Live data from Hacker News

U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

reuters.com

11–20 of 59 posts

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#11
post #6

Checklists are not the answer. Some kind of liability framework seems like the answer. And perhaps through such a lens we'll discover that some businesses simply shouldn't exist.

Standardization is how most other industries address safety. It's not ideal in many ways, but it's better than the nothing we live with today.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#12
post #6

Checklists are not the answer. Some kind of liability framework seems like the answer. And perhaps through such a lens we'll discover that some businesses simply shouldn't exist.

You see it with HIPAA. It's unclear whether the financial liability causes companies to invest in security and that work discourages hackers. Or, if hackers aren't as interested in customer data / healthcare records. Seems like the low hanging fruit is just to infiltrate a network and figure out how to get it to mine monero.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#13

One area the US government could really make a difference in cyber security is making identify theft more difficult. Currently all you have to do to defraud banks is get your hands on some government issued numbers (social security numbers and driver licenses). If the government created an identify system that was no so easy to impersonate, some types of hacking and data leaks would not longer cause problems to the p…

Even more fundamental than national ID or PKI is incentives. If the burden of proof is clearly on the creditor, they will very quickly tighten up their anti-fraud measures. The current equilibrium of creditors being able to burden random people with the cost of proving they're not responsible for fraudulent loans is Kafkaesque.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#14
A huge joke. If you have ever had to work with the DoD you may have had to deal with CMMC.

It's totally ridiculous. At least it will boost the economy by adding thousands of security officer jobs and pad the pockets of any security vendor, and drive system administrators nuts by having to deal with shit like Microsoft Azure GCC High

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#15
We're getting closer and closer to cyber and kinetic warfare intermingling regularly. Attacking a US company may become akin to attacking a US citizen. State backed or State sanctioned actors will be looked at as an agent of the state itself. Hacks will lead to proportional responses from governments against governments.

It's not much different than our military and contractors protecting domestic oil company interests abroad.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#16

One area the US government could really make a difference in cyber security is making identify theft more difficult. Currently all you have to do to defraud banks is get your hands on some government issued numbers (social security numbers and driver licenses). If the government created an identify system that was no so easy to impersonate, some types of hacking and data leaks would not longer cause problems to the p…

Even more fundamental than national ID or PKI is incentives. If the burden of proof is clearly on the creditor, they will very quickly tighten up their anti-fraud measures. The current equilibrium of creditors being able to burden random people with the cost of proving they're not responsible for fraudulent loans is Kafkaesque.

For many years retail stores didn't care about stolen credit card information being used to buy gift cards. The banking sector ate those fraud losses. Once the payment card oligopoly shifted the liability onto merchants, retailers had to eat way more fraud. Retailers immediately took down gift card displays, rushed to upgrade to chip terminals, and when they put the displays back they stopped selling $500 cards.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#17

We're getting closer and closer to cyber and kinetic warfare intermingling regularly. Attacking a US company may become akin to attacking a US citizen. State backed or State sanctioned actors will be looked at as an agent of the state itself. Hacks will lead to proportional responses from governments against governments. It's not much different than our military and contractors protecting domestic oil company interes…

What do you do in the case the actor is using a weak state as cover? Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#18
post #6

Checklists are not the answer. Some kind of liability framework seems like the answer. And perhaps through such a lens we'll discover that some businesses simply shouldn't exist.

The only way to have liability is ... show people didn't follow a checklist. The main way to show a restaurant is liable for getting people sick is to show they didn't follow the health code, the main way to show a company is liable for fire is to show they violated various codes, etc.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#19

One area the US government could really make a difference in cyber security is making identify theft more difficult. Currently all you have to do to defraud banks is get your hands on some government issued numbers (social security numbers and driver licenses). If the government created an identify system that was no so easy to impersonate, some types of hacking and data leaks would not longer cause problems to the p…

I'd be a lot more interested in an id system that was controlled by the individual rights holder: a verified system granting or revoking access to their data. Individuals have far more incentive to protect their data than state apparatus.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#20
> ...as President Joe Biden appealed to private sector executives to "raise the bar on cybersecurity."

So a new banner has been hoisted, under which some lobbyist interests will be serviced, and if this results in any security improvements - it will be a happy accident. Here, I'll fix the problem for you Biden - here is what you say: "Today I've been directed to announce that... I've directed the Department of Justice to investigate the negligent actions of companies that have contributed to the growing trend of identity theft and associated crimes." Boom, problem solved. This solution is well known, and has been for as long as I can remember. If somebody fills their orphanage-for-the-blind adjacent warehouse full of TNT, and a chain smoking burglar breaks in... the warehouse owner isn't the victim.

Post reply on HN