correct.

Historically the choices were made to spend billions (and trillions) of dollars to invade countries harboring terrorists and use the situation to project power against other adversaries, advantageously control the price of oil, work trade deals, etc.

I predict the same path will be taken with cybercrime. The U.S. defense apparatus won't be giving subsidies to non-tech companies to boost security. Rather, they'll be waging war and using overlapping objectives and narratives to further other goals.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#518
post #366

Earlier quoted context omitted.

It's surprising and disappointing to see this point of view here, particularly with so little evident dissent. Of course you can "break into" a typical computer system by gaining physical access to it, for example by breaking into the house that it's in and unscrewing the computer's case; but that's only metaphorically connected to what's going on here, which is that criminals are sending data over the internet to th…

> The problem is that our systems are architected so that even one exploitable bug anywhere in hundreds of millions of lines of code enables total and irreversible subversion of the system A modern jet airliner uses about 1,500,000 bolts and screws. Imagine if they were designed so that a failure of any one of them could cause a catastrophic failure of the entire aircraft. Then imagine if people were defending it by…

I am definitely going to use this wonderful analogy. Thank you.

(Yes, fuzzy metaphorical reasoning is what misled us in the first place, but the problem isn't that the "this is victim blaming, you can always break into a house" people are using fuzzy metaphorical reasoning; it's that, like physics crackpots trying to build the Grand Unified Theory out of styrofoam models, they are only using fuzzy metaphorical reasoning.)

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#519

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

It's impossible to build a safe airliner, but we can get pretty damn close. Airline engineers know one cannot create a component or system that cannot fail. So the question then becomes, assume a system fails. Now how does the airplane survive? With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that f…

> And the largest piece of hubris and madness in critical systems is allowing over-the-internet updates.

What would you suggest in its place?

You'd need to replace the internet with something - postal mail, Fedex, courier deliveries, etc, or just have things that never get upgraded. Every one of those options has significant limitations, and in many countries, I'd trust SSL over postal mail every single day.

I think if you alter the wording to be "more-secure internet deliveries" then you'll have me agreeing with you, but unless I've missed something, your comment seems poorly aimed (which is odd, as your previous example of the root password is spot-on).

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#520

Earlier quoted context omitted.

Adversarial relationship with security are very often created by very annoying security requirements which do very little to improve security. Like requiring users to change all passwords ever 2 or 3 months and requiring a new password to have characters from every class (see also [1]). While all you need in the most cases is just minimum length requirement and some guidance how to choose a good password. If user wil…

Leaving a key inserted is still a vast improvement over the current situation. Yubikeys have to be pressed to generate a new code each time (as they expire after each use) and the situation you avoid is remote hacking especially via social engineering.

Not all u2f keys require being touched. That's an optional hardware implementation detail, rather than a mandatory trait across all u2f devices. Yubikey sells keys that are commonly used by plugging them in, leaving them, and never again touching them. This effectively turns the computer itself into the second factor.

Depending on the precise scenario, that may or may not represent an improvement. If the key is used as a second factor to authenticate to the network, then an infected Excel document will trivially ignore the involvement of a Yubikey as it uses the logged-in user's Kerberos ticket to spread.

You're completely right, though. Even this would definitely cut down on phishing attacks that send users to fake websites pretending to be internal systems.

Post reply on HN