Live data from Hacker News

U.S. Senate to probe whether legislation needed to combat cyber attacks

reuters.com

61–66 of 66 posts

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#61

I am always worried non-programmers don't sufficiently understand how pathetic it is that we limp along with bloated Unix and other accidents of history that were never retired. And this lassies-fair approach to cleanliness and reducing complexity both makes us more vulnerable and less productive.

Why single out Unix and not, you know, Windows ?

No good reason :) Unix is older but yes Windows has all the complexity problems to a much worse degree.

I use Unix every day but rarely Windows so I sometimes don't remember it. Our industry self-congradulates on not using Windows like those untechnical normie companies or whatever, but then forgets that other than being FOSS (most of the time), Unix has all the same problems just to a lesser degree.

Maybe this is the transition plan we need; first ban Windows in prod for things important enough that government is going to take on the costs if something goes wrong.

Then, at some later point, ban Unix too for all the same reasons, just less magnitude.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#62

Earlier quoted context omitted.

Why single out Unix and not, you know, Windows ?

No good reason :) Unix is older but yes Windows has all the complexity problems to a much worse degree. I use Unix every day but rarely Windows so I sometimes don't remember it. Our industry self-congradulates on not using Windows like those untechnical normie companies or whatever, but then forgets that other than being FOSS (most of the time), Unix has all the same problems just to a lesser degree. Maybe this is th…

And replace them with what?

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#63
post #46
post #33

Earlier quoted context omitted.

I'd argue they make it less risky . Ransomeware has been around since the 90s, just not nearly as prevalent as it was harder to do without getting caught. They could easily instead demand somebody mail cash/money order to an abandoned address or mail forwarding service.

Not that "easily." Moving that much cash around requires a lot of manual effort and some skill at money laundering. By removing that need, cryptocurrency makes ransomware scalable. And as Paul Graham and other Silicon Valley types have said a thousand times, scalability is the difference between a modest mom-and-pop operation and a rapidly growing enterprise.

You are correct in that handling that volume of physical cash is likely more difficult than I implied, though I don't think removal of cryptocurrency from the equation removes the ability to scale.

In my mind, the catalyzing effect of a cryptocurrency in this context is from:

1. The ability to move something of value digitally

2. The thing of value being resistant to governmental control--crypto can't be easily seized, but a US bank account can.

There may be other properties of crytocurrency that make it useful for ransomware, but I doubt there aren't other vehicles that could be used--though alternatives are likely less lucrative due to the overhead in laundering your ransomeware payment into hard currency.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#64
post #38
post #33

Earlier quoted context omitted.

I'd argue they make it less risky . Ransomeware has been around since the 90s, just not nearly as prevalent as it was harder to do without getting caught. They could easily instead demand somebody mail cash/money order to an abandoned address or mail forwarding service.

Collecting a ransom in physical cash is extremely risky for criminals! Law enforcement knows where you are at a specific time. I have never heard of ransomware that predated cryptocurrency; could you share a link to an article?

It's a fascinating topic! Wikipedia has a pretty detailed entry on the topic and reports the earliest known ransomware attack to be as early as 1989[1][2]!

1. https://en.wikipedia.org/wiki/Ransomware#History

2. https://en.wikipedia.org/wiki/AIDS_(Trojan_horse)

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#65

Earlier quoted context omitted.

No good reason :) Unix is older but yes Windows has all the complexity problems to a much worse degree. I use Unix every day but rarely Windows so I sometimes don't remember it. Our industry self-congradulates on not using Windows like those untechnical normie companies or whatever, but then forgets that other than being FOSS (most of the time), Unix has all the same problems just to a lesser degree. Maybe this is th…

And replace them with what?

seL4? Fuchsia? Something else new?

We've known for now that proper capability-based security is both more safe and more productive (global state is just hard). We just need to put it into practice.

Re: U.S. Senate to probe whether legislation needed to combat cyber attacks

#66
post #64
post #38

Earlier quoted context omitted.

Collecting a ransom in physical cash is extremely risky for criminals! Law enforcement knows where you are at a specific time. I have never heard of ransomware that predated cryptocurrency; could you share a link to an article?

It's a fascinating topic! Wikipedia has a pretty detailed entry on the topic and reports the earliest known ransomware attack to be as early as 1989[1][2]! 1. https://en.wikipedia.org/wiki/Ransomware#History 2. https://en.wikipedia.org/wiki/AIDS_(Trojan_horse)

Interesting! I am a bit struck by how low the early ransoms seemed to be (looks like they were around $200 or less) even when they gained access to anonymous remote payment methods in ~2005 (e.g. eGold and Liberty Reserve).

It’s also interesting that all of those early anonymous remote payment methods have been significantly altered specifically to nerf their utility for extortion and scamming.

Post reply on HN