Live data from Hacker News

Cyber Security: A pre-war reality check

berthub.eu

191–200 of 286 posts

Re: Cyber Security: A pre-war reality check

#191
post #47

Earlier quoted context omitted.

Yeah, sure. But the US chooses who it integrates with militarily. An alternative approach would have been to say "hey, yeah we can see why you'd want to join - but this will foment tensions with Russia, so you can't". That is the kind of diplomacy would have prevented Russia from invading its neighbours. It would have been difficult to get worse outcomes with that approach than what the powers that be managed to get…

The only thing that would have changed is that Russia now also could invade the baltic states. Why do you think Russia would not have invaded Ukraine if the NATO had not been expanded?

Under what circumstances would Russia feel a need to invade Ukraine if they didn't fear NATO involvement? It is pretty clear in the current war that exactly what the Russian leadership feared was happening - a pushover country on their border was being militarised by the US. In hindsight they must feel naive for not being more paranoid and bulking up their military before going in. The NATO enlargement is a broad strategy of threatening Russia and building up force to use against them. And the political rhetoric out of the US on Russia has been unhinged since at least 2016. The Russians would be stupid not to be scared and this invasion of Ukraine looks like a desperation play through that lens.

Ukraine is a great example of what US support does - if the US had told them that they're on their own, Ukraine would have just gone with whatever Russia wanted diplomatically.

Instead, a lot of Ukrainian's are dead, they've lost a double-digit percentage of their country, the west is hell-bent on destabilising the leadership that controls the world's largest nuclear arsenal, it looks like we're escalating into a WWIII style situation because the US deterrence is failing and Ukraine is STILL likely to end up having to do what Russia wants. Technically not maybe because they've lost the territory that Russia was most interested in.

The US shouldn't be involved in militarily organising Eastern Europe. It has not helped, it seems to be making war a certainty.

Re: Cyber Security: A pre-war reality check

#192

Earlier quoted context omitted.

Not sure I entirely agree? #1 > Or disable a hospital. The entire Ascension Healthcare system of hospitals (142 hospitals, 2600 total facilities) in on divert since 8 May because they had to switch back to paper records. Change Healthcare has lost $872M since it was attacked in February. Maybe it's more like the pandemic: seems like nothing, unless it affects you . https://en.wikipedia.org/wiki/Ascension_(healthcare_…

> Change Healthcare has lost $872M since it was attacked in February. The question is, what is the cost to secure? I've been in so many meetings where the cost of security is 10-15x the cost of a breach. It's horrifying.

Sounds like the government needs to make breaches more expensive so incentives align correctly.

Re: Cyber Security: A pre-war reality check

#193

Earlier quoted context omitted.

> As an SWE I do agree somewhat with what you say but this story is not complete. If you look at the attacks on Ukraine and the cybersecurity damage done it was fairly small in the grand scheme of things. It's worth mentioning that the most expensive and extensive malware attack in history was caused by one of such Russian cyberattacks hitting systems which (at the time) they weren't intended to. Causing severe shipp…

Why don't we see these attacks though? I know they're worryingly practical and the West certainly has enough enemies (especially from extremist groups who don't have the same peace keeping concerns as a nation state), and yet we don't see groups just sabotaging critical infrastructure and businesses left and right. Is it really just difficulty/a lack of skill?

A reasonable guess is that some entities are storing / collecting attacks patiently waiting for one big event. Having smaller constant incidents only helps strengthen the opponent over time, thus making it harder to deploy a coordinated attack that can change history. The dutch narrative in the article is a good example of what happens whem nontechnical people make decisions over long periods of time without major incidents.

Re: Cyber Security: A pre-war reality check

#194

Earlier quoted context omitted.

Definitely, we've seen this in fiber cuts before. That said a degraded availability is better than no availability. I know it's controversial in the context of net neutrality but personally I'd be okay with traffic shaping/prioritization for critical infra in cases such as this. Keep the power plants, emergency services, military, government, transit running over intsagram and netflix when things come down to it.

Does the government not maintain its own dedicated communication infrastructure between important installations? Or has it all been replaced with public connections?

"It depends." Two data points that I know of first hand:

1) There is a dedicated microwave link between Vandenberg Space Force Base and Edwards Air Force Base. Mil. owned and operated solely for their own use.

2) The US Federal government decided to build a standardized communications network for government/first responders/etc. This is FirstNet. They farmed the build-out to AT&T and gave them 20 MHz of bandwidth (Band 14) but it runs over their standard wireless infrastructure and network but FirstNet traffic gets prioritized.

https://www.firstnet.gov/

https://www.firstnet.com/

https://en.m.wikipedia.org/wiki/First_Responder_Network_Auth...

Re: Cyber Security: A pre-war reality check

#195
post #164
post #21

Earlier quoted context omitted.

Well US is not dependent on anyone for her Energy needs. Unlike China. Its quite vulnerable on that front if a few pipelines blow up ala nord stream. This is also why the US has such a large presence in the middle east.

The Chinese are building solar farms and wind farms at an incredibly fast pace. Have you seen how cheap Chinese solar panels are? It's safe to assume by the time they decide to make a military move on Taiwan, they will have achieved energy independence as well.

Its more that the army, navy airforce world over all are heavy oil guzzlers. Its not going to simple if its a long war.

Re: Cyber Security: A pre-war reality check

#196

Earlier quoted context omitted.

The back of my head is screaming "defense in depth! Redundant systems!" The whole idea of the internet (and even some of our infra, like suburbs or highways/rail) is that there's no one single point of failure. Like designed-to-survive-nuclear-war redundant. Definitely incorporate the most advanced tech you can for when things are going smoothly to get that efficency gain, but there's a reason all branches of the mil…

>The whole idea of the internet (and even some of our infra, like suburbs or highways/rail) is that there's no one single point of failure. Like designed-to-survive-nuclear-war redundant. The reality of course is that the internet has turned into a fragile, centralized system of complication that rests on single failure points like Cloudflare, AWS, and Chrome. The internet as envisioned by DARPA would have survived t…

Yeah it’s pretty bad nowadays.

Thinking about this though it’s really the big tech companies manufacturing “the latest thing” to be tossed in the bin after a year. Dollars over longevity. Then they become “no longer maintained.” Could we STILL use a 3g network? Or is there a simpler, slow network that should be good enough barring our pointless desire for cat videos?

And some folks wonder why companies still use floppy disks on air-gapped infrastructure. Because it fucking works don’t litter it with complexity to modernize.

Now… the situation with skills to manage infrastructure? Now that the whole AI thing is happening? The internet is going to be fucked people. It’s time to go analog.

Re: Cyber Security: A pre-war reality check

#197
Over a decade ago I wrote an article that included the prediction that the vulnerability of western infrastructure to cyber operations would prevent the US from intervening to support lesser allies. The rationale was the domestic costs of chaos caused by infrastructure attacks would cause hesitation to intervene in foreign wars, and this hesitation and vulnerability would embolden foreign antagonists like Russia and China to invade smaller countries.

So far, it has been wrong. Even though there have been several infrastructure incidents in recent memory that looked like Russian deterrent operations that said, "back off or this is just what we're willing to reveal," but the US still seems fully invested in the conflict in Ukraine, and it appears to be providing cover for Israel against Iran- each with no real concern about both adversaries being able to launch a US power grid shutdown. China has been bold about Taiwan, but even they have been content to just manage it instead of full political annexation, and appear to take US support for Taiwan seriously, all while China could plausibly shut off anything in the US with a semiconductor in it.

Maybe the new world order is that nation states don't need to expand sovereign territory so long as they can effectively manage the ones they need. With the exception of missile placements, why invade the cow when you can secure the milk without the headache of governing it- and this puts cyber into a more fluid dynamic than the assumptions of pre-space and network technology geopolitics.

Re: Cyber Security: A pre-war reality check

#198
post #40

>Why did it happen? Non-technical people have made choices and have optimized for stuff being cheap. Yes and amplified by: + Cybersecurity 'bad actors' are decentralized and distributed. They innovate at speed, with no barriers, and share their innovation. Cybersecurity 'good actors' are centralized, proprietary and bounded. + Software and service providers traditionally couldn't build secure networking into their pr…

> Cybersecurity 'good actors' are centralized, proprietary and bounded.

IME the main problem is that, with rare exceptions, building secure products is seen as a distraction that is best pawned off to the cybersecurity team. And that cybersecurity team is more often than not fairly light on actual product development engineering talent. So they do what they can, which is mostly buy yet another tool from the thousands of vendors hawking The Answer, the final service you need to buy and then you'll be secure.

Which to anyone who has built secure products, should obviously sound like nonsense. Because it is nonsense. Most of these tools are mildly useful (some useless) but not that great. They're certainly not The Answer.

To build secure products you need to actually make it a tier one requirement and design it in from day one. It's as simple, and as difficult, as that.

Re: Cyber Security: A pre-war reality check

#199

Earlier quoted context omitted.

> Change Healthcare has lost $872M since it was attacked in February. The question is, what is the cost to secure? I've been in so many meetings where the cost of security is 10-15x the cost of a breach. It's horrifying.

One reason, is probably because retrofitting security is a freaking nightmare . In my opinion, security (as well as Quality, and things like error handling, accessibility, and localization) is something that needs to be planned and implemented, from Day One. Do a better job from the start, and the cost will drop like a stone.

Nobody implements security from day 1 because it's not some one time cost. It is an ongoing, continuous cost you pay for the system to exist.

People build walled garden security models because security imposes a pretty large operational cost on everything else.

Re: Cyber Security: A pre-war reality check

#200
post #9

I cannot agree more with the author’s point of view. As an illustration, many people want to use GPS for the safe positioning of trains in the European Train Control Systems. This makes the space sector happy because it justifies the expenditures incurred for putting things like Galileo in orbit. However, in a pre-war check exercise, one immediately come to the conclusion that all European trains would crawl to a sto…

Railroads... Railroads can now outsource train control. Wabtec's "Wabtec Cloud Positive Train Control Communication Solution" - "A complete turnkey hosted office solution for I-ETMS-based Positive Train Control (PTC) systems"[1] (Wabtec used to be Westinghouse Air Brake.) Wabtec has had break-ins, but claims they only involved employee info, not control systems.[2] [1] https://www.wabteccorp.com/digital-intelligence/…

Lol is this basically a train SaaS solution? Whats wild to me is that SaaS products aren’t actually required to issue CVEs since customers aren’t the ones responsible for patching.
Post reply on HN