Live data from Hacker News

U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

reuters.com

21–30 of 59 posts

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#21
What good can come from this? "We want to improve our cybersecurity - lets engage the biggest technology companies in the country." If we invite them all to a luncheon, their collective knowledge of "cyber" must lead to something good, right? Except all of these executives likely have limited understanding of cybersecurity at best. At worst, they or their team already thought up regulations to help crush early companies, and this is an opportunity to get them through.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#22
post #6

Checklists are not the answer. Some kind of liability framework seems like the answer. And perhaps through such a lens we'll discover that some businesses simply shouldn't exist.

Agreed. My last few experiences with 'security officers' were that they knew how to read off a checklist, and check said checklist.

None of the three had any clue if what we were saying was even true. Or what it would mean if it weren't.

To make myself more clear: checklists might be ok, if the checker can scour the code and prove such things. I've never met one that does or even seems to have the ability to.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#23
post #17

We're getting closer and closer to cyber and kinetic warfare intermingling regularly. Attacking a US company may become akin to attacking a US citizen. State backed or State sanctioned actors will be looked at as an agent of the state itself. Hacks will lead to proportional responses from governments against governments. It's not much different than our military and contractors protecting domestic oil company interes…

What do you do in the case the actor is using a weak state as cover? Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?

> Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?

Work with law enforcement agencies in those countries to apprehend the person. If the country won't cooperate or shields the attackers, then sure, a drone strike could work.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#25

A huge joke. If you have ever had to work with the DoD you may have had to deal with CMMC. It's totally ridiculous. At least it will boost the economy by adding thousands of security officer jobs and pad the pockets of any security vendor, and drive system administrators nuts by having to deal with shit like Microsoft Azure GCC High

Or the wonderful world of FIPS and Common Criteria.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#26
post #17

We're getting closer and closer to cyber and kinetic warfare intermingling regularly. Attacking a US company may become akin to attacking a US citizen. State backed or State sanctioned actors will be looked at as an agent of the state itself. Hacks will lead to proportional responses from governments against governments. It's not much different than our military and contractors protecting domestic oil company interes…

What do you do in the case the actor is using a weak state as cover? Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?

>* Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?*

Here's the plan: invade Afganistan, and eventually find the guy years later in a compound in Pakistan.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#27
post #6

Checklists are not the answer. Some kind of liability framework seems like the answer. And perhaps through such a lens we'll discover that some businesses simply shouldn't exist.

The only way to have liability is ... show people didn't follow a checklist. The main way to show a restaurant is liable for getting people sick is to show they didn't follow the health code, the main way to show a company is liable for fire is to show they violated various codes, etc.

Well, yes and no. You can have liability on inputs or liability on outputs. For restaurants, liability on outputs would mean a restaurant being liable for any food poisoning that occurs within X hours of eating there. But, human health has many confounding factors, so the inputs are easier to measure and to impose liability on.

For computer security, I'd want to see liability on results, and not just on the methods and the checklists. If a company has a data breach, then that's something for which they can be held liable. That might mean that it becomes much more expensive to maintain large databases on users, which would be a good change.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#30

What good can come from this? "We want to improve our cybersecurity - lets engage the biggest technology companies in the country." If we invite them all to a luncheon, their collective knowledge of "cyber" must lead to something good, right? Except all of these executives likely have limited understanding of cybersecurity at best. At worst, they or their team already thought up regulations to help crush early compan…

The year is 2026. Cyberattacks have escalated to the point that megabanks are offline for weeks at a time, power grids go dark for ransom, airliners are guided into deadly collisions, a database of every American's Social Security Number is leaked, and drinking water is sabotaged by remote criminals. The USA CYBERSAFE ACT is passed with overwhelming bipartisan support. It mandates trusted federal security co-processors in every computer, key escrow, a national firewall at every ISP, an end to crime enabling online anonymity, and a chain of custody for all actions done on a computer: logs must be retained by a licensed business IT department or manufacturer of a consumer device for two years. Root access is a felony.
Post reply on HN