Live data from Hacker News

Cyber Security: A pre-war reality check

berthub.eu

131–140 of 286 posts

Re: Cyber Security: A pre-war reality check

#131
post #9

I cannot agree more with the author’s point of view. As an illustration, many people want to use GPS for the safe positioning of trains in the European Train Control Systems. This makes the space sector happy because it justifies the expenditures incurred for putting things like Galileo in orbit. However, in a pre-war check exercise, one immediately come to the conclusion that all European trains would crawl to a sto…

Railroads should absolutely use GPS. They also should supplement it with local transmitters, like aviation does.

They should have lots and lots of local transmitters.

Re: Cyber Security: A pre-war reality check

#132
post #109

Earlier quoted context omitted.

> FAA have spent a lot of time thinking about how to keep aviation secure in a GPS denied environment, which is their basis for the *build out* of the VOR MON That’s an interesting characterization, given that the MON is a list of VORs they are not planning to take down .

But that's better than taking them all down. Fact of the matter is most of us hate using VORs anyway, and left to our own devices probably wouldn't care one bit if they were removed. It is a good thing that someone is second-guessing that. Degrading to MON wouldn't be great, but it would be much preferrable to hoping poor ATC can figure out how to vector everyone all the sudden. I think more industries could apply th…

> Fact of the matter is most of us hate using VORs anyway

This is partly UX and doesn't have to be like this. Cockpit systems could make this a lot easier to select VORs and radials without having to manually keep track of frequencies.

After all a successful GPS fix is impossible to accomplish by a human given the raw receive data, which is why it's all automated inside the receiver. We can optimize the hell out of VORs as well. And only people flying ancient aircraft still have to do the thing.

In fact it probably would be great to add some optional authentication signal to it, as even a VOR can be prone to jamming or spoofing.

Re: Cyber Security: A pre-war reality check

#133
post #110

Earlier quoted context omitted.

> Unfortunately these are being used less and less and even deprecated Fortune may have something to do with it. Like copper land communications that cost billions to establish over almost 100 years, are extremely resilient and can be repaired by anyone with a ladder and pair of pliers. They're being ripped out across Europe and the US because the private companies they were sold to want to shrug maintenance to squee…

Copper land lines cost a fortune to maintain, and with everyone having moved to cellphones years ago, don't generate income to pay for their upkeep. People pay far more for an internet line that dumps out a gig of traffic, while very few pay for a hard line that is hard to cut and only carries a few kb of traffic.

> everyone having moved to cellphones years ago

That is untrue. The news is full of stories of people who are right now being forced-off hard line connections that they want and will pay for. The choice is being removed, which is not a fair market.

But, telling any group of people that "they are the only ones" is gas-lighting. Systematic lies to marginalise people was central to the Purdue Pharma opioid scandal and to the British Post Office scandal - telling people "You're the only one" when a problem is evidently extensive should be a very serious fraud.

> don't generate income to pay for their upkeep

When many private companies took on telecommunications properties they did so under obligations to maintenance of infrastructure, availability and reliability standards. If it turns out their choices of technology don't meet those standards of affordable resilience then that's their financial miscalculation and their problem now. Or are you saying that markets are incompatible with national security?

Re: Cyber Security: A pre-war reality check

#134

I agree with the overall thesis, but I do need to quibble about Stuxnet. Yes, Stuxnet was very interesting, and it did disrupt Irans nuclear program. However, its impact is often overblown. It likely delayed Irans nuclear program by only a few weeks. Cyber attacks can absolutely cause a lot of damage and harm, but Stuxnet is not the best example of that.

The reason I personally think Stuxnet is so interesting is because of it's reach. The goal was so specific and it accomplished it while infecting lord knows how many machines (but I bet Wikipedia knows).

Impact wasn't massive by any means, but the scope of the project will always impress me.

Re: Cyber Security: A pre-war reality check

#135

Earlier quoted context omitted.

> Change Healthcare has lost $872M since it was attacked in February. The question is, what is the cost to secure? I've been in so many meetings where the cost of security is 10-15x the cost of a breach. It's horrifying.

Part of this is that nobody has cared about security since the beginning, for basically anything in tech. It’s an industry-wide issue that permeates every level of the stack. And so yeah, individual companies trying to retrofit security onto a jenga tower of technology is going to have to spend a ridiculous amount of resources to have any kind of impact. I don’t know what the answer is, but I too believe things won’t…

> I don’t know what the answer is, but I too believe things won’t change until the day someone figures out how to push a “kill all humans” OTA update to all the self-driving cars on some random Tuesday afternoon.

Even in that case I’m pessimistic that any action will happen. People will go on TV and say grave things, hearings will be held. Fingers will be pointed. Task Forces will kick off. Reports will be written. Bureaucrats will have stern conversations with bureaucrats. Politicians will say: we must this and we shall that. IT companies will sell their “solutions”. But no actual action will happen. It will be all talk and commerce but no actual hands unplugging and plugging in cables. We have completely lost the societal will to actually do anything besides generate words and reports.

Re: Cyber Security: A pre-war reality check

#136
post #39

Earlier quoted context omitted.

>Well US is not dependent on anyone for her Energy needs. China's strength is they have the means of production (and maintenance) of everyone today, including the US. All the energy in the world means jack squat when all the means of using that energy rely on China. Could the west regain our own means of production? Certainly, but it's going to take far too long at the point China starts pursuing Bigger Gun Diplomacy…

China makes consumer crap not our guns and bombs. In a wartime situation maybe people can’t get iphone cases from temu, big whoop. Not the first time the american population rationed consumer products in wartime. We will still have power and air, sea, and space superiority which is what really matters.

Everyone has outsourced all their cheap and low-quality manufacturing to China, therefore China is only capable of manufacturing cheap, low quality items. Is this your argument?

Re: Cyber Security: A pre-war reality check

#137
post #128

Earlier quoted context omitted.

The back of my head is screaming "defense in depth! Redundant systems!" The whole idea of the internet (and even some of our infra, like suburbs or highways/rail) is that there's no one single point of failure. Like designed-to-survive-nuclear-war redundant. Definitely incorporate the most advanced tech you can for when things are going smoothly to get that efficency gain, but there's a reason all branches of the mil…

> The whole idea of the internet (and even some of our infra, like suburbs or highways/rail) is that there's no one single point of failure. Like designed-to-survive-nuclear-war redundant. Sure, the routing algorithms can quickly adapt to changes in network topology, but they assume infinite bandwidth, which hasn't been the case since a long time now. In other words, if a couple of important pipes disappear between t…

Definitely, we've seen this in fiber cuts before. That said a degraded availability is better than no availability.

I know it's controversial in the context of net neutrality but personally I'd be okay with traffic shaping/prioritization for critical infra in cases such as this. Keep the power plants, emergency services, military, government, transit running over intsagram and netflix when things come down to it.

Re: Cyber Security: A pre-war reality check

#138
post #47
post #41

Earlier quoted context omitted.

> US not having a policy of signing new people up to the anti-Russia military alliance every few years Weird how all of Russia's neighbors are eager to join a military alliance protecting them from Russia. I wonder if that has something to do with Russia's actions towards its neighbors? No, no, surely the US is to blame for that...

Yeah, sure. But the US chooses who it integrates with militarily. An alternative approach would have been to say "hey, yeah we can see why you'd want to join - but this will foment tensions with Russia, so you can't". That is the kind of diplomacy would have prevented Russia from invading its neighbours. It would have been difficult to get worse outcomes with that approach than what the powers that be managed to get…

> That is the kind of diplomacy would have prevented Russia from invading its neighbours.

Really? You believe the Russian claim that it attacks its neighbours because they're mumbling about NATO membership?

Russia attacks its neighbours because it regrets its loss of a "zone of influence" at the end of the Cold War. Like all former imperial powers (I'm a Brit!), loss of empire is hard to swallow.

Re: Cyber Security: A pre-war reality check

#139
post #47
post #41

Earlier quoted context omitted.

> US not having a policy of signing new people up to the anti-Russia military alliance every few years Weird how all of Russia's neighbors are eager to join a military alliance protecting them from Russia. I wonder if that has something to do with Russia's actions towards its neighbors? No, no, surely the US is to blame for that...

Yeah, sure. But the US chooses who it integrates with militarily. An alternative approach would have been to say "hey, yeah we can see why you'd want to join - but this will foment tensions with Russia, so you can't". That is the kind of diplomacy would have prevented Russia from invading its neighbours. It would have been difficult to get worse outcomes with that approach than what the powers that be managed to get…

> That is the kind of diplomacy would have prevented Russia from invading its neighbours.

Only if you subscribe to the argument that Russia has no intention to gobble up countries west of it at least to the furthest extent of USSR and its satellites.

No European neighbors of Russia subscribe to that anymore. Finland and Sweden were the last holdouts who thought that having a "responsible" diplomacy would prevent war with Russia, but the absurd and fabricated excuses Russia uses to justify the invasion of Ukraine have destroyed almost overnight all credibility of that line of thought.

Assuming imperialistic intentions, staying neutral and out of alliances only lowers the cost of invasion for Russia. If Russia decides to invade a country like Poland, then at the moment they risk a large multinational response that can go far-far beyond Poland's own means, up to a nuclear war. If Poland didn't have solid allies, the potential cost associated with the invasion would be considerably smaller for Russia.

Re: Cyber Security: A pre-war reality check

#140
post #113

This is one of my favorite reads on HN to date. I hope more people see it. It's funny how, even as a "nerd," I often think about if we are doing the wrong thing by taking the nerdy approach to problems that could be solved more simply. It feels like we often choose the most complex or nerdiest approach to prove to ourselves and others that we can and not whether we should - which isn't to say that we shouldn't ever -…

At least in my education, the Therac-25 incidents [0] featured pretty prominently as an example of software overconfidence.

https://en.m.wikipedia.org/wiki/Therac-25

Post reply on HN