Live data from Hacker News

U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

reuters.com

31–40 of 59 posts

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#31

What good can come from this? "We want to improve our cybersecurity - lets engage the biggest technology companies in the country." If we invite them all to a luncheon, their collective knowledge of "cyber" must lead to something good, right? Except all of these executives likely have limited understanding of cybersecurity at best. At worst, they or their team already thought up regulations to help crush early compan…

The year is 2026. Cyberattacks have escalated to the point that megabanks are offline for weeks at a time, power grids go dark for ransom, airliners are guided into deadly collisions, a database of every American's Social Security Number is leaked, and drinking water is sabotaged by remote criminals. The USA CYBERSAFE ACT is passed with overwhelming bipartisan support. It mandates trusted federal security co-processo…

The year is 2027. Power grids still go dark for ransom, but at least the internet has been turned back into TV. If you know how to use Linux, you might be able to pick up a fourth podcast!

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#32
post #6

Checklists are not the answer. Some kind of liability framework seems like the answer. And perhaps through such a lens we'll discover that some businesses simply shouldn't exist.

You see it with HIPAA. It's unclear whether the financial liability causes companies to invest in security and that work discourages hackers. Or, if hackers aren't as interested in customer data / healthcare records. Seems like the low hanging fruit is just to infiltrate a network and figure out how to get it to mine monero.

I think HIPAA is a good example, especially the somewhat infectious nature of business agreements. There are serious penalties with leaks, and the BAs leave everyone liable (and very, very cautious). I do think the teeth of the law make a lot of HIPAA leaks go unreported. I imagine the almost crippling financial and reputational impact gets weighed heavily against the cost of getting caught.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#33
Director of Engineering - Security from Coalition here (we participated in the event) - We committed to building more free security tools for all organisations to protect themselves. We’ve already made Coalition Control our Attack Surface discovery and monitoring platform free (https://control.coalitioninc.com) and we will continue to add more features and more tools for free there. If there are any questions,I am happy to answer them!

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#35

What good can come from this? "We want to improve our cybersecurity - lets engage the biggest technology companies in the country." If we invite them all to a luncheon, their collective knowledge of "cyber" must lead to something good, right? Except all of these executives likely have limited understanding of cybersecurity at best. At worst, they or their team already thought up regulations to help crush early compan…

The year is 2026. Cyberattacks have escalated to the point that megabanks are offline for weeks at a time, power grids go dark for ransom, airliners are guided into deadly collisions, a database of every American's Social Security Number is leaked, and drinking water is sabotaged by remote criminals. The USA CYBERSAFE ACT is passed with overwhelming bipartisan support. It mandates trusted federal security co-processo…

Sounds pretty bullish for decentralized systems

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#36
post #23
post #17

Earlier quoted context omitted.

What do you do in the case the actor is using a weak state as cover? Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?

> Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it? Work with law enforcement agencies in those countries to apprehend the person. If the country won't cooperate or shields the attackers, then sure, a drone strike could work.

Extra-judicial executions for unauthorized information access is not the right way to conduct yourself as a nation.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#37
post #17

Earlier quoted context omitted.

What do you do in the case the actor is using a weak state as cover? Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?

>* Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?* Here's the plan: invade Afganistan, and eventually find the guy years later in a compound in Pakistan.

And then multiply that by all the organized crime hackers out there... lots of bogged down slogs... so maybe let's find ourselves another way.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#38

One area the US government could really make a difference in cyber security is making identify theft more difficult. Currently all you have to do to defraud banks is get your hands on some government issued numbers (social security numbers and driver licenses). If the government created an identify system that was no so easy to impersonate, some types of hacking and data leaks would not longer cause problems to the p…

I'd be a lot more interested in an id system that was controlled by the individual rights holder: a verified system granting or revoking access to their data. Individuals have far more incentive to protect their data than state apparatus.

login.gov would be great for this, with the obvious caveat being that it ties a persistent user identifier to sites you login with.

Maybe there could be two login flows - one that generates a unique pseudo-identity for each service, and another that actually beams over your PII for identity verification purposes.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#39
post #33

Director of Engineering - Security from Coalition here (we participated in the event) - We committed to building more free security tools for all organisations to protect themselves. We’ve already made Coalition Control our Attack Surface discovery and monitoring platform free ( https://control.coalitioninc.com ) and we will continue to add more features and more tools for free there. If there are any questions,I am…

What kind of create standards could you create?

Some thoughts:

1) Certain infrastructure should be off the net automatically - pipelines, water treatment plants and similar things (or online with hardware guaranteed one ways connections).

2) Standards for testing backups.

3) Standards for IoS devices (a million insecure Internet light bulbs, what could possibly go wrong).

4) Standards for not having a hundred companies auto-updating onto the systems of critical infrastructure companies.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#40

What good can come from this? "We want to improve our cybersecurity - lets engage the biggest technology companies in the country." If we invite them all to a luncheon, their collective knowledge of "cyber" must lead to something good, right? Except all of these executives likely have limited understanding of cybersecurity at best. At worst, they or their team already thought up regulations to help crush early compan…

The year is 2026. Cyberattacks have escalated to the point that megabanks are offline for weeks at a time, power grids go dark for ransom, airliners are guided into deadly collisions, a database of every American's Social Security Number is leaked, and drinking water is sabotaged by remote criminals. The USA CYBERSAFE ACT is passed with overwhelming bipartisan support. It mandates trusted federal security co-processo…

> megabanks are offline for weeks at a time

Yeah not going to happen. Might happen to government, but not banks.

Banks are incentivized by profit, and being offline pose extreme risk to profit. Government are just mostly self promoting bureaucracy until something goes really wrong, and then it's still the same bureaucracy.

Post reply on HN