Live data from Hacker News

U.S. Senate to probe whether legislation needed to combat cyber attacks

reuters.com

31–40 of 66 posts

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#31

Earlier quoted context omitted.

Why single out Unix and not, you know, Windows ?

Because most IT infrastructure is based on some form of Unix? Linux fans really like to play up the "Windows is so insecure!" rhetoric, but it isn't really true. Linux and the common systems implemented on it, for instance, have had plenty of vulnerabilities. Windows gets an especially bad rap pretty much only because it is the most common Desktop OS, but Desktop Windows and Desktop Linux have the same giant gaping s…

Everything you say is true, but that wasn't my point. The OP said

> ... how pathetic it is that we limp along with bloated Unix and other accidents of history that were never retired.

So, why single out Unix? Is Unix more bloated than Windows? I doubt it. Is it more of an accident of history than Windows? No. Is it more in need of being retired than Windows? I think it would take someone with an axe to grind to say so.

And that's what my comment was about: Trying to expose that axe being ground.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#33
post #28
post #11

Translating to plain language: bureocrats are evaluating the possibility to ban encryption and cryptocurrencies under the veil of combating cyber attacks.

I mean cryptocurrency is indeed what made ransomware possible.

I'd argue they make it less risky. Ransomeware has been around since the 90s, just not nearly as prevalent as it was harder to do without getting caught. They could easily instead demand somebody mail cash/money order to an abandoned address or mail forwarding service.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#34

An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

All that guarantees is ransomware attacks morph into existential threats. You're locked out of your data with no recourse.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#35
post #27

Earlier quoted context omitted.

All you get at that point is the right people using it to prosecute the honest people.

I think it would just give CEOs who want to do the right thing (and not pay) legal cover to tell the board of directors "Nope, not paying — the company is going to be shut down for a month. Deal with it, I'm not going to jail."

And it would give CEOs who want to do the wrong thing an avenue to destroy competitors under the table.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#36

An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

Isn’t it already extremely difficult to know whether you’re committing a felony by paying a ransom? You’re sending millions of dollars in bitcoins to an unidentified group of known felons; if they are (or are affiliated with) a group dedicated to the violent overthrow of a government, then congratulations, you’ve just provided material support to a terrorist organization.

The US Treasury Office of Foreign Assets Control specifically warns about the legal risk you take by paying a ransom here: https://home.treasury.gov/system/files/126/ofac_ransomware_a...

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#37

Legislation is required to reverse the posture of the NSA from offense to defense. Nothing else will help until that is done.

What would a defensive NSA look like? I picture them openly accessing all US networks claiming they were "boosting defense" rather than secretly infiltrating them.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#38
post #33
post #28

Earlier quoted context omitted.

I mean cryptocurrency is indeed what made ransomware possible.

I'd argue they make it less risky . Ransomeware has been around since the 90s, just not nearly as prevalent as it was harder to do without getting caught. They could easily instead demand somebody mail cash/money order to an abandoned address or mail forwarding service.

Collecting a ransom in physical cash is extremely risky for criminals! Law enforcement knows where you are at a specific time.

I have never heard of ransomware that predated cryptocurrency; could you share a link to an article?

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#39
post #27

Earlier quoted context omitted.

All you get at that point is the right people using it to prosecute the honest people.

I think it would just give CEOs who want to do the right thing (and not pay) legal cover to tell the board of directors "Nope, not paying — the company is going to be shut down for a month. Deal with it, I'm not going to jail."

What if it was more than a month? What if it was.. permanent?

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#40
post #36

An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

Isn’t it already extremely difficult to know whether you’re committing a felony by paying a ransom? You’re sending millions of dollars in bitcoins to an unidentified group of known felons; if they are (or are affiliated with) a group dedicated to the violent overthrow of a government, then congratulations, you’ve just provided material support to a terrorist organization. The US Treasury Office of Foreign Assets Cont…

No different to paying your US taxes to fund the same thing.
Post reply on HN