U.S. to give ransomware hacks similar priority as terrorism, official says
211–220 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#212Earlier quoted context omitted.
I know, in theory you can have a law for everything. For example, in the Soviet Union basic electronics such as radios were restricted and you were not allowed to tune your sets to western stations.
You can also have a total free for all. Murder, kidnapping, etc, all legal. See? I can do it too.
But yes, everything can be banned eventually. We'll just go back to living in the cave.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#213Earlier quoted context omitted.
Bitcoin is just math. The US isn't going to be able make holding bitcoin illegal, and I very much doubt it will ever be able to make the buying and selling of it illegal -- there are even free speech issues here. But what it can do is tax the hell out of it, regulate the exchanges as investment platforms, but they will have a hard time trying to make it illegal to pay someone to sign a cryptographic hash.
The US very much decides who, where, and what can be bought or sold in USD. Worldwide.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#214I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
That's the case with a lot of these companies who:
a) Have pitiful/non-existent bug bounty programs (or even worst, prosecutes white hat hackers who raise issues)
b) Prioritizing exec bonuses instead of investing in InfoSec
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#215Earlier quoted context omitted.
As someone who isn’t a security expert, If you had a magic wand, what does this future look like to you? What is properly implemented security?
> Because the lessons of capability based security were ignored for decades, and not taught, the common consensus is that computers can never be made secure, and your best hope is to hire the smartest people in the world, at less than the average market rate, to secure your systems. I presume the OP is a fan of capability-security and while I'm not an expert on capabilities, I agree they can go a _long_ way to mitiga…
Yes, Fuschia and Genode both have a way to go before they are good enough for general purpose use.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#216Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#217Let's look at the chain of events. Computing machinery becomes exponentially cheaper, and it gets pushed into all corners of industry. Shared computing becomes a thing, and the need to have a better model of security is realized as a lesson from Viet Nam, and the Capability Based Security model is born. Microprocessors again exponentially decrease the cost of computing, and Capability Based Security isn't required be…
The irony of this post on a VC hosted forum. If you believe this, couldn’t/shouldn’t you pitch it get funding and live the Silicon Valley dream and “make the world a better place”?
If I were going to pitch something, it would be a kit consisting of 2 servers and a data diode, useful for getting data to move only in your direction of choice, guaranteed by the laws of physics to be un-hackable. (LED/Photodetector pair)
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#218I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
Sure, given enough time and motivation anyone can probably break into anything, but that isn't an excuse to let the password for the FTP server that pushes out updates be 'password123'.
Here's the problem companies have absolutely no incentive to care about Security. Several years back some hackers stole a bunch of my information from Experian. You know what I got out of it, a free $10 subscription to their identity service, along with lifelong worry of wondering if someone has opened an account in my name and racked up a ton of debt that I'll be held responsible for.
You know what Experian got, nothing, a slap on the wrist and now their stock is in the same place it was before.
I am doing my Masters in Information Assurance and Cybersecurity right now, and the whole mindset of all of my classes is "you're going to be pwned eventually so figure out how to move the risk to some other poor sucker to take the blame when it happens." pisses me off so much. The entire industry basically uses this as an excuse to avoid responsibility and just make sure they aren't the ones held responsible when the manure hits the rotary oscillator, and that bugs me to no end.
At the end of the day there are real people who are getting screwed and hurt by this, while the execs and security "consultants" spend their time trying to figure out how to make sure that when sh* hits the fan they can't be sued, and d** the customer and their well-being we've got to figure out how to make sure we keep the law away.
EDIT: Clarity and formatting
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#219Earlier quoted context omitted.
I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.
If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#220What, in that they're going to entrap kids into thinking they're doing it?