Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

281–290 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#281

Earlier quoted context omitted.

Sure. But laws for dealing with legitimate threats sometimes get co-opted to also deal with extraneous matters.

That doesn't mean you avoid making laws for the legitimate threats, it means you also keep tabs on how they're used. A system of laws, and a system of oversight for the use of those laws.

Yes, keep tabs on how it's used. But also, when it's being written, try to think about how it's likely to be misused, and write it in a way that it can't be misused like that. (Amusingly, I made a typo, and misused came out mis-sued.) Legislators try to write laws broad enough that they cover everything and can't be weaseled out of, but that leads to them covering more than intended.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#282

Earlier quoted context omitted.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping f…

I think if you had good attribution it's more like armies. We have been focused on locking our doors, on building better walls, etc. But there is a non-defensive side.

In meatspace we expect the government to use kinetic force to stop people from attacking us. Like if I leave my door unlocked and some person comes in to start stealing my stuff, the cops really will respond and come stop that person (I have had a home breakin they responded quickly to). They didn't blame me for having bad locks. I pay a lot of taxes so my walls and locks don't have to be perfect.

In cyber land, it's an anarchy. The government offers no defense. But there's no reason someone can't offer a deterrent. Like if you knew who broke into your servers, and there was a goon squad that went and broke down their door either kinetically or electronically I think a deterrent strategy could eventually work. Like it literally does for meat-space security.

(Not totally sure I want that, but I'm just saying it would probably work and we haven't really tried it yet.)

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#283
post #45
post #25

What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

Police forces are paid for with taxes and respond to private businesses. What if publicly funded cybersecurity ends up costing everyone less money over the long term?

Tax laws are a different issue, even though I agree some megacorps aren't paying their fair share of "private security" right now.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#284

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

It's not any different than the war on drugs. The gov't can't really think in a different manner than just black and white. The world is made up of shades of gray, and it's just too difficult to create legislation to handle shades of gray.

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#285

Earlier quoted context omitted.

> even if we ignore China's likely response China is literally the only reason the US tolerates North Korea. And China solely tolerates North Korea because it causes all sorts of irritation for the US. Arguably, it would be better off for everyone living in North Korea if one of those two powers annexed it outright, but geopolitics loves backwater proxy wars.

> China is literally the only reason the US tolerates North Korea. Closer to the active phase of the Korean War, the USSR was also a factor. Today, the US distaste for instability, and naiton-building, and North Korea not having a hoard of oil or something similar to overcome that distaste is also a reason, today.

> Today, the US distaste for instability, and nation-building

This is an unpopular opinion, but I feel like we should generally accept nation-building doesn't work well, countries we leave tend to go back to being horrible in a number of years after we set up a new nation there. And accepting that, and accepting sometimes that countries are completely failed, harmful to world security, and larger countries need to intervene: Annexation isn't actually a bad concept. It's absolutely frowned upon today, but I'm not sure is worse than what we've done to half a dozen countries in the past couple decades alone.

The barrier to war should be high, but at the point you obliterate a nation's governing structure, defenses, and likely civic infrastructure, you should accept you have a permanent responsibility for the civilians there. And maybe the best way to be democratic about it is to establish a process that states one annexes can petition and vote for secession after they've reached a more stable position.

> North Korea not having a hoard of oil or something

There's that. North Korea is a property that literally only Kim Jong Un wants. And major powers seem perfectly fine to let him have it as long as he mostlyish behaves.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#286
If we don't get ahead of this we'll regulatory capture ourselves into oblivion and the enemy will win anyway. As long as state-sponsored-actors are indistinguishable from black-market criminals this will never escalate beyond the perpetual cat and mouse game. We simply have to be better, and we can't have oversight committees and regulatory boards managing it. Infosec is ripe for being revolutionized.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#287

Earlier quoted context omitted.

If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?

They'd restore from backups, which is already what they did even after paying the ransom. More importantly, would the hack have happened in first place if they knew there was no chance of being paid? Every ransom paid just funds and encourages the next hack. The social damage is deserving of a large fine (i.e. 10x the ransom).

Cleary it wasn’t that simple or they would have just done that.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#288
I think this is needed because the security industry seems to be well on the way to adopting paying off these people as a routine cost of business. That is going to lead to an absolute disaster if it is allowed to continue and grow.

It needs to be a double edged sword though where companies are just as afraid of facilitating ransomware attacks as they would be of the consequences of facilitating terrorists. In other words, this will only work if it means company's are taking the threat more seriously, not less.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#290

Earlier quoted context omitted.

nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…

I don’t think that’s a fair comparison. I think a fair comparison would be 80,000 companies buy the same vault door from supplier X. But suddenly one criminal group has found a universal key to the vault that no one else knows about, and can now access all 80,000 vaults nearly simultaneously and clandestinely even though they still look closed and secure from outside observers.

... but this was 5 years ago and everyone and their dog knows it by now, the company just didn't bother to change that door. Also, the criminal group doesn't hit doors with cameras, but nobody bothered to install one.

---

What you described is a zero day, which is very rarely used - most ransomware simply uses the absolutely low hanging fruit of companies lagging behind years in security updates combined with highly insufficient backups.

Post reply on HN