Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

371–380 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#371
post #330

Earlier quoted context omitted.

We have to think of this similar to how any other human or company behavior is monitored. Hold companies responsible and have a market sell ransomware insurance. (One exception to my solution is poor government and public institutions who run awful software. Not sure what we can do) If I have a habit of burning down my house by being sloppy with safety, my rates will go up. There should be something similar Let us ta…

> That $$ amount will indirectly decide whether we go to war with Russia or pay software engineers. Not related to the subject, but wow I wonder how alarming it is that "war with Russia" meme is having a strong comeback, as it's being casually brought up in online discussions about software.

If that's what it takes to defend our sovereignty, it's what it takes.

They elected one of ours, we can unelect one of theirs.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#372
post #335

Earlier quoted context omitted.

I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…

You have to enforce standards. Good security is expensive. If companies in competition don't have to pay for good security those that do have it will have higher costs and have trouble competing.

> "running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing"

running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#373
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Most these hacks where done using leaked tools from the same alphabet peoples tools to fight terrorism in the first place. Horrible idea. We need companies to get their act together. Personal responsibility.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#374

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is. Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world. I despise seeing simple apps with ridiculous dependency trees (package.json with line counts…

Surely you mean lock files not package jsons?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#375
I find it wild that the "run government like a business" crowd now wants government to run business. No one in this thread is really discussing what, if anything, the government can really do. Meanwhile, business is more than happy to be a toddler wielding a gun of computer security literacy, or to take the money of such companies and not truly helping.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#376
post #320

Earlier quoted context omitted.

I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…

Many of the most serious recent incidents don't involve theft of end user data or impacting end users in any real way, unless you consider the "end users" of gas stations and ferry boats to be the victims of these attacks. That's not incorrect in a way, but also seems like a pointlessly wide net. The thing I'm a bit tired of is IT people in these threads taking every incident that comes along as an opportunity to ele…

The debate is pretty much divided between people who say "improved security is the solution" and people who say "treating it as crime/terrorism/the-mafia is the solution".

I'm in the improve the security camp. I think security can be improved if we impose good standards (meaning enforce inconvenient things like no backdoor updating apps, no critical infrastructure connected to the web).

The reason "treating this like terrorism" is useless is that there's always another hacker. It's hard but not that hard and anything doable today will be automatable tomorrow.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#378
post #335

Earlier quoted context omitted.

I'm a bit tired of the victim blaming with security. The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems. That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents…

You have to enforce standards. Good security is expensive. If companies in competition don't have to pay for good security those that do have it will have higher costs and have trouble competing.

Why I said you have to actually force the standards down people's throat, with laws or liability. Restaurants don't like health standards either.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#379
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

I think this is an unfair false choice. I blame security "experts" who store private keys on public facing web servers or allow for SQL injection in the same way as I blame doctors who over-prescribed Oxycontin for way longer than was safe to avoid dependence. Sure, there will always be procedural mistakes and zero days, but gross dereliction of even basic level expertise deserves scorn.

My anecdata is that the majority of times someone has gained access to a user's system somewhere that it has not been anything technical but purely social engineering. Whether that was a secretary at a medium-sized company or someone in medical records at a hospital. The latter case was more extreme - user received an email from the hospital's lawyer, replied saying she wasn't sure, "lawyer" emailed back to go ahead and access the website. Lawyer was the 'hacker' who had already broken into and taken over the lawyer's email. Luckily, it was phishing attack and not ransomware.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#380
post #346

Earlier quoted context omitted.

> I'm surprised at how dismissive the comments are. I've gotta ask: has the US's stance on terrorism been effective? Or did they merely use it as an excuse to militarize the police and erode human rights? Because I want the government to take effective action around ransomware, but "similar priority to terrorism" just doesn't fill me with hope.

The headline might be vague (though I'd personally love to see drone strikes on the scumbags that scam elderly people to of their meager savings) but the article itself talks in terms of priority and effort for investigations into malware attacks. E.g., they won't just shrug and do nothing because they care about other crimes more, like with my stolen GPS case.

I'm astonished you would support drone strikes on civilians. Scammers are working a bad job out of necessity. They are not villains who deserve to be extrajudicially murdered.
Post reply on HN