The government should make it a criminal offence to pay a ransom to hackers. Just as with kidnappings, when you pay ransoms, you reward the criminals.
U.S. to give ransomware hacks similar priority as terrorism, official says
521–530 of 591 posts
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#522Earlier quoted context omitted.
> The incentives are all misaligned and the solutions aren't obvious. How is the USG going to secure some random admin access password? Are they going to update the code in the repo? They can publish best practices, research vulnerabilities, provide educational support, and generally do all the kinds of things governments do to encourage the right behaviors. We have some of this, but at some point, switched to the se…
It makes me wonder there the offense is. Where is the asymmetric response that sends a clear message not to do this again?
How are we going to handle the calls from very angry officials in Ukraine, Belarus, Poland, Hungary, Slovakia, the Czech Republic and Germany?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#523Earlier quoted context omitted.
yeah of course it's an analogy. But by adding liability we'll get more recalls (patches) done. Vendors will stop playing FUD and will focus on the real cost of their security flaws. And yes some will still not do patches, just like some car vendors are considered less trustworthy. But at least the risk of suit will loom over their heads.
But the parent's point is that's still putting the liability on the vendor rather than the actual criminal. Perhaps it's more like if a car is sold without an immobilizer or an alarm, holding the manufacturer liable if it's stolen. But if that kind of fails, because it's pretty simple to mandate a handful of security additions to cars, whereas software is orders of magnitude more varied and complex. It would be hard…
My point is this If vendors were liable (at least in part) for security faults in their products, then they would be more diligent about closing those gaps.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#524Earlier quoted context omitted.
IMO the first step to fixing is to add liability. If a breach happens through a piece of software, then the vendor is liable. Same way cars get recalls. (sometimes)
Liable in what way? Wouldn't that just kill OSS? Or do you not count programmers who upload swiss-cheese scripts to Github as vendors? What about Linux, openSSH, etc?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#525Earlier quoted context omitted.
Oddly enough though, the analogy tends to diverge when scaled: the more material you put into your house, the less vulnerable it is; the more lines of code you put into your software, the more vulnerable it is. Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world. I despise seeing simple apps with ridiculous dependency trees (package.json with line counts…
> but nobody can exploit hello world If I may quibble over a technicality, hello world is just one layer of an already complex technology stack. Suppose someone was able to slip code somewhere deeper in the stack such as your printf implementation (which generally a programmer will, and should, trust just works like it's supposed to) that opened a C2 channel. Then when you run your innocent hello world program, you'r…
Your comment speaks to exactly how people underestimate the true attack surface. It's far more vast than most anticipate, and their conception of it tends heavily towards the literal surface.
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#526Earlier quoted context omitted.
> For example, software is still stuck in the dark ages where the idea is better training / better programmers / more punishment will prevent these sorts of failures. What is your source on this? This goes against what anyone at any company where I have worked at ever believed. No-fault root cause analysis, process improvements, inherently safer practices, languages, libraries is what every place aimed for. I don’t e…
> What is your source on this? See "Trust the programmer" https://beza1e1.tuxen.de/articles/spirit_of_c.html Also, a general belief among C++ programmers that better training is the answer to programming bugs. This belief is slowly fading, but it's got a long way to go. Scott Meyers' books on Effective C++ represent a lot of effort to educate programmers out of making mistakes. For example, from the table of contents…
So would that make D the airplane version of C++?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#527Earlier quoted context omitted.
Not only that, but we spend billions of dollars on defense to protect those airlines from bad actors. I mean when a person blows up a bomb in an airplane, our response isn't "build bomb-proof airplanes".
You're correct. Historically the choices were made to spend billions (and trillions) of dollars to invade countries harboring terrorists and use the situation to project power against other adversaries, advantageously control the price of oil, work trade deals, etc. I predict the same path will be taken with cybercrime. The U.S. defense apparatus won't be giving subsidies to non-tech companies to boost security. Rath…
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#528Earlier quoted context omitted.
Not only that, but we spend billions of dollars on defense to protect those airlines from bad actors. I mean when a person blows up a bomb in an airplane, our response isn't "build bomb-proof airplanes".
You're correct. Historically the choices were made to spend billions (and trillions) of dollars to invade countries harboring terrorists and use the situation to project power against other adversaries, advantageously control the price of oil, work trade deals, etc. I predict the same path will be taken with cybercrime. The U.S. defense apparatus won't be giving subsidies to non-tech companies to boost security. Rath…
We might seem some special forces go into action under cover. However it would be assassinations done in such a way that Russia either won't know who did them, or is willing to look the other way (the later implies something diplomatic).
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#529Earlier quoted context omitted.
they made a LOT more than 5m. I would have also been putting bets into the markets much earlier and cashing in on the stupid chaos. Continuing to let them do this with impunity is going to lead to escalated attacks.
Those bets could be easier to trace than the ransom payment though. Is there a way to make market bets completely untraceably?
Re: U.S. to give ransomware hacks similar priority as terrorism, official says
#530Earlier quoted context omitted.
they made a LOT more than 5m. I would have also been putting bets into the markets much earlier and cashing in on the stupid chaos. Continuing to let them do this with impunity is going to lead to escalated attacks.
Those bets could be easier to trace than the ransom payment though. Is there a way to make market bets completely untraceably?