Live data from Hacker News

Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

nbcboston.com

111–120 of 267 posts

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#111
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

As an alternative question, how much is this worth stopping? As how much is being spent on these payments overall each year? How would that compare to the massive IT fortification project people are demanding? We don't meaningfully fight bike theft for this reason. The cost of doing so relative to the benefits is just too high. We can debate whether that is reasonable, but that is essentially what has been decided as…

We don't meaningfully fight bike theft for this reason.

And this erodes trust in society and rule of law, and gradually leads to vigilantism, privatization of security, and segregation due to middle-class flight from high-crime areas.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#112

This isn't news anymore, its weather. If your company does not have a full time cybersecurity team, they soon will, even if they say they don't need it.

Most companies should really outsource their IT infrastructure instead of hiring a full-time cyber security team. It will be cheaper in the long run.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#113
post #18

Earlier quoted context omitted.

Isn't this like banning cash to stop muggings?

It is, and it has proven very effective. Robberies against banks and stores have been cut in half during the last ten years, as cash is getting harder to access. Many store open after 19:00 don't have much cash on hand so robbing them is not really attractive any more. There are almost no bank robberies, as even banks doesn't actually have cash. The people who get mugged are normally forced to go to an ATM to withdra…

That's not a function of banning cash however, its on account of the rise of credit cards. No one sacrificed or was inconvenienced to get here, it was just natural progression with good side effects.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#114

Earlier quoted context omitted.

You won't even be able to get private insurance if the industry has to insure against complete destruction of a given business. Are you expecting the US gov to backstop every business regardless of size against ransomware? Who is going to pay for that? Additionally, how do you protect against the obvious opportunities for fraud and abuse (business deliberately attacks itself to collect the insurance payout, business…

>"insure against complete destruction of a given business." Isnt that what fire/flood insurance is for?

Fire and flood insurance protect against discrete or regional risks whereas ransomware will potentially disrupt operations globally, and actually most private insurers won't offer flood insurance to large swaths of the US because the risk has been deemed to be too high. The US gov insures against coastal flooding at GREAT expense to the tax payer.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#115
post #112

This isn't news anymore, its weather. If your company does not have a full time cybersecurity team, they soon will, even if they say they don't need it.

Most companies should really outsource their IT infrastructure instead of hiring a full-time cyber security team. It will be cheaper in the long run.

[deleted]

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#116

Earlier quoted context omitted.

As an alternative question, how much is this worth stopping? As how much is being spent on these payments overall each year? How would that compare to the massive IT fortification project people are demanding? We don't meaningfully fight bike theft for this reason. The cost of doing so relative to the benefits is just too high. We can debate whether that is reasonable, but that is essentially what has been decided as…

We don't meaningfully fight bike theft for this reason. And this erodes trust in society and rule of law, and gradually leads to vigilantism, privatization of security, and segregation due to middle-class flight from high-crime areas.

Source to support your statement?

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#117

Earlier quoted context omitted.

You won't even be able to get private insurance if the industry has to insure against complete destruction of a given business. Are you expecting the US gov to backstop every business regardless of size against ransomware? Who is going to pay for that? Additionally, how do you protect against the obvious opportunities for fraud and abuse (business deliberately attacks itself to collect the insurance payout, business…

You would be able to get affordable private insurance if you had a cyber security team.

Various providers of "cyber insurance" are right now busy getting rid of ransomware coverage because it turns out offering that isn't working for them. and yes, they do require companies to have cyber security infrastructure and audits.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#118
post #112

This isn't news anymore, its weather. If your company does not have a full time cybersecurity team, they soon will, even if they say they don't need it.

Most companies should really outsource their IT infrastructure instead of hiring a full-time cyber security team. It will be cheaper in the long run.

Seeing some of the mess that IT-support is for enterprise customers I wonder would they really do better. On other hand SLA could be a real thing and kill the incompetent providers.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#119

Earlier quoted context omitted.

As an alternative question, how much is this worth stopping? As how much is being spent on these payments overall each year? How would that compare to the massive IT fortification project people are demanding? We don't meaningfully fight bike theft for this reason. The cost of doing so relative to the benefits is just too high. We can debate whether that is reasonable, but that is essentially what has been decided as…

We don't meaningfully fight bike theft for this reason. And this erodes trust in society and rule of law, and gradually leads to vigilantism, privatization of security, and segregation due to middle-class flight from high-crime areas.

As I said, we can dislike it, but as a society we have basically decided that anything short of reasonably straightforward violent crime/extreme violent crime and high value property crime and easy to prosecute drug crime is not worth the effort.

I don't disagree, but I hear very little discussion about low solve rates for smaller crimes.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#120

Earlier quoted context omitted.

You won't even be able to get private insurance if the industry has to insure against complete destruction of a given business. Are you expecting the US gov to backstop every business regardless of size against ransomware? Who is going to pay for that? Additionally, how do you protect against the obvious opportunities for fraud and abuse (business deliberately attacks itself to collect the insurance payout, business…

>"insure against complete destruction of a given business." Isnt that what fire/flood insurance is for?

I wonder what the biggest company is that's totally dependent on a single location (or locations in the same flood zone) and at the same time is usefully insured against such destruction.
Post reply on HN