I'm 100% in favor of better systems/processes/technology to prevent exploits, but I'm also 100% in favor of blaming the perpetrators of the ransom also.
In the real world we don't accept the argument that the victim is primarily at fault.
* leaving your car unlocked doesn't mean that is OK for someone to steal it and demand a ransom for its return
* leaving your house/apartment unlocked doesn't mean that it is OK for someone to swap out the locks and demand ransom for the new keys
And it really isn't about being locked/unlocked. Doors and locks can generally be easily broken or bypassed, doesn't mean that everyone should have to purchase industrial strength doors and locking systems (and windows, and...).+2 for that ;)
But when financially lucrative attacks can be carried out with very little risk of being caught, and the results are so bad, organizations who don't take security very seriously are at fault for not recognizing the threat landscape, and government is at fault for not recognizing that the market isn't solving this problem, stepping in and requiring higher quality assurance or liability for software.
If you're worried about X, and Y promises to prevent X for a cost, you seek recourse against Y.
X: I can't miss this flight. Y: Pay this surcharge to reserve a seat. Overbooking ensues. I'm blaming Y and not the other passengers.
X: Really don't want this disease to kill me. Y: Take these pills to not die. Death ensues. I'm (well somebody else is) blaming Y and not the disease.
In life we can't always control the cause so we aim to minimize the effect. Thus, while the ransomers are culpable for the blast, IT security are accountable for the size of the blast radius.
Due to the nature of the web, unless you unplug from the Internet, the risk is persistent. So although a cybercrime-free world would be swell, until that day arrives we must control the effects.
I'm not convinced this isn't the answer. What are we gaining by putting hospital networks on the Internet? Are those gains worth the cost in increased vulnerability?
Which is to say, that public health countermeasures and similar modes of risk-mitigation apply.
Bad weather is indifferent to the shaking fists. It won't get worse or more frequent if people fail to shake their fist. But human behavior is very much responsive to feedback from other humans. I'm arguing that we should all be shaking our fists when we see extortionists at work as well as tracking them down and punishing them. And we should also take care to protect ourselves from them. It isn't a binary choice.
Nowhere id I assert that it's a binary choice, and that interpretation of ym words only make sense if you ignore chunks of what I'm saying. Over the near term, you're not going to eliminate crime by moral suasion so it's important to have a strategy to mitigate its predictable incidence while we also work on the problem of how to reduce crime through deterrence, reducing incentives, and so on.
That doesn't make you correct.
https://www.ncbi.nlm.nih.gov/pubmed/9532958
Crime is a public health issue. It shares common causes with ill health, particularly poverty, and fear of violent crime is itself a major cause of anxiety. Community development in pre-school education, parental education, and among ethnic minorities, both reduces crime and promotes better health, for example in reducing the effects of alcohol and illicit drugs. Health workers should contribute in full to community development.
I note that I'm standing with my earlier characterisation of a public health domain rather than weather, but both carry very strong similarities, including a risk / forecast / mitigations approach.
If you hire a bodyguard and still get shot while the bodyguard is on his phone both the perpetrator goes to jail and the bodyguard gets fired/pays restitution. Not that unheard of. It's not like one person gets all of the legal and ethical blame and everyone else is entirely absolved.
In your bodyguard example I don't think in that type of a situation that people fixate on the quality of the security detail. They rightly demand that the shooter be tracked down.
The civic justice system, on the other hand, is completely driven by public interest—nothing gets done to change things unless somebody (or some class) bothers to sue.
Well, for one thing, we could try to think of ways how to catch these criminals, how to help law enforcement.
We can blame the criminals, but we will always have criminals when the crime is easy.
Those who are really responsible here are the ones who allowed themselves to become dependent on an ancient and insecure operating system.
To me, the buck should stop with the head of the hospitals.
Any number of reasons all boiling down to the same reason: what does calling bad people bad accomplish? Best for people who want to be good to talk about how to be good.
https://mobile.nytimes.com/2017/05/12/world/europe/uk-nation...
The NSA?
Not saying that the NSA is innocent as a child, but please don't put all on them.
If I would have a zero-day I wouldn't go out and encrypt people computers.
But if you find a cooler with a vial of Ebola on the street, take it home instead of turning it in, then have it stolen and have that strain implicated in an outbreak?
Yeah... that's definitely at least partly on your hands.
The 'arms' in 'right to bear arms' is not clearly defined, and the founders would not have had any concept of software or weaponised software, but I can't think of an argument against people owning malicious software if the argument for owning firearms is also in play.
I would say this is closer to having your guns stolen from your home while you're asleep and then used in a crime.
It shouldn't be a surprise when someone else starts shooting off doorknobs.
Wouldn't that hold Microsoft liable then?
No, it would make IT security about as expensive as good lawyers. Just to cover the losses. A method to reliably produce vulnerability-free software is not invented yet.
I beg to differ. We have formal methods, ranging from type systems to full blown verification. This isn't a technical problem, it's an economic one.
That's not the goal. Well it is, but it's unachievable. We need to get people to care about security beyond ensuring that teenagers can't trivially get in—the current state of affairs for enterprise IT.
A law would at least require companies to give a fuck beyond the "can the CEO's niece break in" level.