Earlier quoted context omitted.
Can we partially blame IBM? Every municpality I've worked for runs a majority of their systems on the IBM System i (iSeries, AS/400) IBM is very slow to update any of the tools for Windows that are included with these systems. Ditch the green screens, use the IBM EasyAccess or whatever they call it on Windows, you just saved some $. Now, there are database tools and admin utilities that are also included in this. Mos…
We can partially blame every software vendor that’s ever existed. In 10 years we will be blaming Google for applications that only run on outdated versions of Chrome because the API the developer used only existed in Chrome and wasn’t accepted into the standard and then was removed a few years later. Everyone does it and everyone will do it.
U.S. Cities Strain to Fight Hackers
111–119 of 119 posts
Re: U.S. Cities Strain to Fight Hackers
#112I'm surprised no one has mentioned it here on hacker news. But when CFAA makes all hacking criminal, the only hackers left are criminals. Ethically motivated hackers should have the same protections as whistle blowers - The day that happens, the world becomes more safe and transparent. But transparency is not what everyone wants, obviously. I wish I was more surprised that mainstream media fails to mention this impor…
Re: U.S. Cities Strain to Fight Hackers
#113Earlier quoted context omitted.
I spent years as a infosec consultant specialized in major healthcare companies, and my experience is completely the opposite. It is absurdly easy to be 'compliant' with the HIPAA security rule yet still have abysmal security. The biggest issue IMO with the HIPAA SR is that it is first and foremost a legal matter that involves legal teams, and is not very good at being a technology matter that effectively prescribes…
There will always be some organizations that do the minimum necessary to check some sort of "compliance" checkbox. However you can't deny that overall the healthcare industry as a whole has better security and security controls than they would if HIPAA had never been enacted.
The companies that were actually good at security merely used HIPAA as a starting point, and sometimes had to divert resources away from actual security efforts just to meet redundant HIPAA audits. They would just as easily get by with any of the other myriad of security frameworks out there.
The companies that were bad at security either: 1) mostly ignored HIPAA because in many cases it's easier to just buy insurance to cover the cost of a breach, 2) viewed HIPAA as a legal matter and got lawyers involved, who many times actively impeded security infrastructure efforts (fines are less for a HIPAA breach if you "weren't aware" you were doing anything wrong, which leads to companies intentionally avoiding security assessments or altering them to read "everything is fine!" even when they know it's not), or 3) viewed HIPAA as a checklist and once they achieve HIPAA compliance, they think their security is good enough and stop investing in it (hint: achieving HIPAA compliance does not mean you have good security. not even close).
I certainly do contend that HIPAA has not benefited the security of the healthcare industry as a whole. IME, it may have very well hurt it.
* - I'm speaking specifically of the HIPAA security rule and it's effect on organizations' security maturity. In other areas, like patient privacy and disclosure rules, it does seem to have had an effect closer to what is intended.
Re: U.S. Cities Strain to Fight Hackers
#114Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…
Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…
Re: U.S. Cities Strain to Fight Hackers
#115I'm surprised no one has mentioned it here on hacker news. But when CFAA makes all hacking criminal, the only hackers left are criminals. Ethically motivated hackers should have the same protections as whistle blowers - The day that happens, the world becomes more safe and transparent. But transparency is not what everyone wants, obviously. I wish I was more surprised that mainstream media fails to mention this impor…
In the process of using a town's court website to try to pay a parking ticket, I practically-accidentally found a security vulnerability in it. The vulnerability immediately showed me many people's personal information. I closed the page when I realized what had happened. I didn't report the issue because I was worried that the people running a small town's buggy court website might be more interested in figuring out…
35 years of jail time has a powerful chilling effect.
How this article could talk about the 'surprising' lack of ethical hackers without covering this law and it's abuse is beyond me.
It's like talking about the 'surprising lack of research into clinical MDMA studies' and not talk about the war on drugs. It's like they are intentionally ignoring the HUGE elephant in the room.
Re: U.S. Cities Strain to Fight Hackers
#116Earlier quoted context omitted.
There will always be some organizations that do the minimum necessary to check some sort of "compliance" checkbox. However you can't deny that overall the healthcare industry as a whole has better security and security controls than they would if HIPAA had never been enacted.
I absolutely do deny that. Of the many healthcare companies I worked at, small 50-200 people shops and massive F500 companies and everything in between, I don't think HIPAA* made any kind of material difference in their security maturity. The companies that were actually good at security merely used HIPAA as a starting point, and sometimes had to divert resources away from actual security efforts just to meet redunda…
When all is said and done it's really the organization. I don't know how many bigcorps I've been at that were just totally inept. The existence or not of HIPAA would not change their ineptness.
Re: U.S. Cities Strain to Fight Hackers
#117Re: U.S. Cities Strain to Fight Hackers
#118Could someone suggest recognized and useful certifications, for those interesting getting into cybersecurity? The article has a link to another mentioning CompTIA and CISSP, are they any good?
Study to learn skills, not to get certs.
A lot of resources seems to be more like games than something applicable to the real world.
Re: U.S. Cities Strain to Fight Hackers
#119There is a big industry starting to spring up around this, data insurance. Go to any big insurance conference and all they are talking about right now is cyber insurance. Construction companies are asking for it for example; they've always had to insure their employees, but now they are seeing things like their offices being hit by cryptolockers and being extorted for bitcoin by Russians. They can't afford to lose pr…
[1] https://www.lawfareblog.com/moment-truth-cyber-insurance