Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

521–530 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#521
post #516

The government should make it a criminal offence to pay a ransom to hackers. Just as with kidnappings, when you pay ransoms, you reward the criminals.

The government should also cover any damages, then, for failing to protect its citizens, if it will prevent them from remedying the situation themselves.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#522
post #305

Earlier quoted context omitted.

> The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? They can publish best practices, research vulnerabilities, provide educational support, and generally do all the kinds of things governments do to encourage the right behaviors. We have some of this, but at some point, switched to the se…

It makes me wonder there the offense is. Where is the asymmetric response that sends a clear message not to do this again?

What’s a proportional response? Say we shut down the druzhba by bricking Transnefts systems.

How are we going to handle the calls from very angry officials in Ukraine, Belarus, Poland, Hungary, Slovakia, the Czech Republic and Germany?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#523

Earlier quoted context omitted.

yeah of course it's an analogy. But by adding liability we'll get more recalls (patches) done. Vendors will stop playing FUD and will focus on the real cost of their security flaws. And yes some will still not do patches, just like some car vendors are considered less trustworthy. But at least the risk of suit will loom over their heads.

But the parent's point is that's still putting the liability on the vendor rather than the actual criminal. Perhaps it's more like if a car is sold without an immobilizer or an alarm, holding the manufacturer liable if it's stolen. But if that kind of fails, because it's pretty simple to mandate a handful of security additions to cars, whereas software is orders of magnitude more varied and complex. It would be hard…

Yeah, I think it's just a fault in the analogy and in part demonstrating why reason from analogy is faulty.

My point is this If vendors were liable (at least in part) for security faults in their products, then they would be more diligent about closing those gaps.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#524
post #367

Earlier quoted context omitted.

IMO the first step to fixing is to add liability. If a breach happens through a piece of software, then the vendor is liable. Same way cars get recalls. (sometimes)

Liable in what way? Wouldn't that just kill OSS? Or do you not count programmers who upload swiss-cheese scripts to Github as vendors? What about Linux, openSSH, etc?

I do think this might encourage companies to actually support (Financially) OSS they use.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#525

Earlier quoted context omitted.

Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is. Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world. I despise seeing simple apps with ridiculous dependency trees (package.json with line counts…

> but nobody can exploit hello world If I may quibble over a technicality, hello world is just one layer of an already complex technology stack. Suppose someone was able to slip code somewhere deeper in the stack such as your printf implementation (which generally a programmer will, and should, trust just works like it's supposed to) that opened a C2 channel. Then when you run your innocent hello world program, you'r…

Exactly this. And, of course in practice, it's also the OS, firmware and so much more.

Your comment speaks to exactly how people underestimate the true attack surface. It's far more vast than most anticipate, and their conception of it tends heavily towards the literal surface.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#526

Earlier quoted context omitted.

> For example, software is still stuck in the dark ages where the idea is better training / better programmers / more punishment will prevent these sorts of failures. What is your source on this? This goes against what anyone at any company where I have worked at ever believed. No-fault root cause analysis, process improvements, inherently safer practices, languages, libraries is what every place aimed for. I don’t e…

> What is your source on this? See "Trust the programmer" https://beza1e1.tuxen.de/articles/spirit_of_c.html Also, a general belief among C++ programmers that better training is the answer to programming bugs. This belief is slowly fading, but it's got a long way to go. Scott Meyers' books on Effective C++ represent a lot of effort to educate programmers out of making mistakes. For example, from the table of contents…

>If C++ was an airplane, #define would simply be removed.

So would that make D the airplane version of C++?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#527

Earlier quoted context omitted.

Not only that, but we spend billions of dollars on defense to protect those airlines from bad actors. I mean when a person blows up a bomb in an airplane, our response isn't "build bomb-proof airplanes".

You're correct. Historically the choices were made to spend billions (and trillions) of dollars to invade countries harboring terrorists and use the situation to project power against other adversaries, advantageously control the price of oil, work trade deals, etc. I predict the same path will be taken with cybercrime. The U.S. defense apparatus won't be giving subsidies to non-tech companies to boost security. Rath…

Cyberwarfare will be used to further terrible agendas (and already is) - that must be fought politically, but I am plenty jaded enough to see where that is likely to go. Unfortunately not participating in Cyberwarfare is not an option.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#528

Earlier quoted context omitted.

Not only that, but we spend billions of dollars on defense to protect those airlines from bad actors. I mean when a person blows up a bomb in an airplane, our response isn't "build bomb-proof airplanes".

You're correct. Historically the choices were made to spend billions (and trillions) of dollars to invade countries harboring terrorists and use the situation to project power against other adversaries, advantageously control the price of oil, work trade deals, etc. I predict the same path will be taken with cybercrime. The U.S. defense apparatus won't be giving subsidies to non-tech companies to boost security. Rath…

I disagree - Russia seems to be a large source of these crimes and they are a bit too big to invade (without nuclear bombs it might be possible, but only a fool would invade given they have them)

We might seem some special forces go into action under cover. However it would be assassinations done in such a way that Russia either won't know who did them, or is willing to look the other way (the later implies something diplomatic).

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#529

Earlier quoted context omitted.

they made a LOT more than 5m. I would have also been putting bets into the markets much earlier and cashing in on the stupid chaos. Continuing to let them do this with impunity is going to lead to escalated attacks.

Those bets could be easier to trace than the ransom payment though. Is there a way to make market bets completely untraceably?

Let's not do the criminals' jobs for them.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#530

Earlier quoted context omitted.

they made a LOT more than 5m. I would have also been putting bets into the markets much earlier and cashing in on the stupid chaos. Continuing to let them do this with impunity is going to lead to escalated attacks.

Those bets could be easier to trace than the ransom payment though. Is there a way to make market bets completely untraceably?

Yes they can just pay in monero.
Post reply on HN