Earlier quoted context omitted.
Sure. But laws for dealing with legitimate threats sometimes get co-opted to also deal with extraneous matters.
That doesn't mean you avoid making laws for the legitimate threats, it means you also keep tabs on how they're used. A system of laws, and a system of oversight for the use of those laws.
U.S. to give ransomware hacks similar priority as terrorism, official says
281–290 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#282Earlier quoted context omitted.
If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?
The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping f…
In meatspace we expect the government to use kinetic force to stop people from attacking us. Like if I leave my door unlocked and some person comes in to start stealing my stuff, the cops really will respond and come stop that person (I have had a home breakin they responded quickly to). They didn't blame me for having bad locks. I pay a lot of taxes so my walls and locks don't have to be perfect.
In cyber land, it's an anarchy. The government offers no defense. But there's no reason someone can't offer a deterrent. Like if you knew who broke into your servers, and there was a goon squad that went and broke down their door either kinetically or electronically I think a deterrent strategy could eventually work. Like it literally does for meat-space security.
(Not totally sure I want that, but I'm just saying it would probably work and we haven't really tried it yet.)
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#283What about the other side of this? Instead of seeking backdoors and using them to spy on Americans, the NSA should be stepping up their game and securing vital infrastructure and domestic businesses against these attacks.
I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.
Tax laws are a different issue, even though I agree some megacorps aren't paying their fair share of "private security" right now.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#284Earlier quoted context omitted.
Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.
It's not any different than the war on drugs. The gov't can't really think in a different manner than just black and white. The world is made up of shades of gray, and it's just too difficult to create legislation to handle shades of gray.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#285Earlier quoted context omitted.
> even if we ignore China's likely response China is literally the only reason the US tolerates North Korea. And China solely tolerates North Korea because it causes all sorts of irritation for the US. Arguably, it would be better off for everyone living in North Korea if one of those two powers annexed it outright, but geopolitics loves backwater proxy wars.
> China is literally the only reason the US tolerates North Korea. Closer to the active phase of the Korean War, the USSR was also a factor. Today, the US distaste for instability, and naiton-building, and North Korea not having a hoard of oil or something similar to overcome that distaste is also a reason, today.
This is an unpopular opinion, but I feel like we should generally accept nation-building doesn't work well, countries we leave tend to go back to being horrible in a number of years after we set up a new nation there. And accepting that, and accepting sometimes that countries are completely failed, harmful to world security, and larger countries need to intervene: Annexation isn't actually a bad concept. It's absolutely frowned upon today, but I'm not sure is worse than what we've done to half a dozen countries in the past couple decades alone.
The barrier to war should be high, but at the point you obliterate a nation's governing structure, defenses, and likely civic infrastructure, you should accept you have a permanent responsibility for the civilians there. And maybe the best way to be democratic about it is to establish a process that states one annexes can petition and vote for secession after they've reached a more stable position.
> North Korea not having a hoard of oil or something
There's that. North Korea is a property that literally only Kim Jong Un wants. And major powers seem perfectly fine to let him have it as long as he mostlyish behaves.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#286Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#287Earlier quoted context omitted.
If it was illegal to pay the hackers back, and the Colonial Pipeline ransomware attack still happened, what would the options be? We'd have to turn the systems back on some way right?
They'd restore from backups, which is already what they did even after paying the ransom. More importantly, would the hack have happened in first place if they knew there was no chance of being paid? Every ransom paid just funds and encourages the next hack. The social damage is deserving of a large fine (i.e. 10x the ransom).
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#288It needs to be a double edged sword though where companies are just as afraid of facilitating ransomware attacks as they would be of the consequences of facilitating terrorists. In other words, this will only work if it means company's are taking the threat more seriously, not less.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#289Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#290Earlier quoted context omitted.
nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…
I don’t think that’s a fair comparison. I think a fair comparison would be 80,000 companies buy the same vault door from supplier X. But suddenly one criminal group has found a universal key to the vault that no one else knows about, and can now access all 80,000 vaults nearly simultaneously and clandestinely even though they still look closed and secure from outside observers.
---
What you described is a zero day, which is very rarely used - most ransomware simply uses the absolutely low hanging fruit of companies lagging behind years in security updates combined with highly insufficient backups.