Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

391–400 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#391
post #324

Earlier quoted context omitted.

Really? I don’t think this is at all similar to a car safety recall. That’s more like trying to issue a recall for a car because people can smash it’s windows and break in.

yeah of course it's an analogy. But by adding liability we'll get more recalls (patches) done. Vendors will stop playing FUD and will focus on the real cost of their security flaws. And yes some will still not do patches, just like some car vendors are considered less trustworthy. But at least the risk of suit will loom over their heads.

But the parent's point is that's still putting the liability on the vendor rather than the actual criminal. Perhaps it's more like if a car is sold without an immobilizer or an alarm, holding the manufacturer liable if it's stolen. But if that kind of fails, because it's pretty simple to mandate a handful of security additions to cars, whereas software is orders of magnitude more varied and complex. It would be hard for any vendor, let alone small companies, to prove they'd followed every conceivable best practice. Might even be impossible, as some likely conflict. And if you try to codify exactly what security practices should be followed, what do you do when those practices become obsolete?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#392
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Crime needs to be dealt with but a lot of companies I worked with in the past 30 years are simply negligent. If you do not blame the victim, what is the incentive for spending money on even basic security? Not morality surely, so...

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#393
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Sure, but terrorism has always been the blanket "fuck it, max charge it, we can't be bothered to ACTUALLY come up with legislation" so maybe don't fuck it and work out a proper set of laws.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#394
post #375

I find it wild that the "run government like a business" crowd now wants government to run business. No one in this thread is really discussing what, if anything, the government can really do. Meanwhile, business is more than happy to be a toddler wielding a gun of computer security literacy, or to take the money of such companies and not truly helping.

As others are pointing out it various ways in this thread, to put it bluntly, this viewpoint treats it as a 100% computer science theoretical question, there are many many angles to making this more painful, even just via signalling. Ex. the pipeline hackers backing off and creating a code of conduct for themselves, then disappearing altogether

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#395
post #335

Earlier quoted context omitted.

You have to enforce standards. Good security is expensive. If companies in competition don't have to pay for good security those that do have it will have higher costs and have trouble competing.

> "running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing" running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing

[deleted]

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#396
post #364

As someone who has mainly done web apps and desktop development for near a decade, I am interested in maybe a career in cyber security. Any tips or ideas?

You might try submitting that as an "Ask HN".

There are a number of cybersecurity folk here (tptacek, nickpsecurity, etc.)

And a few earlier threads: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#397
post #244

“Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.” That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.

they made a LOT more than 5m. I would have also been putting bets into the markets much earlier and cashing in on the stupid chaos. Continuing to let them do this with impunity is going to lead to escalated attacks.

Those bets could be easier to trace than the ransom payment though. Is there a way to make market bets completely untraceably?

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#398
post #115

They fucked up by targeting infrastructure. If they stuck with small companies they could keep doing it till the cows came home. But now they have governments against them so now they will be hunted down.

These groups aren't really "targeting" anyone. These ransomware attacks are as sophisticated as nigerian prince emails. Send out a lot of spam, wait for someone who clicks on it and is running outdated software and boom. Sooner or later you will encrypt something important enough to pay for.

> Send out a lot of spam, wait for someone who clicks on it and is running outdated software and boom.

outdated Windows software

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#399
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

>> Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment and everything in between.

Not exactly. Executives are choosing to hire el-cheapo offshore middlemen to manage security, software development and to save money (latter is more important - more money in their own pockets) - and we all are on a hook for this behavior. Criminals and hackers are like viruses - they are always there. But we need to maintain the health of the whole body (country and it's entities) to make sure we're resilient.

Execs and politicians selling our security and freedoms for profits and bribes need to be dealt with appropriately.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#400
post #354

Earlier quoted context omitted.

> It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Which is exactly why you don’t store your savings in your sock drawer, you put it in the bank. Companies not taking appropriate backups is akin to keeping all of your money in a dish by the front door. Sure your house may never get broken into but nobody is going to have sympathy for you if it does.

Backups are no longer sufficient - as the hackers now threaten to disclose stolen data to the public.

Which only works because they’re paying the ransom. The second the government introduces criminal penalties against the executives and boards for paying ransom, it will stop.
Post reply on HN