Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

371–380 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#371
post #347

Earlier quoted context omitted.

As seen from another capitalist country, namely Switzerland, I take the "higher interest" rates as a tired argumentative "canard". It's a false idea perpetrated by lobbyists. We don't have such databases. The difference here is that the bank's mortgage divisions have much lower profits, because checking somebody out is actually done by humans. It costs the credit provider more. US style mortgage broker do not exist.…

...so low- and middle-income people are not buying their own homes under that system, which is exactly what I said. What is the disagreement here? You say that interest rates are not higher, but that is a meaningless statement if people do not generally buy their homes on credit. Low- and middle-income Americans typically buy a home using a mortgage, and credit scores are an important part of that system.

My opinion point is that maybe if the US tried to do old style approach to home ownership, old fashioned banking, it wouldn't need that many artifices like rating agencies. Why I think that:

Your position is that the lack of a well informed credit market would make interest rates high, precluding acquisition of houses, hence the need for rating agencies.

My position is that truthful, complete information is enough to keep rates low, a market for that information is not necessary for assets which are not liquid (houses, mortgages). Swiss mortgage rate oscillate between 1-1.5%, depending on your financials.

Absolutely everybody buys houses and buildings on credit in Switzerland, due to huge tax deductibles. Those who don't are a rounding error around 99.9%, mainly due to some rare people's estate planning triggers.

Selling cheaper houses and apartments at lower prices has been repeatedly in the last 20 years (as low as a third of the usual price range). They doesn't sell.

Swiss are conservative, they tend to like long term investments with low degradation risk, regardless of current market price levels. Hence high prices, because they want high, long lasting quality.

Again nothing to do with credit information markets.

Re: US companies hit by 'colossal' cyber-attack

#372
post #347

Earlier quoted context omitted.

As seen from another capitalist country, namely Switzerland, I take the "higher interest" rates as a tired argumentative "canard". It's a false idea perpetrated by lobbyists. We don't have such databases. The difference here is that the bank's mortgage divisions have much lower profits, because checking somebody out is actually done by humans. It costs the credit provider more. US style mortgage broker do not exist.…

Yet another reason why I think Switzerland would be a great country to move to.

Yes and no.

It's not as good as it once was, and purchasing power is slowly but certainly going down. Everything is tightening up. Switzerland is extremely integrated into the western money circuits. If it goes to shit in the US, it'll follow suit at a much slower pace.

However, Eurasia is replete with countries which try to imitate Western European successes by applying the same receppies. If you can swing it, the purchasing power is 3-5 times larger on the same net income, and you don't have pesky invasions of your private sphere at each corner.

Also, as a Swiss, I can tell you that past the superficial welcome, we're a mountain people. We're really not as warm as others peoples. Over time, depending on your character, it may accrues and impact quality of life.

We are also very disciplined in a lot of aspects of life, even outside work. That is a problem for some over time.

But if your character fits, you'll have a blast.

Re: US companies hit by 'colossal' cyber-attack

#373
post #312

Earlier quoted context omitted.

> We set up software on a lot of machines Windows, right?

In the case I had in mind, the company runs a mix of windows and os x. And some android. Luckily it's mostly mac in the shops now, but personal laptops and tablets that connect to the LANs are also involved, and definitely the most dangerous point of failure.

Yup, if I had to run a company, it will be macbooks and iphones with MDM, like by jamf.com. That will cover device security. Then SSO, separated networks and no Windows whatsoever.

Re: US companies hit by 'colossal' cyber-attack

#374
post #339

Earlier quoted context omitted.

What is OPM ? Office of Personnel Management ?

Yes. In case you're asking what OPM is and not just the acronym intended, OPM is an agency that manages and maintains stewardship of a stupid amount of information about all employees that work for or closely with the federal government. Background checks and investigations, healthcare related policy information, etc. e-QIP, managed by OPM specifically, collects a lot of highly sensitive information on federal employ…

Holy hell... no wonder they snuffed it out in the media.

I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin.

The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!"

I sometime find wisdom in the approach from olden times :-)

Re: US companies hit by 'colossal' cyber-attack

#375
post #328

Earlier quoted context omitted.

I think that this is the case, from the reporting it seems like it’s just their payment infrastructure that is affected. Likely they could handle cash transactions just fine. It’s just that the vast, vast majority of Swedish customers don’t use cash anymore, so it’s not worth it to keep the stores open until it’s fixed.

That sounds so wrong, they should try to use cash if they can.

Going cashless is extremely common for customers in Sweden. They would get so few customers (everyone would just go to the next grocery store), and the aggravation it would cause from customers who haven't heard the news and can't pay probably just makes it not worth it to have them open. Take the loss, fix the issue, reopen all the stores when it's done.

Re: US companies hit by 'colossal' cyber-attack

#376

Earlier quoted context omitted.

You'd think that one of the credit bureaus responsible for maintaining the most sensitive data, and making it difficult for people to get affordable housing would be a government institution, but nope.

Would you rather have a government agency assign credit scores? The abuses would be rampant. Right now there is one party openly pushing to restrict voting access to people who are likely to vote for the other party, and a few years ago that same party enacted a new tax code that almost surgically penalized the residents of states that supported the other party; do you really trust such politicians to set up a fair c…

>Would you rather have a government agency assign credit scores? The abuses would be rampant.

Do you think the abuses are any less rampant when power is privatized? The main problem that would be solved by a government institution is a pathway for transparency and citizen recourse against questionable practices. It's admittedly not a lot of transparency or accountability but it can be far more than currently exists.

People talk about government corruption and sure, there's lots of it, but there's just as much if not more private corruption hidden behind privacy protection veils. At the very least, there is some degree of transparency with the government and we can in theory hold them accountable with explicit rights granted to us (more-so than private institutions).

I cannot hold these private institutions that have gamed the system so far they're beyond my grasp accountable for their actions. Ill start a credit rating agency tomorrow and compete with Equifax, Transunion, and Experian so through market forces of competition I can fix these problems! Consumers and market forces will fix these problems! Yea, right, give me a break.

This whole government bad, private good, anti-communism/socialism/whatever argument has grown tiring because we're at a point now where you can chuck private institutions in the same gutter of corruption as different systems of government. We played that fiddle and gave private institutions the benefit and here we are, with rampant corruption in concentrated pockets of business as well, governing our daily lives with little oversight or means of recourse beyond avoiding the system or hoping some competitor can actually change things.

Privatization works well when you can actually hold institutions accountable, when there are competitors that actually compete and give consumers the option to vote with their wallets. When that doesn't exist, it's far worse than a US government agency managing it. It might be cheaper but there's probably a good undesirable reason it's cheaper than a public institution that isn't related to poor management and basic optimization practices to improve efficiency. Those efficiency gains probably exist because the institution is doing something it shouldn't be doing, focusing on profit margins over implications on the consumer.

Re: US companies hit by 'colossal' cyber-attack

#377
post #192

Earlier quoted context omitted.

I wonder how much of a human element is involved in each individual hack. I would have thought the sticky note, encryption, payment & decryption was all automated.

As I understand it there is often a lot of discourse that takes place between the hacker and the hacked - agreeing prices, haggling, proof of files etc. Yes much can be automated but there is usually a human element to these deals and that costs the hackers money. They also want to be careful to limit their hacks to companies their handlers are happy for them to hack. Go too wide and you risk hitting a company direct…

You are correct. I have had the "pleasure" of going through the negotiation process before. There are even companies that specialise in it, and have DBs on who is a "trusted" threat actor (the industry term) who will actually honor the terms of the transaction or not.

There are thousands, if not tens of thousands, of such deals done every year.

Re: US companies hit by 'colossal' cyber-attack

#378

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

Unfortunately, these tools are so damn useful that people almost feel compelled to buy and use them. Eventually, as these attacks becomes more and more commonplace, I think companies will start looking for two things:

1) How secure is the software? Where are the audits?

2) If your software compromises my business, how much of the losses I incur as a result will you cover?

Re: US companies hit by 'colossal' cyber-attack

#379

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

> But giving the keys to the castle to some mid-tier company is just a recipe for disaster It sucks, because I know my company is quite small but we take security extremely seriously (we have 9 people, 4 are security engineers, and the other 5 have varying degrees of experience in security). I think people might worry that, because of our size, we won't be as secure as a larger company. But the irony is that larger c…

Much easier to do it Ina small company, very hard to get it right in a company "100x your size".

Re: US companies hit by 'colossal' cyber-attack

#380

Earlier quoted context omitted.

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

ISC² has done so much damage to the industry via enabling the fallacy of appeal to false authority it is mind-blowing. The cissp is such a terrible proof of whether someone knows anything, everyone knows it, but for some reason people keep falling for it.

I view it as a shared level of baseline knowledge that helps with conversation. If I see someone has it, it at least tells me they understand the words I’m using and have a basic knowledge of the concepts we are discussing (or should, at least). It also tells me they are good at taking tests.

It doesn’t tell me whether they understand how it all works together, or if they understand the organization’s environment, or if they are a good worker.

I don’t hold it against people who fail (I’ve seen good people fail the test) or who don’t have it - I just have to ask a few more probing questions to ensure they know the tech I’m discussing. But I don’t outright ask if someone is a CISSP, so typically I ask the clarifying questions anyway so our understanding of the problem is accurate and aligned.

And cert or not, I’m still more interested in whether you know what you’re doing than what you put on your resume.

Post reply on HN