7 ms·
U.S. Senate to probe whether legislation needed to combat cyber attacks
- convolvatron 5y agoreverse the terrible ITAR legacy fund foundational security and mandate its use by government agencies and suppliers
- e40 5y ago> foundational security Can you tell us what that means?
- mikewarot 5y agoI suspect the Bell-LaPadula model would be part of it https://en.wikipedia.org/wiki/Bell%E2%80%93LaPadula_model https://en.wikipedia.org/wiki/Bell%E2%80%93LaPadula_model Much research was funded, and solutions were found long, long ago, to many of our current "problems".
- kragen 5y agoAgreed. I wrote about this last week: https://news.ycombinator.com/item?id=27389993 https://news.ycombinator.com/item?id=27389993 In reality, though, the Continental attack is likely to provoke a reaction as counterproductive as the reaction to 9/11 was.
- MeinBlutIstBlau 5y agoIt's mind boggling that the government needs to require this. What bureaucrat is refusing some IT person from requesting the funds doing this?
- artful-hacker 5y agoLiterally all of them. Security is a cost center, and non bureaucrats salaries are minimized as much as possible until you are left with "warm body to fill chair". Even the NSA doesn't pay well, compared to private sector.
- milkytron 5y agoThe gap between the security and defense seems to be becoming smaller. If some of the defense budget was put towards cyber defense, I bet we could see some drastic improvements.
- MeinBlutIstBlau 5y agoI'm wholly aware the private sector pays better, but in the grand scheme of pay/average citizen, they still make decent salaries. In that regard, why is upper management ignoring IT security at a base-line level of at least rotating backups? Like even that is pretty cheap and you can revert systems back within a day or two with a few days of lost work. Nobody is saying have a top tier security team.
- hn8788 5y agoI was on a temporary pentesting contract at a Fortune 500 company, and the reason for ignoring security came down to cost. Our contact in their IT department said that when they were trying to get the budget to fix their longstanding security issues, they were told that it's cheaper to accept occasionally getting hacked than it is to fix things. They said that public relations people at big companies had pushed the "the bad guys attacked us, it could have happened to anyone" narrative so well that besides a few day dip in stock prices, there would be no negative financial impact on the company. The average person thinks of getting hacked like being robbed at gunpoint, where it can happen to anyone through no fault of their own.
- jnwatson 5y agoIn terms of dollars and cents that makes complete sense. Real security is extraordinarily expensive. Very rarely is that compatible with shareholder value.
- ForHackernews 5y ago> Even the NSA doesn't pay well, compared to private sector. On the other hand, I bet it's pretty fun working for the NSA: https://en.wikipedia.org/wiki/NOBUS https://en.wikipedia.org/wiki/NOBUS
- handrous 5y agoIt's very hard to get raises or promotions on all the bad things that would have happened, had your actions not entirely prevented them. Much better to devote those resources to new initiatives or "transformations" or whatever, ideally ones that can be tied directly to higher revenue, while doing just enough about security that you can't be accused of being unusually lax if something goes wrong (and since all your peers are very lax, for the same reasons, this isn't much).
- deleted 5y ago[deleted]
- Ericson2314 5y agoI am always worried non-programmers don't sufficiently understand how pathetic it is that we limp along with bloated Unix and other accidents of history that were never retired. And this lassies-fair approach to cleanliness and reducing complexity both makes us more vulnerable and less productive.
- AnimalMuppet 5y agoWhy single out Unix and not, you know, Windows?
- eplanit 5y agoExactly -- Windows is the biggest vector for malware, by orders of magnitude.
- AnIdiotOnTheNet 5y agoBecause most IT infrastructure is based on some form of Unix? Linux fans really like to play up the "Windows is so insecure!" rhetoric, but it isn't really true. Linux and the common systems implemented on it, for instance, have had plenty of vulnerabilities. Windows gets an especially bad rap pretty much only because it is the most common Desktop OS, but Desktop Windows and Desktop Linux have the same giant gaping security problem: the human being using them.
- AnimalMuppet 5y agoEverything you say is true, but that wasn't my point. The OP said > ... how pathetic it is that we limp along with bloated Unix and other accidents of history that were never retired. So, why single out Unix? Is Unix more bloated than Windows? I doubt it. Is it more of an accident of history than Windows? No. Is it more in need of being retired than Windows? I think it would take someone with an axe to grind to say so. And that's what my comment was about: Trying to expose that axe being ground.
- Ericson2314 5y agoNo good reason :) Unix is older but yes Windows has all the complexity problems to a much worse degree. I use Unix every day but rarely Windows so I sometimes don't remember it. Our industry self-congradulates on not using Windows like those untechnical normie companies or whatever, but then forgets that other than being FOSS (most of the time), Unix has all the same problems just to a lesser degree. Maybe this is the transition plan we need; first ban Windows in prod for things important enough that government is going to take on the costs if something goes wrong. Then, at some later point, ban Unix too for all the same reasons, just less magnitude.
- mikewarot 5y agoLegislation is required to reverse the posture of the NSA from offense to defense. Nothing else will help until that is done.
- jnwatson 5y agoNSA’s posture has been both for at least twenty years. They have separate divisions and everything.
- smolder 5y agoThe issue of course is that their missions are out of alignment with respect to fixing vulnerabilities, and we've seen red team capabilities prioritised such that harm came to the vulnerable. Generally, defending an intentionally security-impaired infrastructure is going to be a lot of additional, probably costly work.
- dhx 5y agoThe US federal government have been spending 90% of their cyber security budgets on offense and only 10% on defense[1]. Practically speaking, what more could legislation and budget increases require of the US federal government to increase spending on defensive measures? Some ideas (without judgement on the pros and cons): * Educate: produce more hardening guides and product-specific educational material more often for more products. * Invest: run free or heavily subsidized training courses and conferences, provide sought-after internships, fund more academic research, fund open source project security improvements. * Develop: produce new standards, produce new open source software products (previous examples: SELinux, Ghidra, etc) and encourage their uptake. * Detect and advise (software developers): reverse engineer, fuzz, debug and find vulnerabilities in software products and advise developers immediately of any security issues discovered. * Detect and advise (network end users): scan all US Internet Address ranges for not so much vulnerabilities, but bad practices or misconfigured and/or weakly configured services. For example, scan for and detect domains with an e-mail service that doesn't support DMARC, then send advisory notices to the operator educating them on the benefits of implementing better security for the service. For example, scan for and detect home security cameras that are exposed to the Internet with default passwords, then send advisory notices to the owner suggesting they secure their home security cameras. * Increase domestic surveillance: tap international and domestic exchanges and/or require "metadata" to be recorded in bulk to allow an instruction detection system to be created across the entire country, allowing better visibility and traceability of incidents back to their origin, and the ability to advise private companies of incidents at the earliest possibility. * Increase international surveillance and offensive measures: more aggressively hunt down, monitor and disrupt international cyber crime groups. I would argue most of the above with the exception of investment and some limited development and detection/advisory are unlikely to have much impact due to: * Historical issues of Dual_EC_DRBG[2], NIST elliptic curve rigidity[3] and other involvements with standards organisations and groups have all but burnt any bridges that used to exist. Standards organisations and implementers are highly dismissive of contributions from the NSA and NIST as neither organisation are trusted. * Increased centralisation of Internet infrastructure into Amazon EC2, Microsoft Azure/Office 365/Teams, Google Cloud/Google Docs/Gmail/etc, etc allows attackers to easily launch an attack within the same data centre as the target. Vendors such as Amazon, Google and Microsoft are now solely in control of the ICT operations of massive segments of the US economy and end users just have to trust these vendors with much reduced ability to control and audit security of the service provided. As a result of increasing centralisation, there is little investment occurring in "on-premises" solutions including e-mail gateways, VoIP systems, document storage system, etc. * Increased reliance on transport over Secure HTTP results in raw network traffic revealing less and less information on possible intrusion attempts (all traffic starts to just become TLS connections from A to B and it is much harder to ascertain from an outsider perspective whether that traffic is suspicious or not). [1] https://www.reuters.com/article/us-usa-cyber-defense-idUSKBN17013U https://www.reuters.com/article/us-usa-cyber-defense-idUSKBN... [2] https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG [3] https://safecurves.cr.yp.to/rigid.html https://safecurves.cr.yp.to/rigid.html
- akomtu 5y agoTranslating to plain language: bureocrats are evaluating the possibility to ban encryption and cryptocurrencies under the veil of combating cyber attacks.
- sida 5y agoI mean cryptocurrency is indeed what made ransomware possible.
- d4mi3n 5y agoI'd argue they make it less risky. Ransomeware has been around since the 90s, just not nearly as prevalent as it was harder to do without getting caught. They could easily instead demand somebody mail cash/money order to an abandoned address or mail forwarding service.
- giaour 5y agoCollecting a ransom in physical cash is extremely risky for criminals! Law enforcement knows where you are at a specific time. I have never heard of ransomware that predated cryptocurrency; could you share a link to an article?
- d4mi3n 5y agoIt's a fascinating topic! Wikipedia has a pretty detailed entry on the topic and reports the earliest known ransomware attack to be as early as 1989[1][2]! 1. https://en.wikipedia.org/wiki/Ransomware#History https://en.wikipedia.org/wiki/Ransomware#History 2. https://en.wikipedia.org/wiki/AIDS_(Trojan_horse) https://en.wikipedia.org/wiki/AIDS_(Trojan_horse)
- giaour 5y agoInteresting! I am a bit struck by how low the early ransoms seemed to be (looks like they were around $200 or less) even when they gained access to anonymous remote payment methods in ~2005 (e.g. eGold and Liberty Reserve). It’s also interesting that all of those early anonymous remote payment methods have been significantly altered specifically to nerf their utility for extortion and scamming.
- russian-hacker 5y agohttps://en.wikipedia.org/wiki/Manufacturing_Consent https://en.wikipedia.org/wiki/Manufacturing_Consent
- rafale 5y agoMandatory bug bounty programs with a minimum 1k payout. Open to US residents and foreigners alike.
- jjcm 5y agoAt what level of scale? Is this for all businesses, including my weekend startup? What qualifies for a bug? You could likely do this for any publicly traded company, but the qualifiers for what constitutes a bug would take some time to define.
- PeterHolzwarth 5y agoAn unconventional approach could be to make it a severely penalized, strictly enforced, federal crime to pay ransom. (Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)
- hpoe 5y agoAll you get at that point is the right people using it to prosecute the honest people.
- bpodgursky 5y agoI think it would just give CEOs who want to do the right thing (and not pay) legal cover to tell the board of directors "Nope, not paying — the company is going to be shut down for a month. Deal with it, I'm not going to jail."
- russian-hacker 5y agoAnd it would give CEOs who want to do the wrong thing an avenue to destroy competitors under the table.
- Agathos 5y agoYou could always hire a bunch of shadowrunners to destroy your competitor's computer system, but I don't know what that has to do with ransomware. But hey, I guess you could use cryptocurrency to pay the runners.
- bpodgursky 5y agoThis has always been true... and always been illegal.
- _hyn3 5y agoWhat if it was more than a month? What if it was.. permanent?
- rdxm 5y agolol.......i'm trying to figure out how the onion spoofed Reuters.....
- est 5y agoImplement a national wide zero-trust hierarchy?
- failuser 5y agoMaybe they can fund improving of standards and, for example audits of widely used open source projects. Also some give some protection for people who find vulnerable systems: legal threats should not be an acceptable response to reporting security issues. I understand that the government is interested in having security holes to exploit, but you need to choose. A program to fix municipal and state IT systems security should help too.