Live data from Hacker News

U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

reuters.com

51–59 of 59 posts

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#51
post #50
post #9

Earlier quoted context omitted.

Given the push to have vaccination passports and people not pushing back hard on that aspect of privacy, probably pushing through a digital national ID might be as ripe as it’s ever going to be.

I think a regular national ID was attempted under the Obama administration but failed due to pushback, if I'm remembering correctly. The closest we got was Real ID, passed in 2005, which is barely being implemented fully now, over 15 years later. It makes me wonder how long it would take a true national ID system with digital verification, maybe something similar to Estonia's, to take to actually implement. It would…

> I think a regular national ID was attempted under the Obama administration but failed due to pushback, if I'm remembering correctly.

Not really. There was some discussion of it during the period of the Bush Administration which turned into Real ID (2005 was well before Obama was elected), but it's a stretch to call even that, much less any murmurings during the Obama Administration, an “attempt”.

> It makes me wonder how long it would take a true national ID system with digital verification

If you mean a mandatory one, mandatory ID faces Constitutional issues that are central to the US conception of liberty, so probably a collapse of the Constitutional order.

If you mean available standardized digital ID with digital verification, well, TSA had an RFI that closed in June preparatory to a rulemaking on adding digital ID, including digital verification, standards into the Real ID standards, because a number of states have digital ID efforts and there is a demand for them to qualify as Real IDs, because of the uses for which Real IDs already are (and the more that thet will be in the next couple years) mandated for l.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#52

Earlier quoted context omitted.

The year is 2026. Cyberattacks have escalated to the point that megabanks are offline for weeks at a time, power grids go dark for ransom, airliners are guided into deadly collisions, a database of every American's Social Security Number is leaked, and drinking water is sabotaged by remote criminals. The USA CYBERSAFE ACT is passed with overwhelming bipartisan support. It mandates trusted federal security co-processo…

> megabanks are offline for weeks at a time Yeah not going to happen. Might happen to government, but not banks. Banks are incentivized by profit, and being offline pose extreme risk to profit. Government are just mostly self promoting bureaucracy until something goes really wrong, and then it's still the same bureaucracy.

Banks are also incentivized by costs, both real and perceived. security is a perceived cost, easy to discount until it happens. This is why ATMs run very old operating systems, for example.

Capitalism isn't magic pixie dust that makes everything good.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#53
post #36
post #23

Earlier quoted context omitted.

> Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it? Work with law enforcement agencies in those countries to apprehend the person. If the country won't cooperate or shields the attackers, then sure, a drone strike could work.

Extra-judicial executions for unauthorized information access is not the right way to conduct yourself as a nation.

Hard disagree. First, you downplay "unauthorized information access". Foreign adversaries have targeted our industrial SCADA systems, which can lead to death and destruction.

Second, there's no moral absolutes that dictate how a nation should act. I value the lives and information of my family and friends more than I value the lives of someone attacking them. Don't like it, don't attack... :shrug:

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#54
post #53
post #36

Earlier quoted context omitted.

Extra-judicial executions for unauthorized information access is not the right way to conduct yourself as a nation.

Hard disagree. First, you downplay "unauthorized information access". Foreign adversaries have targeted our industrial SCADA systems, which can lead to death and destruction. Second, there's no moral absolutes that dictate how a nation should act. I value the lives and information of my family and friends more than I value the lives of someone attacking them. Don't like it, don't attack... :shrug:

Yeah, let's drone strike Edward Snowden because you have a small dick. Fucking moron.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#55
post #54
post #53

Earlier quoted context omitted.

Hard disagree. First, you downplay "unauthorized information access". Foreign adversaries have targeted our industrial SCADA systems, which can lead to death and destruction. Second, there's no moral absolutes that dictate how a nation should act. I value the lives and information of my family and friends more than I value the lives of someone attacking them. Don't like it, don't attack... :shrug:

Yeah, let's drone strike Edward Snowden because you have a small dick. Fucking moron.

It's kinda funny that when talking about foreign adversaries attacking the United States, you went to Edward Snowden.

You said it, not me.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#56
post #55
post #54

Earlier quoted context omitted.

Yeah, let's drone strike Edward Snowden because you have a small dick. Fucking moron.

It's kinda funny that when talking about foreign adversaries attacking the United States, you went to Edward Snowden. You said it, not me.

Now that the American empire is going to shit, how are you going to get your dick hard without being able to murder people just because you feel like it?

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#57

Earlier quoted context omitted.

The only way to have liability is ... show people didn't follow a checklist. The main way to show a restaurant is liable for getting people sick is to show they didn't follow the health code, the main way to show a company is liable for fire is to show they violated various codes, etc.

Well, yes and no. You can have liability on inputs or liability on outputs. For restaurants, liability on outputs would mean a restaurant being liable for any food poisoning that occurs within X hours of eating there. But, human health has many confounding factors, so the inputs are easier to measure and to impose liability on. For computer security, I'd want to see liability on results, and not just on the methods a…

For restaurants, liability on outputs would mean a restaurant being liable for any food poisoning that occurs within X hours of eating there.

You kind of run up against that old English Common Law principle that a defendant is innocent until proven guilty with that idea.

In simple situations, outcomes can work. If you intentionally cause someone to die, you're guilty of murder no matter how you manage to do that (but a chain of causation still needs to be proven, a rough correlation is patently arbitrary and unjust). But complex situations where causation is complicated require standards - proving someone intentionally killed someone in traffic would be hard if there were no traffic laws.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#58
post #56
post #55

Earlier quoted context omitted.

It's kinda funny that when talking about foreign adversaries attacking the United States, you went to Edward Snowden. You said it, not me.

Now that the American empire is going to shit, how are you going to get your dick hard without being able to murder people just because you feel like it?

> how are you going to get your dick hard without being able to murder people just because you feel like it

What's your obsession with my penis? This is your second comment about it. I ignored it the first time, so you try harder the second time? You're a creepy dude.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#59

A huge joke. If you have ever had to work with the DoD you may have had to deal with CMMC. It's totally ridiculous. At least it will boost the economy by adding thousands of security officer jobs and pad the pockets of any security vendor, and drive system administrators nuts by having to deal with shit like Microsoft Azure GCC High

CMMC is a framework that wasn't really there before. Sure it has bad points but, it at least moves things forward in the right direction and makes things more visible. The problem I've encountered with it is that PHBs want things hidden or "creatively mitigated" to pass inspection. Security would be much better if an independent 3rd party were used to audit all RMF/CMMC packages. That is usually not the case.
Post reply on HN