Live data from Hacker News

The M.T.A. Is Breached by Hackers as Cyberattacks Surge

nytimes.com

1–10 of 75 posts

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#4
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

there are standards and operating procedures that can be used. it’s not that hard.

it comes down to training and cost cutting. If the penalty for failing miserably is 0 you won’t see any change. I would hold the companies responsible for things like this liable to the point they would be put out of business after an event like this. If the cost of being sloppy is that you no longer have a business people will start paying attention really quickly.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#5
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

> Perhaps a pentester or security person can help answer this

Not one of those but since they are [apparently] inadequate anyway...

I read an analogy that pinning this on "cyber security" is like accusing a mugging victim of having a lack of personal security guards. That's just not how civil society works.

Minimum safety standards: laws and ability to enforce them.

This is a short-term win for the bad actors. Just wait until the next "great firewall." Well gain safety, but we'll lose access to those low cost eastern European dev talent. That's more likely than every single US business being forced to hire private security just to operate.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#6
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

There are definitely strategies that significantly reduce the cost of such an attack - one being append-only backups of a sufficient frequency and with a fast enough restore time. We have the tech to do this cheaply (mount user shares via ZFS-backed NFS, for example) but I’m not sure many places have the organizational competence to implement something so simple and effective. They need to spend 100x more money on something 10% as useful.

It’s also possible to eliminate these attacks entirely, but it probably requires corporate tech infra that looks totally different from what most orgs now. If it were my job to set up some sort of hardened corporate setup, my first step would probably be to restrict most employees to iPads. There’s not really any reason a shift manager at a meat packing plant or whatever needs or benefits from a Windows box.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#7
post #5
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

> Perhaps a pentester or security person can help answer this Not one of those but since they are [apparently] inadequate anyway... I read an analogy that pinning this on "cyber security" is like accusing a mugging victim of having a lack of personal security guards. That's just not how civil society works. Minimum safety standards: laws and ability to enforce them. This is a short-term win for the bad actors. Just w…

I think of it more like someone's house getting robbed because of them having bad or no locks¯\_(ツ)_/¯

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#8
post #5
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

> Perhaps a pentester or security person can help answer this Not one of those but since they are [apparently] inadequate anyway... I read an analogy that pinning this on "cyber security" is like accusing a mugging victim of having a lack of personal security guards. That's just not how civil society works. Minimum safety standards: laws and ability to enforce them. This is a short-term win for the bad actors. Just w…

> That's just not how civil society works.

This is a cope and also irrelevant.

Civil society works a certain way because of its social interaction dynamics. The internet works much differently (namely, retribution is much harder, which rules out most tit-for-tat transgression management strategies, and the scale is much larger than is possible with human interaction).

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#9
post #3

Perhaps a pentester or security person can help answer this. Could a list of minimum network safety standards be made that: a) would help the ransomware & hacking crisis, and, b) is practically enforcable at scale?

The primary thing to help randsomemware would be to have tested backups, where you can reimage the computers and restore from backups reasonably quickly.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#10
post #5

Earlier quoted context omitted.

> Perhaps a pentester or security person can help answer this Not one of those but since they are [apparently] inadequate anyway... I read an analogy that pinning this on "cyber security" is like accusing a mugging victim of having a lack of personal security guards. That's just not how civil society works. Minimum safety standards: laws and ability to enforce them. This is a short-term win for the bad actors. Just w…

I think of it more like someone's house getting robbed because of them having bad or no locks¯\_(ツ)_/¯

I don't think the analogy fits because there are so many ways for an attacker to compromise a system besides the "front door". If we want to stretch things, a member of your own family can unwittingly let a guest perform an action that enables the robbery weeks later.
Post reply on HN