Live data from Hacker News

U.S. Senate to probe whether legislation needed to combat cyber attacks

reuters.com

51–60 of 66 posts

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#51

Earlier quoted context omitted.

If the colonial pipeline hadn't paid the ransom there would be pandemonium on the east coast as people were forced to ration gas. I don't see how that helps. As long as computers exist they will be hacked. Spending more on security can help but can't stop it.

Colonial Pipeline ended up restoring data using their own backups anyway. They paid $5 million dollars for a decryption tool that was so slow that their own IT team was able to restore service sooner. https://www.bloomberg.com/news/articles/2021-05-13/colonial-...

The article says they used backups to help restore the system. That tells me that the backups weren't fully up to date, and that the missing info was worth 5 million.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#52

An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

Companies could just use intermediaries, transfer the money to somebody that transfers it to the hackers. They could even do it fairly openly: They're not paying "ransom", they're paying a "consultancy fee" for assistance in dealing with the issue.

That's not to say it shouldn't also be made illegal or in some other way difficult to pay (they could, for example, ban crypto currency use for the purpose of paying ransoms, or whatever-- just tossing out ideas)

Banning ransoms alone isn't going to work. Companies already have liability for things like customer data breaches, and that hasn't eliminated them. We also need some sort of legal framework-- especially for large pieces of infrastructure-- for defining appropriate security procedures that must be followed. Also tie it to the ability to get government subsidies/grants etc. That's how it works in Higher Education: If colleges don't adhere to to DoE regs, they simply can't accept financial aid money given to students by the government. It's actually something that's audited with fines levied on a regular basis. Few schools if any ever lose the ability to get aid, but that's because the regs are enforced and fines are high enough to hurt.

Really though I don't think you can stop this completely. We might say "every company can afford to get security right" etc., but they won't: Some will barely even try, others will simply be unlucky and out of 3,000 employees, one will slip up. The nature of this sort of attack is that on defense, you have to be 100% successful all of the time or you're done, and always having a perfect record is not a realistic expectation for all organizations.

The problem is that for the hackers, this is a low risk, inexpensive, high reward process. As much as security has to improve, so does that equation. If there was a physical attack that shutdown the pipeline it would easily be labelled an act of terrorism, and these should be seen the same way, with the same level of resources used to go after anyone involved in these attacks.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#53
Maybe they can fund improving of standards and, for example audits of widely used open source projects. Also some give some protection for people who find vulnerable systems: legal threats should not be an acceptable response to reporting security issues. I understand that the government is interested in having security holes to exploit, but you need to choose. A program to fix municipal and state IT systems security should help too.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#54

Earlier quoted context omitted.

I think it would just give CEOs who want to do the right thing (and not pay) legal cover to tell the board of directors "Nope, not paying — the company is going to be shut down for a month. Deal with it, I'm not going to jail."

And it would give CEOs who want to do the wrong thing an avenue to destroy competitors under the table.

This has always been true... and always been illegal.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#55

An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

I don’t think criminalizing the victims recovery attempt is the best way to solve this.

Compare this to a street crime: One might say that muggers would be deterred if it were illegal for their victims to cooperate; if you have to fight back instead of handing over your wallet. But, at what cost for the victims?

If we don’t think that companies are doing enough to protect their systems, then we should pass laws that require certain demonstrable standards at all times. We shouldn’t wait for them to become a victim before the law requires them to do anything. It’s too indirect and situationally unaware of a solution.

I think laws should be written so it’s easy to know when you’re in compliance, and easy to know when you’re not. “Don’t get hacked” is basically an impossible moving target, particularly for small organizations. “Follow these best practices” is a much more reasonable standard. And we already have government organizations that put together standards for this, all lawmakers need to do is cite them.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#56
post #39

Earlier quoted context omitted.

I think it would just give CEOs who want to do the right thing (and not pay) legal cover to tell the board of directors "Nope, not paying — the company is going to be shut down for a month. Deal with it, I'm not going to jail."

What if it was more than a month? What if it was.. permanent?

Then they totally failed at continuity planning, backups... a whole lot of things.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#57
post #28
post #11

Translating to plain language: bureocrats are evaluating the possibility to ban encryption and cryptocurrencies under the veil of combating cyber attacks.

I mean cryptocurrency is indeed what made ransomware possible.

To be frank, it was the invention of bridges that enabled most of the crime. Bridges and round wheels. Humans lived happily in harmony with nature before that.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#58

Legislation is required to reverse the posture of the NSA from offense to defense. Nothing else will help until that is done.

NSA’s posture has been both for at least twenty years. They have separate divisions and everything.

The US federal government have been spending 90% of their cyber security budgets on offense and only 10% on defense[1].

Practically speaking, what more could legislation and budget increases require of the US federal government to increase spending on defensive measures? Some ideas (without judgement on the pros and cons):

* Educate: produce more hardening guides and product-specific educational material more often for more products.

* Invest: run free or heavily subsidized training courses and conferences, provide sought-after internships, fund more academic research, fund open source project security improvements.

* Develop: produce new standards, produce new open source software products (previous examples: SELinux, Ghidra, etc) and encourage their uptake.

* Detect and advise (software developers): reverse engineer, fuzz, debug and find vulnerabilities in software products and advise developers immediately of any security issues discovered.

* Detect and advise (network end users): scan all US Internet Address ranges for not so much vulnerabilities, but bad practices or misconfigured and/or weakly configured services. For example, scan for and detect domains with an e-mail service that doesn't support DMARC, then send advisory notices to the operator educating them on the benefits of implementing better security for the service. For example, scan for and detect home security cameras that are exposed to the Internet with default passwords, then send advisory notices to the owner suggesting they secure their home security cameras.

* Increase domestic surveillance: tap international and domestic exchanges and/or require "metadata" to be recorded in bulk to allow an instruction detection system to be created across the entire country, allowing better visibility and traceability of incidents back to their origin, and the ability to advise private companies of incidents at the earliest possibility.

* Increase international surveillance and offensive measures: more aggressively hunt down, monitor and disrupt international cyber crime groups.

I would argue most of the above with the exception of investment and some limited development and detection/advisory are unlikely to have much impact due to:

* Historical issues of Dual_EC_DRBG[2], NIST elliptic curve rigidity[3] and other involvements with standards organisations and groups have all but burnt any bridges that used to exist. Standards organisations and implementers are highly dismissive of contributions from the NSA and NIST as neither organisation are trusted.

* Increased centralisation of Internet infrastructure into Amazon EC2, Microsoft Azure/Office 365/Teams, Google Cloud/Google Docs/Gmail/etc, etc allows attackers to easily launch an attack within the same data centre as the target. Vendors such as Amazon, Google and Microsoft are now solely in control of the ICT operations of massive segments of the US economy and end users just have to trust these vendors with much reduced ability to control and audit security of the service provided. As a result of increasing centralisation, there is little investment occurring in "on-premises" solutions including e-mail gateways, VoIP systems, document storage system, etc.

* Increased reliance on transport over Secure HTTP results in raw network traffic revealing less and less information on possible intrusion attempts (all traffic starts to just become TLS connections from A to B and it is much harder to ascertain from an outsider perspective whether that traffic is suspicious or not).

[1] https://www.reuters.com/article/us-usa-cyber-defense-idUSKBN...

[2] https://en.wikipedia.org/wiki/Dual_EC_DRBG

[3] https://safecurves.cr.yp.to/rigid.html

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#59

Legislation is required to reverse the posture of the NSA from offense to defense. Nothing else will help until that is done.

What would a defensive NSA look like? I picture them openly accessing all US networks claiming they were "boosting defense" rather than secretly infiltrating them.

The NSA has a lot of resources at their disposal. If they wanted to, they could be like a better version of Project Zero: https://googleprojectzero.blogspot.com/p/about-project-zero....

I think the only issue would be maintainers too suspicious to accept patches from the NSA.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#60

An unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)

The same could be achieved by banning the formal exchange of cryptocurrencies in the USA.

If you can't buy the coins, you can't pay the ransom.

Post reply on HN