Live data from Hacker News

U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

reuters.com

41–50 of 59 posts

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#41
post #33

Director of Engineering - Security from Coalition here (we participated in the event) - We committed to building more free security tools for all organisations to protect themselves. We’ve already made Coalition Control our Attack Surface discovery and monitoring platform free ( https://control.coalitioninc.com ) and we will continue to add more features and more tools for free there. If there are any questions,I am…

What kind of create standards could you create? Some thoughts: 1) Certain infrastructure should be off the net automatically - pipelines, water treatment plants and similar things (or online with hardware guaranteed one ways connections). 2) Standards for testing backups. 3) Standards for IoS devices (a million insecure Internet light bulbs, what could possibly go wrong). 4) Standards for not having a hundred compani…

The great thing about insurance is that we don't just get to create baselines our policyholders must adhere to, we also get to enforce them. A perfect example of this is anyone that has a policy with us must have RDP behind VPN/ whitelisted only to specific IPs. I spent years trying for free to convince orgs to do this and was ignored, here we convince all our policyholders to do it and everyday more and more companies as we onboard them.

For backups, not only do they need to have it, they need to be tested, kept offline and encrypted - this doesnt apply to all its split by revenue bands/industry/mix of other logic.

IoT devices - they get notified in Control if we find any on the internet and told to not have them directly exposed

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#42
post #41

Earlier quoted context omitted.

What kind of create standards could you create? Some thoughts: 1) Certain infrastructure should be off the net automatically - pipelines, water treatment plants and similar things (or online with hardware guaranteed one ways connections). 2) Standards for testing backups. 3) Standards for IoS devices (a million insecure Internet light bulbs, what could possibly go wrong). 4) Standards for not having a hundred compani…

The great thing about insurance is that we don't just get to create baselines our policyholders must adhere to, we also get to enforce them. A perfect example of this is anyone that has a policy with us must have RDP behind VPN/ whitelisted only to specific IPs. I spent years trying for free to convince orgs to do this and was ignored, here we convince all our policyholders to do it and everyday more and more compani…

The same thing we do with RDP we also do with any critical vulnerability we notify customers in Control (example all of the latest Exchange vulns)

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#43
post #33

Director of Engineering - Security from Coalition here (we participated in the event) - We committed to building more free security tools for all organisations to protect themselves. We’ve already made Coalition Control our Attack Surface discovery and monitoring platform free ( https://control.coalitioninc.com ) and we will continue to add more features and more tools for free there. If there are any questions,I am…

Thanks balgan!

* Do you know if there are any follow up meetings planned? Did they discuss some kind of process?

* what were the main concerns discussed?

* interesting to find out about the coalition (I was briefly involved in a similar insurance setup in my home country). Is your ‘baseline’ derived from some standard? Can I find it online?

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#44
post #43
post #33

Director of Engineering - Security from Coalition here (we participated in the event) - We committed to building more free security tools for all organisations to protect themselves. We’ve already made Coalition Control our Attack Surface discovery and monitoring platform free ( https://control.coalitioninc.com ) and we will continue to add more features and more tools for free there. If there are any questions,I am…

Thanks balgan! * Do you know if there are any follow up meetings planned? Did they discuss some kind of process? * what were the main concerns discussed? * interesting to find out about the coalition (I was briefly involved in a similar insurance setup in my home country). Is your ‘baseline’ derived from some standard? Can I find it online?

Hey

Yes the group will continue to meet and I believe more will come out overtime as we start to better define how we as private entities can help the gov.

Ransomware and attacks on critical infra were the big ones - Joshua our CEO wrote a bit about it here https://www.coalitioninc.com/blog/coalition-meets-with-presi...

- our baseline is internal. We are with our customers end to end. From selling the policy to scanning them, notifying them and we have our own incident response team which means that we learn a lot with every claim. So when we add a vulnerability in critical state in Control you can assume it came from learnings of losses combined with our cybersecurity expertise.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#45

Earlier quoted context omitted.

I'd be a lot more interested in an id system that was controlled by the individual rights holder: a verified system granting or revoking access to their data. Individuals have far more incentive to protect their data than state apparatus.

login.gov would be great for this, with the obvious caveat being that it ties a persistent user identifier to sites you login with. Maybe there could be two login flows - one that generates a unique pseudo-identity for each service, and another that actually beams over your PII for identity verification purposes.

I'd really like to see a data permissions system that was outside government controls, no idea how that could happen though, definitely not globalist corporate controlled

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#46
post #44
post #43

Earlier quoted context omitted.

Thanks balgan! * Do you know if there are any follow up meetings planned? Did they discuss some kind of process? * what were the main concerns discussed? * interesting to find out about the coalition (I was briefly involved in a similar insurance setup in my home country). Is your ‘baseline’ derived from some standard? Can I find it online?

Hey Yes the group will continue to meet and I believe more will come out overtime as we start to better define how we as private entities can help the gov. Ransomware and attacks on critical infra were the big ones - Joshua our CEO wrote a bit about it here https://www.coalitioninc.com/blog/coalition-meets-with-presi... - our baseline is internal. We are with our customers end to end. From selling the policy to scann…

Nice feedback loop you have there! (re last point). If you can point to the actual proven ‘indicators of risk’ instead of flagging every potential issue onder the sun, everyone is going to love you!

I look forward to a summary report on incidents somewhere in the future ;)

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#47

"Cybersecurity" = Companies must coordinate more closely with the national security state Doesn't sound so nice when you put it like that.

That is one of many ways to address these issues. The underlying problem that needs to be resolved is that the average security posture of most companies is bad and we (US citizens and anyone else vested in the economic well being of the US) need to do better.

Sadly, incentivizing people and organizations isn't always good enough--technical hiring is difficult for most orgs to begin with, the market for technical security specialists is smaller than that of software engineers, and good security is an ongoing business function.

Fixing this at a systemic level will take a broad variety of initiatives: some governmental, some driven by insurance/liability frameworks, and initiatives (government, industry, or social) to encourage more people to get into security.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#48
post #17

We're getting closer and closer to cyber and kinetic warfare intermingling regularly. Attacking a US company may become akin to attacking a US citizen. State backed or State sanctioned actors will be looked at as an agent of the state itself. Hacks will lead to proportional responses from governments against governments. It's not much different than our military and contractors protecting domestic oil company interes…

What do you do in the case the actor is using a weak state as cover? Send a surgical strike into a country that aside from having the presence of the bad actor had nothing to do with it?

This will be an unpopular opinion, but I would require all allied countries to enforce bcp38/rfc2827 to prevent spoofing. Any country not adopting this would be null routed by all other countries. When a country does not police it's own traffic to make a serious effort to stop known criminal entities, all other countries would null route or remove BGP advertising the IP space of that country until they got their act together. This would create some financial incentive to take out the trash. The null routes or filtered BGP advertisements would be temporary unless a country repeatedly violates policy. This puts the onus on each country to take crime seriously in their own jurisdictions. Side stepping the blocks would result in sanctions as a starting point. I do realize and acknowledge this could potentially lead to privacy issues, as countries would have to enforce identity to at least get internet transport level access. There is also the matter of corruption.

Within a country, the same methods would be enforced. If for example, T-Mobile allowed unfettered abuse of its pre-paid wireless cards as they do then the countries they reside in would de-list them from BGP advertisements. The government would have legal immunity in doing so. Or if AWS, DigitalOcean, Linode, OVH, etc... allowed people to abuse their VM's, same deal. De-listing might start with a region then become global depending on the level of abuse and how seriously the company responds and takes action to take out the trash.

In my humble opinion, anything short of this would just be meaningless political posturing and the problems would continue to grow and escalate.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#49

Real security is being able to run any program against a set of data, and knowing for certain that there won't be any undesired side effects. What systems can do that?

What are you even talking about?

In the 1980s we used to be able to buy "shareware" floppy disks for $3 at user group meetings. These things had all sorts of cool stuff on them. We didn't have to worry about our computers being permanently damaged, because back then, unlike now, our operating systems were on write protected, easily copied floppy disks. Our hardware wasn't smart enough to house any trojan horses, so you knew it wasn't at risk.

We had computer security. Not because MS-DOS was such an amazing piece of code, but rather the hardware was simple enough that you couldn't hide a trojan in it.

The job of an operating system is to protect the hardware, and allow the user(s) of a system to use the resources without risk. NONE of the current crop of operating systems we use 40 years later is suitable for the job, not Linux, Windows, MacOS, iOS, Android, the cloud.

Now that even the cheapest persistent storage is likely to have multiple levels of firmware, it's up to the operating systems to virtualize the hardware, and keep applications from directly touching it. NONE of our current crop of systems do that.

All this "cybersecurity" spending is just a grift if it doesn't deliver actual computer security.

Re: U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

#50
post #9

One area the US government could really make a difference in cyber security is making identify theft more difficult. Currently all you have to do to defraud banks is get your hands on some government issued numbers (social security numbers and driver licenses). If the government created an identify system that was no so easy to impersonate, some types of hacking and data leaks would not longer cause problems to the p…

Given the push to have vaccination passports and people not pushing back hard on that aspect of privacy, probably pushing through a digital national ID might be as ripe as it’s ever going to be.

I think a regular national ID was attempted under the Obama administration but failed due to pushback, if I'm remembering correctly. The closest we got was Real ID, passed in 2005, which is barely being implemented fully now, over 15 years later.

It makes me wonder how long it would take a true national ID system with digital verification, maybe something similar to Estonia's, to take to actually implement. It would have to be something not left to each state to handle, or it'd suffer the length and per-state disparities of Real ID.

Post reply on HN