Live data from Hacker News

U.S. Cities Strain to Fight Hackers

wsj.com

51–60 of 119 posts

Re: U.S. Cities Strain to Fight Hackers

#51
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

(Forgot to respond to part about a government organization to get secure products out. Here's response to that.)

It's been done before. It was the Walker Security Initiative. It resulted in some of the most secure products the market ever produced. A combination of lobbying for insecure products to be bought and NSA's actions destroyed what little there was to the market. Bell describes it:

http://lukemuehlhauser.com/wp-content/uploads/Bell-Looking-B...

Just found a link with examples of what they were doing. I haven't read this one fully, though. Linking it mainly because it talks about CSI and how market was responding.

https://csrc.nist.gov/csrc/media/publications/conference-pap...

Here's some of the designs that came out of commercial sector of high-assurance security:

http://www.cse.psu.edu/~trj1/cse443-s12/docs/ch6.pdf

http://lukemuehlhauser.com/wp-content/uploads/Karger-et-al-A...

https://cryptosmith.com/mls/lock/

https://www.researchgate.net/publication/3504794_The_Army_Se...

http://cap-lore.com/CapTheory/upenn/

Note: I don't think KeyKOS itself came from that community. It was from capability-security field. KeySAFE extension was driven by TCSEC requirements, though.

http://webapp1.dlib.indiana.edu/virtual_disk_library/index.c...

Note: Although not first attempt, Trusted Xenix was first attempt at securing UNIX that made it to market. Available from 1990-1994 I think. Coincidentally, OpenBSD starts in 1994 to go even further.

Re: U.S. Cities Strain to Fight Hackers

#52
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going through every machine, all the software, all the systems. These people are never going to work for Baltimore or for Maersk, not in a million years.

Why not? Just 80 years ago, people would have laughed at you if you told them that computer techs would have stores everywhere, every 1st world household would have more than one, and that most office jobs would require some form of basic computer literacy. Just 150 years ago, cars everywhere, owned by most everybody, with everybody capable of taking a 100 mile trip on a whim, would have sounded like Utopian pie in the sky fiction. I'm sure someone said there's no way the everyday Joe and Suzy would be able to maintain a car. In the Ford Model A days, some people would hang a bulb of garlic under the hood to "cure" their car.

A few things could happen, analogous to the progress made by cars and also analogous to what's happened so far with computers: 1) The "packaging" will change, so that higher levels of security maintenance will be greatly simplified and more accessible. (Which might mean that everything is administered centrally to an even greater extent. i.e. Stadia and O365. Maybe O365 over something like Stadia?) 2) Security tools will advance. (SSH vs. Telnet, HTTPS vs. HTTP, and TFA have raised the bar for an exploit.) 3) The culture will become more computer savvy.

It's understandable that you're frustrated, because this sort of progress is going to have a generational component, which is orders of magnitude slower than technological progress.

Re: U.S. Cities Strain to Fight Hackers

#53
I'm painting with a broad brush here, but a lot of government employees do as little as possible. They are union protected, so they can stay in their jobs for a very long time. So you get a lot of the thing in IT where someone has 20 years of 1 year experience. I'm sure the budgets aren't great and the rest of the government isn't pushing tech, but you end up with a lot of 'it works fine just leave it as is'

Re: U.S. Cities Strain to Fight Hackers

#54
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

That just perpetuates the problem. Smaller cities don't have the financial wherewithal to competently run internet-facing services. Usually the best administered parts of a city are in police departments where sworn officers are filling IT roles, aided by injections of grant-driven projects done by consultants. That's not a good situation for anyone. The winning move is not to play. I regularly hire people from citie…

Usually the best administered parts of a city are in police departments where sworn officers are filling IT roles, aided by injections of grant-driven projects done by consultants. That's not a good situation for anyone. The winning move is not to play.

How about turnkey police department SaaS, delivered over a separate network over low orbit satellite connections? That will be separate from the public-facing police SaaS apps.

Re: U.S. Cities Strain to Fight Hackers

#55
post #47
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

"any organization that is not tech first" Then why do all the tech first companies keep getting hacked too?

They're not that much harder to hack, and they have more tech to hack. It's just that your dusty old city desk is even more hopeless.

Re: U.S. Cities Strain to Fight Hackers

#56
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

Can we partially blame IBM?

Every municpality I've worked for runs a majority of their systems on the IBM System i (iSeries, AS/400)

IBM is very slow to update any of the tools for Windows that are included with these systems. Ditch the green screens, use the IBM EasyAccess or whatever they call it on Windows, you just saved some $.

Now, there are database tools and admin utilities that are also included in this. Most of them don't work with anything after Windows XP, so you're in a position where you can't upgrade to securable versions of Windows, because you'll lose IBM access.

Re: U.S. Cities Strain to Fight Hackers

#57
post #27

Could someone suggest recognized and useful certifications, for those interesting getting into cybersecurity? The article has a link to another mentioning CompTIA and CISSP, are they any good?

CISSP is good for getting hired. I'm not sure it proves much about your skills, so much as your vocabulary.

Re: U.S. Cities Strain to Fight Hackers

#58
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

Can we partially blame IBM? Every municpality I've worked for runs a majority of their systems on the IBM System i (iSeries, AS/400) IBM is very slow to update any of the tools for Windows that are included with these systems. Ditch the green screens, use the IBM EasyAccess or whatever they call it on Windows, you just saved some $. Now, there are database tools and admin utilities that are also included in this. Mos…

We can partially blame every software vendor that’s ever existed. In 10 years we will be blaming Google for applications that only run on outdated versions of Chrome because the API the developer used only existed in Chrome and wasn’t accepted into the standard and then was removed a few years later.

Everyone does it and everyone will do it.

Re: U.S. Cities Strain to Fight Hackers

#59
post #6

Replace "cities" with "any organization that is not tech first" and you'll still find hundreds of win 7/vista/xp machines that have never been patched, and ad-hoc network closet/cloud hybrid rigged solutions for everything. There is literally no way to fix all this dumb fragile infrastructure without a massive government program that accepts responsibility for doing so. You need thousands of smart people going throug…

> Then hopefully pillage all the miserable smart people who are currently working at mega corps and agencies who actually want to do positive, meaningful work for a change.

Oof, if you think being a smart technical person working at a megacorp is worse than being a smart technical person working for a government agency... I have no idea what your model of the world and labor market is.

Re: U.S. Cities Strain to Fight Hackers

#60
post #10

Earlier quoted context omitted.

"any organization that is not tech first" - thats pretty optimistic looking at a number of the tech first companies that have being breached.

I don't know why you got downvoted. I know plenty of companies with modern tech that absolutely suck at security. Security is just hard, and it's not easier just because you're a tech company. By comparison, if you spend billions of dollars on a modern building, I can still probably break into it with just a can of compressed air. I doubt the design plans for the building included "mitigate compressed air attacks", a…

> Security is just hard, and it's not easier just because you're a tech company.

We're not talking about everyone having Red Teams here. We're talking about keeping up to date with regards to Patch Tuesday, or even just having an OS that still actually gets patches. That'll get us 80-90% of the way to decent security:

> “Almost two months passed between the release of fixes for the EternalBlue vulnerability and when ransomware attacks began,” Microsoft warned. “Despite having nearly 60 days to patch their systems, many customers had not. A significant number of these customers were infected by the ransomware.”

* https://krebsonsecurity.com/2019/06/report-no-eternal-blue-e...

Post reply on HN