Live data from Hacker News

Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

nbcboston.com

91–100 of 267 posts

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#91
I'd really like to see/hear/read a breakdown of some of related issues from some experts.

Even on HN it's the same knee-jerk reactions every time one of these stories hit.

This is one of the most pressing technology issues of this moment and the discourse just sucks.

* Does banning ransom payments do anything? Good idea/bad idea? Historical analogues?

* Do we need to pay rewards to cyber privateers to take down cyber criminals?

* Is this an issue that can only be solved at the geopolitical level because of the role states play in enabling this activity?

* Will the hardening brought about by this eventually outpace the crappy attacker software?

* Is this a phase or the new reality?

* How much of this is enabled by technology vs the geopolitical situation?

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#92

Earlier quoted context omitted.

Would it? For some businesses, the reality is going to be that paying is necessary to continue to exist. What happens when that option, as crappy as it is, is off the table?

> the reality is going to be that paying is necessary to continue to exist. What happens when that option, as crappy as it is, is off the table? Insurance. Back-ups. Bail outs. Go out of business. That ransom paid has negative externalities that manifest nationally.

You won't even be able to get private insurance if the industry has to insure against complete destruction of a given business. Are you expecting the US gov to backstop every business regardless of size against ransomware? Who is going to pay for that?

Additionally, how do you protect against the obvious opportunities for fraud and abuse (business deliberately attacks itself to collect the insurance payout, business hits their competitors to drive them out of business, etc)?

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#93

I wonder if this will mean an increase in cyber security related postings in industries that have otherwise not had to worry about cyber security before (I.E the Steamship Authority, Meat industry etc)

Cybersecurity is not a technology problem. It's a policy and enforcement problem. Ground and mid-level operating convenience will always destroy any attempt to create security unless strong standards of behavior are created and ruthlessly enforced. I've never seen it happen successfully outside of technology corporations staffed by nerds who actually care or the military. All it takes is one guy who knows a guy and t…

This is one of the important reasons for audits such as HIPAA, SOX, SAS70 etc...

To ensure that you don't have holes in your security posture... The technology you deploy is important, but also important that your security and governance model on top of the technology is also in place.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#94
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

> Historical analogues?

'Don't negotiate with terrorists' or:

> It is wrong to put temptation in the path of any nation,

> For fear they should succumb and go astray;

> So when you are requested to pay up or be molested,

> You will find it better policy to say:—

> "We never pay any-one Dane-geld,

> No matter how trifling the cost;

> For the end of that game is oppression and shame,

> And the nation that plays it is lost!"'

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#96

A federal ban on paying ransomeware would reduce the incentive to commit these attacks.

Aside from the desire to impart chaos via these attacks.

There is definite economic attack damage incentive still in place.

In fact - if ransoms are banned - then it would seem that such types of attacks become more of a state sponsored attack to affect the economy of your enemy/competition

What if it were apple attacking FB or something like that. Surely we will see this in the future, just as originally foretold in Neuromancer.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#97

How exactly are the ransoms even paid out? I would assume cryptocurrencies, but before those existed how did they pay out? I'm not sure what it would be called, but has there been any investigation in a sort of "transparent by default" database system? Ideally if this were possible people wouldn't need to care about data being stolen (though in this case it's unclear what the attack did, but many times it's more like…

Before cryptocurrency you had to buy things from shady online pharmacies or send/fund Visa gift cards. Source: https://www.varonis.com/blog/a-brief-history-of-ransomware/ Crypto is really what's made ransomware at the scale we see it now possible.

I suspect it changes the profile of who gets hit. Individual-level targets would get extorted for maybe a couple hundred bucks - sums that are reasonable to transact in iTunes cards or whatever. Those numbers are low both because it's what that category of target is willing/able to cough up financially, and what they were able to transact irreversibly. Conversely, your meat-packing CEO isn't going down to the corner store for $11m in phone credits, so it was less worth it to go for targets with deep pockets, that might be better-protected, instead of casting a wide net for a lot of easy small hits. The ability to irreversibly and kinda-anonymously transact large amounts definitely incentivizes going for institutional targets.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#98

This isn't news anymore, its weather. If your company does not have a full time cybersecurity team, they soon will, even if they say they don't need it.

and as a parallel to modern industry standard infosec best practices, a good offsite/off-line backup system, disaster recovery program, tested backups/recovery methodology. A lot of the companies I've seen badly affected by a cryptolocker malware would have been equally in a dire situation if their head office/datacenter had burned down.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#99
post #16

Earlier quoted context omitted.

Services can be available, and not reliant on internet connected services. Imagine if all the hacks we've seen in the last year happened all at once. We'd be screwed.

How are you going to sell customers tickets remotely without an internet presence? How are you going to field customer service complaints or general inquiries without email? How are your employees going to do work at multiple sites without VPNs? If you pitch "lets do everything by phone" you will be laughed out of the room. I agree that things should be kept off the internet unless they absolutely need to be there, b…

> How are you going to sell customers tickets remotely without an internet presence?

With this wacky invention known as a telephone. Merely three years ago I used a telephone to order tickets on the Alaska Marine Highway (a ferry service operated by Alaska) while driving through BC. No websites needed; it was utterly painless.

Re: Massachusetts Steamship Authority hit by ransomware attack; ferries delayed

#100
post #91

I'd really like to see/hear/read a breakdown of some of related issues from some experts. Even on HN it's the same knee-jerk reactions every time one of these stories hit. This is one of the most pressing technology issues of this moment and the discourse just sucks. * Does banning ransom payments do anything? Good idea/bad idea? Historical analogues? * Do we need to pay rewards to cyber privateers to take down cyber…

Another issue I don't see discussed much is how cryptocurrencies basically enable the business of ransomware. It's not like we're less secure than we were 20 years ago, the difference is now hackers can actually get paid.
Post reply on HN