Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

431–440 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#431

Earlier quoted context omitted.

> I'm pretty much at the point of thinking people need to learn how to write on paper and whiteboards again. Health IT here: won't happen. You need your CT NOW. The patient is about to be opened. There is no time to wait for the printer and it's Sunday night. The radiologist is at home examining the data while the scanner runs. And man...security is so bad and it's so hard to convince management to invest into proper…

Well, that's the scariest thing I've read all week. Just reading your level of stress between the lines here gives me the chills. Why is it so hard to convince them to take security seriously? Especially with hospitals, this should be a national security issue. The consequences are right in everyone's face now. In my case, an attack might be expensive, even dire, but no one would die. I know why I have a hard time pu…

It's hard because "we've been doing it this way all the time and nothing happened" is what I hear most of the times.

Most of the times I still "sneak" in improvements where I can without disturbing operations but the whole thing needs a proper overhaul and it always is, as we say here: "a dance on the razor blade".

What I hear from other colleges and contractors in the sector: it doesn't look better there. I don't want to leave out that there is a certain amount of IT personal which is responsible for it too. Most of them older guys (yes...they really are all guys) who also follow the mantra I mentioned above.

There is hope though...there is a certification requirement coming up here in Germany. It covers most of the basic security measures. We fail to cover a significant part of it. We've just passed one of the deadlines. Two are coming up and than there is a certification process. I've presented management with the measures we'd have to take to fulfil those. They've been ignored. The whole issue is being actively ignored or played down. The day will come when it'll be too late and I wonder what will happen. Wouldn't be surprised if I lose my job about it since somebody will have to be blamed or the certification issue will be "made to work out" somehow. Seen that happening before.

Re: US companies hit by 'colossal' cyber-attack

#432

Earlier quoted context omitted.

Would you rather have a government agency assign credit scores? The abuses would be rampant. Right now there is one party openly pushing to restrict voting access to people who are likely to vote for the other party, and a few years ago that same party enacted a new tax code that almost surgically penalized the residents of states that supported the other party; do you really trust such politicians to set up a fair c…

>Would you rather have a government agency assign credit scores? The abuses would be rampant. Do you think the abuses are any less rampant when power is privatized? The main problem that would be solved by a government institution is a pathway for transparency and citizen recourse against questionable practices. It's admittedly not a lot of transparency or accountability but it can be far more than currently exists.…

Yes and: Since contractors aren't subject to FOIA, privatization is a time honored strategy to move activities off book.

Re: US companies hit by 'colossal' cyber-attack

#433
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

Honestly, I'm shocked by this comment. As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market. SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time). Insurance is a trap. once you read the small letters, they don't fully cover the damage, us…

How is this comment shocking to you? I actually was using the stock price and public information on their earnings to make a point. The point being that no, these companies aren't losing customers in droves and if you look at their performance from a 3 or 5 year perspective, most breaches have had very little material impact on the companies.

I disagree with you on SolarWinds being fucked... Sure, lots of folks are going to drop it, but they are closing new deals. The types of people that buy things like SolarWinds aren't buying the products because its a good technology.

Not sure what insurance you have been looking at, but many of the larger businesses will essentially write out what they want covered (for example IR, infrastructure replacement due to hacking, business loss due to downtime, professional service implementation, support, PR assistance, etc.), and then the insurance company will come up with a price based on their calculations of risk.

Sure, if an SMB goes and gets a "cyber policy" they are gonna be lots of technicalities, just like a mass market homeowners policy.

Re: US companies hit by 'colossal' cyber-attack

#434
post #322

Earlier quoted context omitted.

If the software used a one-way protocol, then unless you updated the closed-source agents, which are the parts I have the biggest issue with, there wouldn't be RCE. As for remote management. I'm saying you should wisely choose what needs to be remotely managed, what doesn't, what are the foundations for your security and then balance it with reasonable methods to secure access. Which would probably not be "Kaseya VSA…

So, now you have one hardware key that you have to manage either for all networks and therefore is both a single point of failure and constraint on availability, or you need to manage multiple keys with the ensuing chaos. Kaseya was hacked through a patch so the type of protocol does not matter and you are trading convenience for management overhead that you have to deal with because all of your clients and likely ma…

What are you actually arguing for?

For the record, I think none of your points apply.

Re: US companies hit by 'colossal' cyber-attack

#435
post #309
post #279

Earlier quoted context omitted.

Ransomware is not an innovation that came as a result of cryptocurrency, it was just accelerated by it. If you kill cryptocurrency, I guarantee the only thing it will do is increase the amount of the average ransom, because they will be harder to pay and to receive. Also, ransomware is a drop in the bucket compared to other attacks like business email compromise, which often go unreported.

You might be invested in crypto. But that should not prevent you from seeing simple reasons and accepting that crypto helps crime. Would you?

Yes, I am invested in crypto, and yes, I agree that crypto makes some forms of crime easier. There is no denying that, but I stand by my opinion regarding ransomware. Ransomware does not exist because of crypto, it's just the method of payment. If crypto goes away, then the method of payment will become more complicated, which in turn will likely make the ransoms higher, and the turn around times slower.

Re: US companies hit by 'colossal' cyber-attack

#436

Earlier quoted context omitted.

If you screw it up with a building or a bridge, you might go to jail, and we as a society are fine with that. Why not in this case as well?

It is 100% possible to be really good at InfoSec, do everything right, and still be breached. I think there’s a (very simplistic) view of IS, where it’s a black and white process of just engineering everything ’correctly’. It’s not like that in the real world…

Nobody is saying you should go to jail or get fined for getting owned by a 0day. I don't think that it is unreasonable to say that someone is negligent in having a CVE from 2014 unpatched, which then allows your customers to get compromised.

Re: US companies hit by 'colossal' cyber-attack

#437

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

Fun fact: the word “security” comes from the Latin word for carelessness - “securitas.” se = without, curitas = care.

Re: US companies hit by 'colossal' cyber-attack

#438

Earlier quoted context omitted.

Would you mind briefly explaining the concept of "tech debt" to a layperson?

First we have to ask, "why does programming get harder as the project goes on?" Let's say you are designing a system - any kind of system - with the philosophy that everything should be connected to everything else. Your first part goes in quick with no connections. Your second part goes in quick and has one connection. Your third part has to be connected in two places for it to work right, but that's not a problem.…

I intend to add it to my quotes collection.

Should I attribute you or someone else? :-)

Edit: added as a private bookmark to pinboard with tags:

  technical_debt quotes by:whatshisface

Re: US companies hit by 'colossal' cyber-attack

#439

Earlier quoted context omitted.

Would you rather have a government agency assign credit scores? The abuses would be rampant. Right now there is one party openly pushing to restrict voting access to people who are likely to vote for the other party, and a few years ago that same party enacted a new tax code that almost surgically penalized the residents of states that supported the other party; do you really trust such politicians to set up a fair c…

>Would you rather have a government agency assign credit scores? The abuses would be rampant. Do you think the abuses are any less rampant when power is privatized? The main problem that would be solved by a government institution is a pathway for transparency and citizen recourse against questionable practices. It's admittedly not a lot of transparency or accountability but it can be far more than currently exists.…

Did I say anything about communism? No, that is what you brought up. I mentioned possible abuses that are specific to a government agency, abuses that are the result of politics.

There is no reason to think that a government agency would be any more transparent than Equifax et al. are right now. Consumers have the right to receive a free credit reporter from these companies, and the right to dispute information in that report (also free). Maybe there is a need to adjust the regulations in order to combat particular abuses or problems that are happening right now. That does bring up the question of what specific abuses you would like to see fixed -- you did not actually mention anything in particular that Equifax is doing or how a government agency would avoid such a problem.

The previous president spent 4 years trying to use government agencies to punish political opponents, and just before leaving office he filled those agencies with loyalists in an attempt to sabotage his successor, all without regard for the effect such actions might have on the public. Those are forms of abuse that is specific to government agencies and it would be a disaster if it happened at a credit rating agency. This is not an argument that the government is always worse than the private sector; it is an argument that when it comes to something like credit scores the government should not be in charge.

Re: US companies hit by 'colossal' cyber-attack

#440

Earlier quoted context omitted.

A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…

Fun fact: the word “security” comes from the Latin word for carelessness - “securitas.” se = without, curitas = care.

That actually makes sense to me. If I feel secure, I feel carefree. Maybe there should be a different word when providing a secure environment from the word where people enjoy that secure environment.
Post reply on HN