Live data from Hacker News

U.S. Senate to probe whether legislation needed to combat cyber attacks

reuters.com

21–30 of 66 posts

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#21
An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom.

(Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#22

Legislation is required to reverse the posture of the NSA from offense to defense. Nothing else will help until that is done.

NSA’s posture has been both for at least twenty years. They have separate divisions and everything.

The issue of course is that their missions are out of alignment with respect to fixing vulnerabilities, and we've seen red team capabilities prioritised such that harm came to the vulnerable. Generally, defending an intentionally security-impaired infrastructure is going to be a lot of additional, probably costly work.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#23

I am always worried non-programmers don't sufficiently understand how pathetic it is that we limp along with bloated Unix and other accidents of history that were never retired. And this lassies-fair approach to cleanliness and reducing complexity both makes us more vulnerable and less productive.

Why single out Unix and not, you know, Windows ?

Because most IT infrastructure is based on some form of Unix?

Linux fans really like to play up the "Windows is so insecure!" rhetoric, but it isn't really true. Linux and the common systems implemented on it, for instance, have had plenty of vulnerabilities. Windows gets an especially bad rap pretty much only because it is the most common Desktop OS, but Desktop Windows and Desktop Linux have the same giant gaping security problem: the human being using them.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#24
post #18

Mandatory bug bounty programs with a minimum 1k payout. Open to US residents and foreigners alike.

At what level of scale? Is this for all businesses, including my weekend startup? What qualifies for a bug?

You could likely do this for any publicly traded company, but the qualifiers for what constitutes a bug would take some time to define.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#25
post #16

reverse the terrible ITAR legacy fund foundational security and mandate its use by government agencies and suppliers

> foundational security Can you tell us what that means?

I suspect the Bell-LaPadula model would be part of it

https://en.wikipedia.org/wiki/Bell%E2%80%93LaPadula_model

Much research was funded, and solutions were found long, long ago, to many of our current "problems".

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#27

An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

All you get at that point is the right people using it to prosecute the honest people.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#29
post #27

An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

All you get at that point is the right people using it to prosecute the honest people.

I think it would just give CEOs who want to do the right thing (and not pay) legal cover to tell the board of directors "Nope, not paying — the company is going to be shut down for a month. Deal with it, I'm not going to jail."

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#30

Earlier quoted context omitted.

Literally all of them. Security is a cost center, and non bureaucrats salaries are minimized as much as possible until you are left with "warm body to fill chair". Even the NSA doesn't pay well, compared to private sector.

> Even the NSA doesn't pay well, compared to private sector. On the other hand, I bet it's pretty fun working for the NSA: https://en.wikipedia.org/wiki/NOBUS

From what little I’ve heard, the NSA is not different from other public sector work.
Post reply on HN