It will be a long, long time before the marketplace evolves sufficient technological measures to guard against state-sanctioned/possibly-state-sponsored malicious actors operating with impunity in a lawless environment.
It will be a long, long time before the marketplace evolves sufficient technological measures to guard against state-sanctioned/possibly-state-sponsored malicious actors operating with impunity in a lawless environment.
Unfortunately, the marketplace -- at least certain segments of it -- are far beyond .mil/.gov in terms of capacity and sophistication. E.g., AWS's formal tools for code-level security is what DARPA's been yelling about doing for decades, but gov't contractors and the branches/agencies are unable/unwilling to catch.
I'm not sure how to fix gov or mil, but a good starting point within mil is to stop making career officers with theology and polisci degrees but zero CS training the first-line managers of cyber commands.
what tools?
Applied theology.
By the third time I had to seek out existential comfort.
What you got a degree in shouldn't be the make or break of your career.
You are an exception.
In the military and certain parts of the corporate world ("enterprise" companies mostly), there is a wide-spread and systemic problem with horrendously unqualified people managing software/IT groups. E.g., Susan Mauldin for a recent example.
We can allow space for self-taught people without opening the flood gates. No one should be in charge of IT security without first developing deep technical expertise at some point in their career.
For anyone as confused as I was, this is probably referring to the Equifax security officer. My local search engine mostly brought up a murder case.
Theology says something specific about how you process reality.
I will point out that one of the founders of a core CS discipline have written books [1] on what can be called theology.
[1]: https://en.wikipedia.org/wiki/Donald_Knuth#Works_regarding_h...
We all have musings that cross domains; why does this persons book hold significance to you for this thread?
Applied Theology is an American evangelist field of study that focuses on shaping your life and the world around you to operate according to the will and word of the Christian Evangelist god.
Oxford (UK): https://www.ox.ac.uk/admissions/graduate/courses/mth-applied...
California Baptist: https://calbaptist.edu/programs/bachelor-of-applied-theology...
"Everything from preaching to media technology, from helping with funerals to discipling [sic] unbelievers."
This is one of those very frustrating conversations to have online, not that different from people saying "but it's the People's Democratic Republic of whatever."
The Baptist thing called "applied theology" is a part of the Dominionist movement. Fundamentally it's a theocratic endeavor.
I agree that theology has been used in a thousand ways across two thousand years and I'm sad that if you have a degree in "Applied Theology" from a small religious college in the Midwest it's definitely not just "I was thinking of becoming a minister."
But dominionism is a real thing. People major in it, they drop out, they get other jobs, and then you have this record of their beliefs right there on their resumes. It'd be easier if they had no degree at all.
> Everything from preaching to media technology, from helping with funerals to discipling [sic] unbelievers
I don't see an issue with this, if discipling unbelievers means something similar to promoting the church, or missionary-esque behaviour (of the non-colonial form, obviously). If it means how to deal with atheists in a theocracy then I'm not a fan.
(And in part just an opportunity to play with language. I grew up in the Bible Belt. Gentle humor about religion/spirituality is something I am no stranger to.)
Is this true?
This can't be true. Surely they must have some CS experience?
I took my last bus off a USMC base so long ago I've raised a kid who's in med school since. Can someone with more recent experience chime in on whether or not this is hyperbole?
They aren't? Has NORAD control been hacked? Any battleships or predator drones?
I admit it's a bad look when, for instance, a VA database is compromised and private information for millions of government employees are exposed, but I'd also be SHOCKED if the NSA were dedicating resources to protecting that data.
Outside of Snowden, what leaks of stuff "the US defense forces" are actually attempting to protect have been captured?
>yet we're expecting individual companies to go up against them?
The companies in question appear to not even be doing basic things like taking backups and making them immutable. I don't think anybody is expecting them to have perfect security, but it doesn't take a lot of effort to backup to a tape and stick it in iron mountain for 2 years, it just takes money.
Even a cup of water cannot function if it cannot maintain structural integrity.
If it was, how would we know?
(outside of, uh, kinetic consequences)
yes actually over ten years ago this happened already https://www.cnn.com/2009/US/12/17/drone.video.hacked/index.h...
Maybe security holes are just part and parcel to the whole enterprise. So you have to accept them and center your preparation around your response to such losses. How do you get back up and running? How do you operate without the asset that was compromised? And so on.
E.G. http://pulse.ncpolicywatch.org/2021/05/12/as-nc-lawmakers-fa...
OTOH, this isn't just about bad actors raiding. This is also about terrible security practices that are easily avoidable with an ounce of expertise and giving a shit.
In addition to your idea (let's make believe for a moment...) how about the US govt itself sponsors these attacks, and then instead of demanding ransom, they just levy huge fines against the companies who have carelessly let this happen? Extending your analogy, this would be no different than fines or lawsuits for carelessness and failures in physical infrastructure.
So the Internet could be like this if it was more regulated. Anonymous traffic could be prohibited...no more TOR nodes, no hands-off proxying of traffic, no "it's an open access point, I totally don't know who was creating that torrent traffic".
Would these sorts of laws be accepted, or would they simply result in more attempts to anonymize traffic?
I imagine that this is sort of what things are like in more authoritarian places like China. Is it effective there?
Only because we, as a society, have decided that we don't care about information security, to the extent that we protect incompetent, ignorant, or uncaring individuals and organizations from any liability for their actions. How much better off would we be if we had fined Experian $1M for every user account they lost? Or for any of the other breaches in the preceding decades? How much more careful would your average bootcamp grad be writing the code that forms attack surfaces if they had to pay liability insurance?
By and large, we have had a good idea how to make technological measures much more resistant to attack since the '80s. It's always been considered too difficult and too expensive, something we have put exactly no resources towards fixing. Ten years of a quarter of the collective budget we spend on using ML to violate privacy would probably take everyone except state sanctioned actors out of the picture.
(All numbers pulled out of my flying monkeys.)
Then they also don't need to pay the ransoms.
The important part is having the backup in some form. Having a well tested restore ability is a great idea, but not nearly as important as having the backups in the first place. Most backup programs are designed for restore, even if you screwed up, odds are you can get the data back later.
You will have a hard time to find a backup program that doesn't have a good and tested restore procedure. However that doesn't mean it works in your particular edge cases.
Even if the backups would work perfectly, this forced downtime might the best time to apply some change that your admins have known should be done for a while but couldn't afford the downtime. (you couldn't do a schema update, but there are some smaller config changes that still require taking the master database done for a bit)
Backups also ensure business continuity - which might be more important than past data for some workflows.
Regardless, backups are the first priority. Then a tested restore procedure.
Hum... Backups aren't normally "at the edge of failure", the procedure either works or doesn't work. One must test to ensure the procedure works and continue working after all the environment changes done today.
That is, except for proprietary formats, like Exchange. Those can fail at any time, retroactively.
I suspect this bill will face significant lobbying against it by companies involved in secured backups along with the ransomware distributors themselves.
Most probably "state actors" are taking advantage of this asymmetry to extort money and bind resources. It's a hidden "war" going on out there.
Balance is different when you have and a company with understaffed IT and all which usually goes along with this: software which is not updated for months if not years despite known vulnerabilities in it, legacy systems which are kept "just in case" because no-one knows what will be broken if they will be decommissioned, poorly managed credentials to external systems, and so on.
You mean an average person will uninstall MicroSoft Windows?
Peope were telling of the inevitable downfall of MicroSoft since before I was born.
It's also not really a national security issue. The USA will continue to exist and function as the USA even without gas pipelines and power generation.
"National security" isn't some blanket term to mean "large infrastructure required for major industries", it has a specific, defined meaning. Just because the feds use it as a blanket justification for a bunch of stuff doesn't mean we should embrace that usage, otherwise when everything is a matter of "national security" than nothing is. It's just like the overuse of the term "terrorism" to mean "any big crime".
Temporary outages, maybe. Sustained outages (or destruction) of gas pipelines and power generation, if systemic, would almost certainly mean mass starvation.