Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

291–300 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#291
post #285

I wish a country would pass the following law: 1. Any company that makes software with low-level access to systems (i.e. admin privileges on Windows, root privileges on UNIX systems) is criminally responsible for any security breaches of its software, unless it can prove that it took all reasonable steps to keep their software safe. 2. The CEO and CFO will receive a mandatory 30 day jail sentence on the first instanc…

> criminally responsible for any security breaches Criminally? A bit wild. MIcrosoft would probably be bankrupt by now. Just look at PrintNightmare from this week.

Re: US companies hit by 'colossal' cyber-attack

#292

One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...

A cashless society is scary. Cash should always be an option and the inventory system should be disconnected from the internet.

You can pay with cash at Coop. Most if not all cash registers allow cash payments. Most customers don't pay with cash.

Re: US companies hit by 'colossal' cyber-attack

#293
post #285

I wish a country would pass the following law: 1. Any company that makes software with low-level access to systems (i.e. admin privileges on Windows, root privileges on UNIX systems) is criminally responsible for any security breaches of its software, unless it can prove that it took all reasonable steps to keep their software safe. 2. The CEO and CFO will receive a mandatory 30 day jail sentence on the first instanc…

I get the outrage when a company leaks its customer data due to a security breach (or, really, for any reason). But punishing the victims of a crime to encourage better protections? Isn't that the same as to punish house owners in case of burglary for failing to protect their home appropriately?

Re: US companies hit by 'colossal' cyber-attack

#295
post #252

Earlier quoted context omitted.

Gee, cashless is such a great idea. In related news, I saved money by replacing all my house's circuit breakers with old pennies.

I dont think this is necessarily due to 'cashless' as much as general computerization. Stuff like prices, article numbers and inventory are likely all digitized nowadays, so even if people could pay with cash I imagine they'd still be keeping closed.

Why isn't the local shop's systems autonomous - the should sync to the company central, sure, but they shouldn't need constant connection to lookup prices.

Re: US companies hit by 'colossal' cyber-attack

#296
post #44

Earlier quoted context omitted.

> The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If it was me (it was not), I’d use it to gain persistance in companies like Kaseya, extending my beachhead as first priority. After that is basically game over, cleaning it would take making new IT systems from scratch. And lets not forget firmware…

> If it was me (it was not) Sure…

Sure. No melted craters, no fallout.

Re: US companies hit by 'colossal' cyber-attack

#297

The paradox is: The company i work for is (in terms of modern technology) decades behind (we just don`t need it), but in the context of the every bigger growing cybersecurity risk its perhaps an advantage...

Sure is. Whenever I see a company or product brag about how many millions of lines of code it has I shudder. What could be hidden in that maze? I bet tons of vulnerabilities. You don't need so much code, and if you do - you're doing something egregiously wrong.

Re: US companies hit by 'colossal' cyber-attack

#298

Earlier quoted context omitted.

“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.” It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after th…

It's almost as if making shareholder returns and CEO pay the only indicator of company success creates terrible consequences.

Juice the returns at all costs for a few quarters and then walk away with riches from total ruins, you say?

Re: US companies hit by 'colossal' cyber-attack

#299
post #137

Earlier quoted context omitted.

> You have no clue how businesses work if you seriously think that an additional, unexpected $400 million in expenses (almost 50% of their yearly net profits) "isn't a huge impact to them". That's really all that has to be said here. You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building…

>You clearly have no clue how it looks inside the board rooms and executive offices of some of these huge companies. This type of stuff is treated the exact same way as if a 400m building burns down. I sit with CISOs daily discussing this stuff. $400m expenditures is enough to scare the shit out of them. A $400m building burning down would have CEOs fired (see: Equifax CEO being fired after breach). I don't know what…

> A $400m building burning down would have CEOs fired (see: Equifax CEO being fired after breach). I don't know what fantasy land you live in, but you're either delusional or lying.

In what world does getting 90m $ to leave the company constitute "getting fired"? That's early retirement.

> In a time period where every other company is seeing massively rising profits and stock prices, Equifax has been relatively stagnant.

So, it will take them 2 or 3 years longer to reach some arbitrary stock price. Certainly an earth shattering experience.

Re: US companies hit by 'colossal' cyber-attack

#300

One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...

Confirmed here: https://www.aftonbladet.se/minekonomi/a/86bQQw/coop-butiker-...
Post reply on HN