Live data from Hacker News

U.S. to give ransomware hacks similar priority as terrorism, official says

reuters.com

481–490 of 591 posts

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#481

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Crime is a social problem but the US government is especially bad at fixing crime that originates from other countries. See war on drugs, terrorism, call center scams etc. On the other hand, a good team of security experts is very good at preventing computer systems from getting hacked into.

The problem with drug cartels does not originate from other countries. It is domestic demand, paying in dollars. Those dollars overwhelm local economies and police forces abroad.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#482

This is just DOJ, so far. If ransomware gets defined as terrorism for the US anti-terrorism community, it could become very dangerous to be in the ransomware business. The US has a huge anti-terrorism operation in being, and it's not that busy. Islamic terrorism against the US has been confined to minor local nuts since the US wiped out Bin Laden. And, before that, being "#2 in Al Queda" meant having a rather short l…

I don't really see how this designation helps stop hackers based in Russia, China, Iran, North Korea, etc...

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#483

Earlier quoted context omitted.

Surely you mean lock files not package jsons?

Oops, that's the big one. Maybe it's fine for that to be inhumanely large, as merely an artifact? Bad example then, but the point stands.

Well the package.json only specifies the top level dependencies not all of the dependencies in the tree. So the .lock is probably a better representation of the actual dependency tree. It's not uncommon to include one library and get an extra 10, 20+ dependencies you don't even know about unless you care enough to check.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#484
post #45

Earlier quoted context omitted.

I'd rather not see taxpayers have to foot the bill for the profit of megacorps neglecting proper cybersecurity while sitting on mountains of tax-evaded offshore cash, thank you. The industry should be magnitudes larger than it is currently, and we shouldn't encourage corporate recklessness by socializing the costs.

If other States sent proper Armies over to attack critical infrastructure the US government would surely foot the bill to aid in security. Why should cyberarmies be treated more leaniently?

Defending the borders of a nation and making every corporate campus a green zone are different things with different logistics.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#485

Earlier quoted context omitted.

Agreed. I'm a bit tired of the victim blaming with security. It's physically impossible to build a house that can't be broken in to, and even harder for computer systems. Crime is a social problem, we can't rely on a dream world of mathematically perfect zero trust security.

Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is. Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world. I despise seeing simple apps with ridiculous dependency trees (package.json with line counts…

> the more material you put into your house, the less vulnerable it is;

After following the lock picking lawyer on youtube for a while, it seems to me there is a fallacy somewhere in here.

The weak points of a structure are often underestimated to begin with and adding complexity to the building (eg. door badge system vs. a good padlock) doesn't necessarily add security.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#486
post #346
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

> I'm surprised at how dismissive the comments are. I've gotta ask: has the US's stance on terrorism been effective? Or did they merely use it as an excuse to militarize the police and erode human rights? Because I want the government to take effective action around ransomware, but "similar priority to terrorism" just doesn't fill me with hope.

Giving it similar priority does not mean using similar methods. Hopefully..

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#487

Earlier quoted context omitted.

> even if we ignore China's likely response China is literally the only reason the US tolerates North Korea. And China solely tolerates North Korea because it causes all sorts of irritation for the US. Arguably, it would be better off for everyone living in North Korea if one of those two powers annexed it outright, but geopolitics loves backwater proxy wars.

> China is literally the only reason the US tolerates North Korea. Closer to the active phase of the Korean War, the USSR was also a factor. Today, the US distaste for instability, and naiton-building, and North Korea not having a hoard of oil or something similar to overcome that distaste is also a reason, today.

This is strained reasoning. The threat of war with China and the literal guns pointed at millions of heads in South Korea are what prevents the US from picking off DPRK infrastructure and personnel. Compare to Iran if you doubt.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#489

Earlier quoted context omitted.

It's impossible to build a safe airliner, but we can get pretty damn close. Airline engineers know one cannot create a component or system that cannot fail. So the question then becomes, assume a system fails. Now how does the airplane survive? With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that f…

I don't think this is valid comparison. If you are trying to compare software on a plane to application, then airplane software is not attempted to hack into due to it being generally well isolated from outside networks. If you are comparing physical build of systems in a plane to software, then hacking of software is equivalent to bird or drone running into an engine or a laser attack or hijack attempt... Which whil…

At the risk of putting words in their mouth, they are comparing the method of airplane safety, where they look at redundancy (assume X will fail and the plane needs to survive this), looking at system solutions over individual fault (redesigning a warning indicator so pilots cannot miss it rather than blaming individual pilots that do miss it), and a regulatory body of investigators that enforce standards and investigate failures with the aim of learning from them and improving practices. You are thinking about the specific resulting design choices rather than the system that led to them.

Re: U.S. to give ransomware hacks similar priority as terrorism, official says

#490
post #188

I'm surprised at how dismissive the comments are. We need many angles of defense against these criminals. Dismissing this because companies should do better security is like dismissing doctors because people should get more exercise. That's silly. We need preventative care and treatment. I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was notice…

Imagine if all companies had to individually fight pirates in the heyday of pirate hood!

That's exactly what happened.

Ship owners invested in arming their ships to the point where the pirates would hopefully pick softer target which is exactly what they did. Incrementally over the 16th-18th centuries the profitability of piracy was highly reduced because the goods had fairly fixed relative value and the risk kept going up and it more or less went away on its own in the Western hemisphere over the course of the 18th century. Crime rarely pays at scale when every instance carries a high risk of a firefight. A few may make a good living in such an environment but it caps the maximum industry size at a very low level.

Piracy persisted in the Mediterranean where it was more or less a state sponsored activity. They mostly avoided harassing the commerce of major powers (Britain, France, etc). Which worked well enough until the 2nd tier powers got pissed off enough to stomp them a few times (with the blessing of the first tier powers, think of it like a reverse Falklands). They still didn't tone it down sufficiently and they wound up speaking French for that mistake.

If anyone has any good resources on the history of Indian ocean or east Asian piracy I'd be interested in reading them.

As an aside, old school high seas piracy is an surprisingly good parallel to the variations of criminals in the current cyber-crime environment. You've got state sponsored theft of money and goods (privateers). You've got under the table cyber criminals who would be prosecuted by their home jurisdiction if found (traditional western pirates, the kind you typically see portrayed in pop culture). And you've got locally approved as long as they pay their dues professional cyber-criminals (north african pirates). The former groups mostly steal things of value they can use or fence. The latter mostly takes stuff hostage for ransom.

Post reply on HN