Live data from Hacker News

U.S. Cities Strain to Fight Hackers

wsj.com

111–119 of 119 posts

Re: U.S. Cities Strain to Fight Hackers

#111

Earlier quoted context omitted.

Can we partially blame IBM? Every municpality I've worked for runs a majority of their systems on the IBM System i (iSeries, AS/400) IBM is very slow to update any of the tools for Windows that are included with these systems. Ditch the green screens, use the IBM EasyAccess or whatever they call it on Windows, you just saved some $. Now, there are database tools and admin utilities that are also included in this. Mos…

We can partially blame every software vendor that’s ever existed. In 10 years we will be blaming Google for applications that only run on outdated versions of Chrome because the API the developer used only existed in Chrome and wasn’t accepted into the standard and then was removed a few years later. Everyone does it and everyone will do it.

I don't think much of anyone makes stuff for old Chrome versions given how aggressive Chrome is about auto-updating. Chrome doesn't have any official options to disable auto-updating as far as I know.

Re: U.S. Cities Strain to Fight Hackers

#112

I'm surprised no one has mentioned it here on hacker news. But when CFAA makes all hacking criminal, the only hackers left are criminals. Ethically motivated hackers should have the same protections as whistle blowers - The day that happens, the world becomes more safe and transparent. But transparency is not what everyone wants, obviously. I wish I was more surprised that mainstream media fails to mention this impor…

In the process of using a town's court website to try to pay a parking ticket, I practically-accidentally found a security vulnerability in it. The vulnerability immediately showed me many people's personal information. I closed the page when I realized what had happened. I didn't report the issue because I was worried that the people running a small town's buggy court website might be more interested in figuring out what laws I broke than understanding the issue. I'd rather have nothing to do with it. It's the only time I haven't reported a security vulnerability I've found. I'm probably over-thinking it, but when there's other groups that invite vulnerability reports and even give bug bounties, it just feels like an unnecessary risk reaching out to ones that don't.

Re: U.S. Cities Strain to Fight Hackers

#113
post #94

Earlier quoted context omitted.

I spent years as a infosec consultant specialized in major healthcare companies, and my experience is completely the opposite. It is absurdly easy to be 'compliant' with the HIPAA security rule yet still have abysmal security. The biggest issue IMO with the HIPAA SR is that it is first and foremost a legal matter that involves legal teams, and is not very good at being a technology matter that effectively prescribes…

There will always be some organizations that do the minimum necessary to check some sort of "compliance" checkbox. However you can't deny that overall the healthcare industry as a whole has better security and security controls than they would if HIPAA had never been enacted.

I absolutely do deny that. Of the many healthcare companies I worked at, small 50-200 people shops and massive F500 companies and everything in between, I don't think HIPAA* made any kind of material difference in their security maturity.

The companies that were actually good at security merely used HIPAA as a starting point, and sometimes had to divert resources away from actual security efforts just to meet redundant HIPAA audits. They would just as easily get by with any of the other myriad of security frameworks out there.

The companies that were bad at security either: 1) mostly ignored HIPAA because in many cases it's easier to just buy insurance to cover the cost of a breach, 2) viewed HIPAA as a legal matter and got lawyers involved, who many times actively impeded security infrastructure efforts (fines are less for a HIPAA breach if you "weren't aware" you were doing anything wrong, which leads to companies intentionally avoiding security assessments or altering them to read "everything is fine!" even when they know it's not), or 3) viewed HIPAA as a checklist and once they achieve HIPAA compliance, they think their security is good enough and stop investing in it (hint: achieving HIPAA compliance does not mean you have good security. not even close).

I certainly do contend that HIPAA has not benefited the security of the healthcare industry as a whole. IME, it may have very well hurt it.

* - I'm speaking specifically of the HIPAA security rule and it's effect on organizations' security maturity. In other areas, like patient privacy and disclosure rules, it does seem to have had an effect closer to what is intended.

Re: U.S. Cities Strain to Fight Hackers

#114
post #18
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

Advising companies that they can and should fix things is actually the easy part. Getting things fixed in a way that makes companies happy is actually incredibly difficult . You're proposing a government agency get its hands dirty fixining thousands upon thousands of bizarro line-of-business applications and mission-critical excel macros. Convincing companies to update what they see as systems that "work just fine" t…

Hack things apply crypto locker and unlock after the user does a a free cyber security training course.

Re: U.S. Cities Strain to Fight Hackers

#115

I'm surprised no one has mentioned it here on hacker news. But when CFAA makes all hacking criminal, the only hackers left are criminals. Ethically motivated hackers should have the same protections as whistle blowers - The day that happens, the world becomes more safe and transparent. But transparency is not what everyone wants, obviously. I wish I was more surprised that mainstream media fails to mention this impor…

In the process of using a town's court website to try to pay a parking ticket, I practically-accidentally found a security vulnerability in it. The vulnerability immediately showed me many people's personal information. I closed the page when I realized what had happened. I didn't report the issue because I was worried that the people running a small town's buggy court website might be more interested in figuring out…

Over thinking it? I don't think so.

35 years of jail time has a powerful chilling effect.

How this article could talk about the 'surprising' lack of ethical hackers without covering this law and it's abuse is beyond me.

It's like talking about the 'surprising lack of research into clinical MDMA studies' and not talk about the war on drugs. It's like they are intentionally ignoring the HUGE elephant in the room.

Re: U.S. Cities Strain to Fight Hackers

#116
post #94

Earlier quoted context omitted.

There will always be some organizations that do the minimum necessary to check some sort of "compliance" checkbox. However you can't deny that overall the healthcare industry as a whole has better security and security controls than they would if HIPAA had never been enacted.

I absolutely do deny that. Of the many healthcare companies I worked at, small 50-200 people shops and massive F500 companies and everything in between, I don't think HIPAA* made any kind of material difference in their security maturity. The companies that were actually good at security merely used HIPAA as a starting point, and sometimes had to divert resources away from actual security efforts just to meet redunda…

I'm not sure doing anything different or better would have a material difference in how much a breach will cost let alone the need to have insurance companies to cover them. Yes it's a lot of buggyman auditing and such, but in the end a breach is a breach and companies will do anything they can do downplay the cost. At least with the rules there is a workflow and process to go through when the breach happens.

When all is said and done it's really the organization. I don't know how many bigcorps I've been at that were just totally inept. The existence or not of HIPAA would not change their ineptness.

Re: U.S. Cities Strain to Fight Hackers

#117
Do you need hackers for hire? Do you need to keep an eye on your spouse by gaining access to their emails? As a parent do you want to know what your kids do on a daily basis on all social networks in others to make sure they're not getting into trouble? Whatever it is, Ranging from Bank Jobs, Flipping cash, Criminal records, removal of mugshots ,DMV, Taxes, crypto currency fraud investigation Name it, they can get the job done www dot assured hacks dot com

Re: U.S. Cities Strain to Fight Hackers

#118
post #27

Could someone suggest recognized and useful certifications, for those interesting getting into cybersecurity? The article has a link to another mentioning CompTIA and CISSP, are they any good?

Study to learn skills, not to get certs.

Any suggestion on good study material, then?

A lot of resources seems to be more like games than something applicable to the real world.

Re: U.S. Cities Strain to Fight Hackers

#119

There is a big industry starting to spring up around this, data insurance. Go to any big insurance conference and all they are talking about right now is cyber insurance. Construction companies are asking for it for example; they've always had to insure their employees, but now they are seeing things like their offices being hit by cryptolockers and being extorted for bitcoin by Russians. They can't afford to lose pr…

It's not clear how valuable cybersecurity insurance will be if there is no coverage for "acts of war" or if the insurer claims the insured didn't do enough to protect/defend against it. [1]

[1] https://www.lawfareblog.com/moment-truth-cyber-insurance

Post reply on HN