Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

231–240 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#232
post #162

Earlier quoted context omitted.

That assumes all cyber threats can be averted by private corporations. It's difficult for a company to play effective defense against nation-state levels of cyber attack R&D. Yes, companies need better security than they have now, but they cant do it without help.

This is where the threat of retaliation comes in as a deterrent, and the country should be equipped to do so. But publicly subsidizing private cybersecurity is both impractical (how would that work exactly?) and would encourage underspending even further. Why do you think China or Russia prefer to hack foreign private competitors rather than sending a bunch of missiles on their infrastructure?

We publicly subsidize every other kind of security to some degree already. A company might have security guards, but police are certainly going to be there to provide a baseline policing the neighborhood, respond to calls, etc.

And security via threat of retaliation does not sound like a practical or effective solution either: we already have plenty of capabilities in that area, and it didn't stop east coast oil & gas infrastructure from going down or a sizeable portion of the nation's meat processing from going the same way. These attacks are escalating rapidly, and relying in the free market to find a solution doesn't look like it's going to happen fast enough.

This needs to be a national, not (just) a private corporate issue because of the enormous national security implications involved in cyber attacks against infrastructure. When a single company's security failure can cause national chaos, there needs to be a nation-level approach to this.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#233
post #106
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

Let's say you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA. They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends! They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? K…

Let's say that you're a CEO at Big Pipeline Co. One day your phone rings. It's the NSA.

They have a report with a list of vulnerabilities. If you don't fix them to your satisfaction, you will be fined in 2 months, 2 months after that you get fined and publicly reported as negligent, and 2 months after that you get fined again and your outstanding vulnerabilities will be published for everyone to take advantage of.

How much effort are you going to put in to securing your infrastructure?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#234
post #115

They fucked up by targeting infrastructure. If they stuck with small companies they could keep doing it till the cows came home. But now they have governments against them so now they will be hunted down.

These groups aren't really "targeting" anyone. These ransomware attacks are as sophisticated as nigerian prince emails. Send out a lot of spam, wait for someone who clicks on it and is running outdated software and boom. Sooner or later you will encrypt something important enough to pay for.

I've seen a lot of recent articles on the subject that claim it's moving in the targeted direction, here's an example:

Over the past few years, threat actors have shifted to much more targeted attacks that net higher Bitcoin payment returns for their efforts.

https://blog.cloudflare.com/targeted-ransomware-attack/

Edit: Commonly mentioned in the same breath:

- the move from just demanding a ransom for the key, to threatening publication of sensitive info

- trawling through the data to look for anything especially sensitive, as well as clues to what number to ask for in financial records

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#235

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…

I don’t think that’s a fair comparison. I think a fair comparison would be 80,000 companies buy the same vault door from supplier X. But suddenly one criminal group has found a universal key to the vault that no one else knows about, and can now access all 80,000 vaults nearly simultaneously and clandestinely even though they still look closed and secure from outside observers.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#236

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…

The market doesn’t incentivize security until it is too late. A pipeline operator that passes security costs onto consumers will lose to one with lower security and lower costs. Serious, significant attacks might occur at year 5, when the company becomes a big enough target to make it worthwhile to attack. By this time, the company who did not invest as heavily in security has captured the market while the one that invested in security does not have strong market share or may have gone out of business.

Or they invested, but not in the right areas, or there was a new attack through a zero day.

They can be extremely competent in managing oil and gas (and the physical and operational safety that comes with it), but not be competent in Cybersecurity.

It’s real, hard costs today for something that may or may not happen and paying for controls that might prevent an attack. In the best case, as a customer, nothing happens. Whether improving the likelihood that nothing happen is worth a $1 or $3 per barrel premium (or if that $2 is justified) is a hazy mess and hard to make a decision around.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#237
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

I'm a bit tired of the victim blaming with security.

The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems.

That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents on. Since, there are no coherent standards now, just liability isn't useful. And the standards should involve actual topology, what kinds of information is allowed in and out at all.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#238
post #166
post #144

Earlier quoted context omitted.

> an email from the NSA telling IT what they already know No, that's not what the email from NSA would say. It would not say "there is a risk of your systems being compromised by cyberattack" in general terms, which is what IT already knows. It would say "your systems are vulnerable to these specific attacks", which IT does not know. So yes, getting this new information should change the risk-benefit calculation dram…

I've been on the receiving end of various emails like that. They have details on specific systems and specific attacks. They're occasionally useful, but often not. Knowing that a particular app is vulnerable to XSS might be useful, if I have staff that can fix it and they have the spare cycles. For example, a hospital IT department might get an email telling them that their MRI is exposing remote desktop to the inter…

If the message comes with, "You have X time to fix this or you will have Y penalty" it definitely changes the risk/reward equation. Severe enough penalties moves it from "if we have spare cycles" to "how do we get this done."

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#239
post #45

Earlier quoted context omitted.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

Corporations pay tax too, if I was an American shareholder of a company that went to the wall due to a 0 day vulnerability that was known by the NSA I would not be happy. Imagine if you found out that the NSA knew about COVID but didn't develop or release a vaccine because they wanted to use it themselves, why is it really and different if corporations are people too?

[dead]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#240
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

> the way that the pipeline-company ransomware hackers beat a hasty retreat was noticeably unusual, and already seemed to telegraph that the state was getting involved more...actively.

Uh, there was no retreat - the company paid the ransom the day after the hack.

https://www.theguardian.com/technology/2021/may/19/colonial-...

Post reply on HN