Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

351–360 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#351
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

same mentality as dismissing airbags in cars because "people should drive better/pay attention more"

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#352

Earlier quoted context omitted.

I read and heard that as a Def Leppard ballad.

To what tune?

https://youtu.be/urNFQw8VIvA

:big hair band emoji:

:hairbear (too much hairspray) emoji:

:big feline pants emoji:

:leather pants emoji:

:excessive silver jewelry emoji:

:loud motorcycles emoji:

:mosh-pit emoji:

\m/

Looking back with 20/20: clothing styles back then, even for the rockstars, were damn basic: 99% long-haired, half-naked paler-than-I people in jeans, jean jackets, and wifebeaters. xD

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#353
post #330

Earlier quoted context omitted.

We have to think of this similar to how any other human or company behavior is monitored. Hold companies responsible and have a market sell ransomware insurance. (One exception to my solution is poor government and public institutions who run awful software. Not sure what we can do) If I have a habit of burning down my house by being sloppy with safety, my rates will go up. There should be something similar Let us ta…

> That $$ amount will indirectly decide whether we go to war with Russia or pay software engineers. Not related to the subject, but wow I wonder how alarming it is that "war with Russia" meme is having a strong comeback, as it's being casually brought up in online discussions about software.

I was being sarcastic in this instance. Meant to say there is more to do within software before blaming “user”/“hacker”. Russia reference is only based on recent news/claims

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#354
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

> It's physically impossible to build a house that can't be broken in to, and even harder for computer systems.

Which is exactly why you don’t store your savings in your sock drawer, you put it in the bank.

Companies not taking appropriate backups is akin to keeping all of your money in a dish by the front door. Sure your house may never get broken into but nobody is going to have sympathy for you if it does.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#355
post #218

Earlier quoted context omitted.

You have a point, but I also can expect a minimum level of competance and caring about the data you have stewardship over. Sure, given enough time and motivation anyone can probably break into anything, but that isn't an excuse to let the password for the FTP server that pushes out updates be 'password123'. Here's the problem companies have absolutely no incentive to care about Security. Several years back some hacke…

The concept of Moral Hazard is important here, which basically states that there is a lack of incentive to guard against risk where one is protected from its consequences. In a lot of cases the execs of these companies will continue to collect a large bonus, despite the fact that they utterly failed their customers.

Tieing the CEO pay to attacks should be as common as Poison pills, Golden Parachutes, and Stock incentives.

Backups, and strict security, might be important? Put security right up their as important as their rediculious salaries.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#356
post #79
post #57

Earlier quoted context omitted.

> Cash is a solution to the problem of portable assets. Barely. The portability usually ends at country borders. > Bitcoin is a problem in search of a solution. Don't you mean "a solution in search of a problem?" Nice Freudian slip, though :)

I thought being a solution in search of problem was perhaps too charitable. Every joule we waste on hashes is another gram of carbon in the air. And it is all waste — the only problem cryptocoins solve better than other solutions is illicit transactions. It’s not even close to as anonymous as cash. Coinage used to be more portable in the days of precious metal coins. But honestly I’ve had very little barriers in conv…

bitcoin and related systems are a solution to the double spending problem. Perhaps a flawed solution based on the information we know now, but it is a solution nonetheless. some related systems such as monero, zcash, and GNU taler make attempts at ensuring spender privacy, like cash.

but the computational power is nessisary for the network to function in a manner that is provable to new nodes. Because you can use a digital signature to confirm a transaction happened after some time, but not before some time.

I don't think cash is a solved problem within the context of computer networks. If I could transfer money using a program by using a digital signature, I would be satisfied, but anyone who can get access to my credit card numbers (and name, billing address and other open source info) can make purchases in my name. And you of course must rely on the fractional reserves of some central entity.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#357
post #346
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

> I'm surprised at how dismissive the comments are. I've gotta ask: has the US's stance on terrorism been effective? Or did they merely use it as an excuse to militarize the police and erode human rights? Because I want the government to take effective action around ransomware, but "similar priority to terrorism" just doesn't fill me with hope.

It's a bad comparison, becauSe organized "War on Terror" terrorism is extremely rare, because it's not very profitable.

The news is PR fluff.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#359
post #354

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

> It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Which is exactly why you don’t store your savings in your sock drawer, you put it in the bank. Companies not taking appropriate backups is akin to keeping all of your money in a dish by the front door. Sure your house may never get broken into but nobody is going to have sympathy for you if it does.

Backups are no longer sufficient - as the hackers now threaten to disclose stolen data to the public.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#360

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

nope but we also demand some due diligence from private entities. When you leave the garage, the windows and the front door open with a "here's the money" sign pointing at your safe you might have a problem if someone steals your customers stuff. Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastruct…

If the pipeline could run without corporate, why would corporate exist?
Post reply on HN