https://www.reuters.com/article/us-usa-defense-cybersecurity...
https://www.reuters.com/article/us-usa-defense-cybersecurity...
The correct solution is to change the flawed thinking in our regulations that treats all changes as equally hazardous to patent safety. The government should be encouraging (the right) changes to be released more quickly -- punishing companies for following the rules won't fix anything.
1) Security in healthcare is a shit show. If there are lots of open exploits, there needs to be a fast way for them to get fixed and the software vendors shamed on.
2) when someone discovers an exploit, they shouldn’t have to fight lawsuits. The response to security flaws should not be suppressing them but fixing them ASAP.
3) people shouldn’t have to lose lives to make a point that security is weak and you better pay up for disregarding it.
"Oh we brought it upon ourselves by making it easy to break in so we should fix that instead of going after the thieves?"
Our life is to this day in many small ways runs on a contract that others are not trying to kill us. Security check or not.
https://en.wikipedia.org/wiki/United_Nations_Security_Counci...
Reality is essentially unverifiable at this point, so ... nuke Russia?
It's not that that's what I want, I just can't find a way to know what's real.
From having some knowledge of some investigations like these (though not on behalf of any government), the investigators and forensics experts are constantly asking themselves "is this a false flag? is this piece of evidence deliberately planted, or an actual mistake?" Investigators obviously want to get the right people and not get the wrong people. And in the case of nation-states, they also have classified information they can use (like from NSA global spying, etc.).
[1] (I shudder at the term "cyber" as much as anyone else reading this, but that pretty much is the official term the government uses.)
SWATting via VoIP spoofing etc., could arguably fall entirely within the realm of this.
Absence of evidence is not evidence of absence.
Everyone should be subject to due process. If some organized crime ring in Ukraine is blamed for some particular ransomware attack and they get tricked into traveling somewhere that lets them be extradited and tried in a US court, the prosecution still needs to prove beyond a reasonable doubt at trial that they're the responsible party. Things get more complicated when an entire nation-state government is accused of launching ransomware attacks, but so far I think only North Korea has faced that (someone please correct me if I'm wrong), and they're kind of an outlier among all the other countries.
We should always be skeptical any time any government accuses any entity of a crime, of course. There should always be a presumption of innocence. But that's what the legal system and due process are for. The onus is on the government to prove their case.
The government alleges something that sounds terrible that would justify an invasion, both parties play along, media is pushing pro war propaganda, allies abroad go along as well. Twenty years later, still no consequences, no apologies from our politicians, and any time someone seriously considers pulling out the troops, mysteriously some dubious war story comes up that is supposed to distract us or justify the war.
During the Cuban missile crisis, US intelligence showed photographs to the world proving the existence of the missile launch pads. During the Mueller investigation, the FBI provided hundreds of pages of concrete evidence to support their claims, which was supported by all other agencies and all of private industry.
Prior to the Iraq war, US intelligence showed jack shit; they just told the public "take our word for it: Saddam has WMDs".
If there were a future situation where there was an attempt to justify a country invasion or war, I absolutely would demand the highest possible rigor.
However, I don't think that can really be compared to trying to extradite and prosecute some criminals accused of ransoming hospitals and other institutions. They're not accusing any government of being behind these ransomware attacks and I doubt they will be. The only government believed to have ever done something like that is North Korea's, but they're kind of a special circumstance and are already technically and pragmatically at war with much of the world in many ways.
I think it's not really fair to assume a priori that the US government is lying, or that they're telling the truth, when they make some accusation. Things have to be carefully evaluated on a case-by-case basis, and the concrete evidence they provide needs to be looked at impartially. If there's no public evidence besides "trust us", then I'd agree that doubt is the correct action.
Then you wonder why everyone is burning US flags.
This is going to be a controversial suggestion, but I have a feeling that we might already be in an asymmetric world war and our leaders might quietly know it. This year has felt like checkmate.
Mutually assured destruction for the cyber-age.
If it's organized criminal hackers we're dealing with, then we should treat them how we would treat any legitimate terroristic threat. I would want our intelligence agencies to reach out and touch them.
This may not be a popular point of view on Hacker News. I unfortunately cannot fathom an alternative solution.
TGD
It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?
WRT engineering- if someone walks into a production cell and a robot swings and hits them in the head, guess who generally gets the blame in an investigation? The group that somehow didn't put safety scanners or a cell wall with door interlocks or didn't use safety-rated equipment.
There's a big difference between "guys, please get out of the way before I make the bot move" and "guys, I can't make the bot move until you're out of the way and the door is closed and latched" and worst-case scenario, that difference can be any number of human lives.
Surely things can improve, but it'll take time, dedication, and sucking it up and rewriting legacy code and probably being slower at pushing features out. (Keep in mind this isn't a universal guidebook- and should mostly be for companies that create software and infrastructure that is or can be life-critical.)
But.. there are certain classes of software that I think should be written differently.
I feel like we made a lot of bad decisions. There should be a completely separate stack for hospitals, power plants, etc., including a custom operating system. Why is Windows running on every machine? Isn't this a national security issue at this point?
Because for better or worse people make their choices and who are you to tell them what to run.
Infrastructural software - sure there should be some kind of security certification. this probably will not help much. Switches and routers are not running Windows and are still being attacked and crippled. Or consider the Stuxnet.
Yeah I agree there.
I'm curious what the surface area could look like. What is the minimum a hospital could operate with? How locked down could things be? Anyone in healthcare care to comment?
Even if I leave the door unlocked, it's still a crime to break in and take my stuff.