One-Fifth of U.S. Beef Capacity Wiped Out by JBS Cyberattack
bloomberg.com
bloomberg.com
Yes it's painful and interferes with the economy, but ultimately this will harden up potential targets. And boy do some of these guys need hardening up.
The question is whether the pains we’re currently feeling are enough to cause a change in the industries affected.
That's not the case for cyberattacks. Solarwinds was attacked many months before it was detected, Stuxnet was hidden for years. We have attributed some attacks but not most and attribution often succeeds only years after detection. And the attackers aren't as vulnerable to cyberattacks simply because their economy is "less connected" - for example, North Korea is at the extreme end of that scale and they really don't care much about what exploits you have; you have a digital economy that's wealthy but vulnerable to attacks by those who don't have it.
Considering downthread there are honest suggestions to send special forces after the ransomware gangs, I’m gonna go with “probably not”. That type of denial is pervasive.
The F500 and companies like JBS just need to move essentially dataframes around from automation to automation, but somehow the software ecosystem is still building that with the same tools used to write Google. The next answer is usually “they don’t invest in a security team, clearly,” and I’m waiting for that subthread to kick off, too, to continue the denial.
Software complexity is the enemy, not the malicious actors exploiting it. Fix one, fix the other.
See the recent post on why the Uber app is so large: https://news.ycombinator.com/item?id=25376346
Either that or the cost of attacks will remain lower than the benefit of being able to sell bits and bytes to your adversaries. I do not expect this to be the case, but maybe.
The open, global, semi-anonymous web is what's not going to survive this fight, I'm afraid. I give it 20 more years, tops, and maybe a lot less.
Also IP-level blocks will never be perfect. See Hong Kong proxies. Or people in traded IP ranges classified as coming from another country.
Yes, some relatively slow, difficult, and expensive attacks would of course still be viable. That does not mean that, "it wouldn't change anything in practice."
> escalation through residential connections, existing international botnets
Right—so how are you going to talk to your botnet from outside the target sub-Internet when it won't even route packets you send it, except maybe to some hardened commerce-and-propaganda-only subnet that may have limited or no connection to the rest of the target state/bloc's Internet (and again, even that part existing is a maybe)?
I don't believe a complete separation would ever be possible. We'd have to put banks on the commerce side. But that means every single business entity would also have to have access to them. But most businesses also need access to the other side and will not do perfect separation.
In malware research labs you can find rooms literally painted in two colours to separate the isolated part and prevent joining networks by accident. Normal companies do not care that much. Most single-person entities will just plug both ends into one computer and go on with their life.
Two things that are surprising me in this thread: 1) "there are ways to work around this, so it's completely useless" (yes, that's... any security), and 2) either not a lot of people are paying attention to future-Internet development, as in actual, technical development and research, or they're not seeing what I'm seeing in them, somehow, as, for example:
Even if you physically firewalled every connection into a country all it takes is one little node connected via RF (satellite, HF, etc) dropped near an open WiFi hotspot.
There is nothing that guarantees the Internet will keep working the way it does now, and if an open Internet causes enough problems, it will be reigned in. How it works now is a choice, not a law of nature. I'm not happy about it, but that's just how it is. Either these kinds of attacks won't get much worse, or they'll get a lot worse and something like that will be what happens.
Again, I reckon it's either that or this problem never gets much worse. Given trends, I expect we're gonna lose the open, global Internet.
The real problem is that here, like so many other places in modern society, we've allowed consolidation to proceed far beyond healthy levels - when a single company is responsible for 20% of beef supply, it's time for antitrust action! (Yes, I'm looking at you, too, Internet, Tech, Media, Pharma, Aerospace/Defense, etc. companies...)
Maybe just allow one merger per decade, only available to companies with less than 10% of their market?
I expect the problem to be addressed with technology, treaties, extraditions and putting a lot of people in prisons before the fragility of consolidation is addressed.
The primary problem here is criminals and criminal organizations parading as nation-states. The secondary problem is systems and networks that are insufficiently secured.
Or it will just be home grown criminals doing the same thing.
Further, I think states are likely to use this both to prevent beyond-their-reach nationals from attacking infrastructure and citizens, and to curtail foreign astroturf propaganda efforts.
The ID stuff is something I don't think all states will adopt, but some might, even in Democratic states. I think adjusting backbone routing to allow easy network-wide black holing based on verifiable origin, though, is very likely to become widely adopted over the next couple decades.
awaits with bated breath
Great marketing, Equifax - they created the problem and tried to sell you the fix.
No thanks.
This is a 21st century hot war that we are losing badly.
Or they mop up, get bailed out, and then maybe make some minor changes that don't really solve the problem that their insecure corporate culture begins to undermine immediately. We need companies to essentially go into a perpetual cyber-security war-footing. I don't see that happening without business being impossible to conduct without it.
Voluntary pentesting is a good thing. Costly attacks executed by criminals is not.
Now that there's an actual financial motivation for random non-tech industries to have decent software, they might start to do so.
I get it, but that's a bit of a false dichotomy. That is, there's also valid pentesting and that's the good thing, as opposed to being attacked by criminals (bad thing). And, the purpose of standing up defenses would be to prevent successful attacks. So, if it's the successful attack that prompts those defenses, then it's already too late.
The bigger point is that, in general, I'm puzzled by the constant stream of people thanking the criminals and blaming the victims after each of these attacks.
I think people underestimate the complexity that has evolved over time in many company systems. Securing systems/networks is hard. Doing it retroactively with mountains of technical debt is even harder. The reality is that some of these companies don't have the wherewithal to do it and, even if they did, the timeline to getting them there would leave them vulnerable for some time.
So it sounds great, but very idealistic to say "hey this will help them harden their security". The reality is we need to stop thanking the criminals and support/protect our companies/agencies with a "layer" above their own security, including via deterrence at the nation-state level.
Like how we protect them from all legal consequences of loosing private information of millions of people time after time, such as recent Equifax and Facebook cases?
Or like how we allow companies to sell vulnerable routers, IP cameras, internet enables printers and phones with knows vulnerabilities at the time of release, and leave it without updates?
they are getting away with murder and you are asking for more protection for them? Maybe it's time to accept that this industry is greedy, arrogant and negligent in a way that's unmatched by almost anyone, except maybe hedgefunds.
"This industry"? Which industry is that? I mean, it's a tempting narrative: a big greedy industry, etc. But, this is not isolated to any one industry or any one company. These are attacks by foreign actors on a variety of our companies, government agencies, infrastructure, etc. And they result in real harm to our economy, infrastructure, and people.
>allow companies to sell vulnerable routers, IP cameras, internet enables printers and phones with knows vulnerabilities at the time of release, and leave it without updates
Again, this sounds like a compelling narrative, and sure, there need to be improvements. But, the reality is that the attack surface is vast and includes zero-days in well-maintained software, social engineering, OSS, custom software, network configs, etc.
In general, it seems like there's a lot of anger in your post, but none of it directed at the actual criminals (or their national sponsors) who are actually responsible for the attacks. That's really puzzling to the point where it almost reads like defending the criminals.
We have plenty of our own hackers and ransomware, i am not seeing how foreign-angle adds anything to the debate
"none of it directed at the actual criminals"
There will always be criminals. If a bank was robbed by two kids armed with a banana, then the real fault lies with the bank's management for being negligent, and every court will recognise it.
As it stands, most data leaks and hacks are not unpreventable zerodays, they are people being negligent and irreaponsible.
Large organisations need to change, and ignorance of the issue needs to be adressed. This is not just "there need to be some minor improvements"
The overwhelming majority of the recent, most notable attacks have been traced near-exclusively to foreign actors, including the one that is the subject of the actual thread here.
>i am not seeing how foreign-angle adds anything to the debate
Of course, it has everything to do with the debate. Specifically, with how we respond/deter.
>most data leaks and hacks are ... people being negligent and irreaponsible.
The attack surface is vast.
>If a bank was robbed by two kids armed with a banana
We're literally veering into cartoon territory here. Not sure I understand why you're working so hard to exonerate the actual criminals.
Most criminals are "foreign" because most of Earth's population is foreign.
"The attack surface is vast."
Because we made it vast. It could have been small.
"We're literally veering into cartoon territory here"
Yes we are, because spying on millions of people and then leaving that data unprotected is childishly irresponsible.
Ordinary citizens are the injured party, not companies. They have given up privacy and control over their devices. Even the software that runs on voting machines is copyrighted and secret, and when inspected, it turned out even the basics of security have not been followed.
Now that the chickens are coming home to roost, why are you so vehemently looking to absolve them of all responsebility?
It's breathtakingly hypocritical.
Here's the "foreign" part of the discussion from our "sub-thread" to make things clearer:
Me: These are attacks by foreign actors on a variety of our companies, government agencies, infrastructure, etc.
You: We have plenty of our own hackers and ransomware, i am not seeing how foreign-angle adds anything to the debate
Me: The overwhelming majority of the recent, most notable attacks have been traced near-exclusively to foreign actors, including the one that is the subject of the actual thread here...It has everything to do with the debate. Specifically, with how we respond/deter.
You: Most criminals are "foreign" because most of Earth's population is foreign.
Some hardcore goalpost-moving there. You went from "it's domestic and doesn't matter" to "it's foreign, but only due to a statistical artifact". You're talking in circles in your effort to absolve the attackers. And, it's made clear here that you're not just trying to lay the blame on U.S. companies; you're actively working to absolve/divert focus from the foreign adversaries who are attacking us.
Maybe you can explain why you find it so important that we blame only U.S. entities, whether they be companies or criminals. It's that criminal bit that gives up the game. This isn't just about a crusade against negligent companies. Your narrative seeks to lay blame with U.S. actors and absolve foreign actors.
But, FWIW, a disproportionate number of these attacks come from one country with a population less than half the size of the U.S. It's a country that has been engaged in asymmetric warfare with us. So, you're wrong there too: the foreign nature of the attacks is not a statistical artifact.
>Because we made it vast. It could have been small.
No. It's vast because it's vast. Complexity + interconnectedness.
Fallible humans are responsible for this and it's a problem that's grown over time. Probably every person who's written any significant amount of production code can be said to have contributed to the problem.
And, of course, there's no degree of effort that can defend with 100% efficacy, which is why we also need a deterrent approach.
>why are you so vehemently looking to absolve [companies] of all responsebility?
I've specifically stated that companies need to do better. You, on the other hand, have not assigned an iota of culpability to the actual criminals who attack us. Instead, you've worked against all-logic to absolve them (or, failing that, to place the criminals in the U.S.). It's a simple thing to say "criminals are doing bad things and should be held accountable". Odd that you refuse to say it. Odder still that, to the extent that you even acknowledge criminals exist in this problem-scope, you find it necessary to relocate them to the U.S.
Firstly, thats not an argument, its a tautology.
Secondly Attack surface is vast because we have shipped several billion locked down phones with known vulnerabilities and priprietary binary blob drivers, meaning they can't be updated. We could fix the problem overnight by voiding copyright protection on all software where vendor has abandoned uodates for a year or more.
It's not american companies, its the entire shithead industry.
"You, on the other hand, have not assigned an iota of culpability to the actual criminals"
Mate, they are criminals, they are culpable by definition, its in the Oxford dictionary. They have always existed and always will.
Whats the point of banging on about them like a broken record?
Even if Russia and China magically dissapear tomorrow, the problem will remain: if you have vulnerable systems someone will hack them.
Ita like if someone is always stealing stuff from your house, and I tell you maybe you should try locking the door.
No, it's a correction. You suggested that "we made the attack surface vast". The point is that you're wrong. It's vast due to actual complexity and interconnectedness. It's vast by definition.
>Secondly Attack surface is vast because we have shipped several billion locked down phones...
This again illustrates that you don't understand what the attack surface is, thus you believe fallacies such as "we made it vast". It's not a phone or single entry point. It's every bit of software that a system touches or is comprised of, including custom, commercial, and OSS. It's firmware and hardware and networks and configs. It's social. And, to some extent, it's those same vulnerabilities in systems that connect to a system.
Again, it's vast by necessity b/c our modern world depends on software, technology and interconnectedness.
>Mate, they are criminals, they are culpable by definition, its in the Oxford dictionary. They have always existed and always will.
So, this is your grand rationale for focusing all ire on the targeted companies vs the actual criminals? Your overall position then is that we should have no deterrent (why have laws at all?) and just lock our doors/secure our systems. If the inevitable criminals get you, then it's your fault.
>Whats the point of banging on about [criminals]?
Pretty obvious: to acknowledge they exist, are the actual cause of the problem, and need to be deterred/punished as part of any comprehensive solution.
>Even if Russia and China magically dissapear tomorrow, the problem will remain:
Actually, the problem would be substantially reduced to relatively nil. Just removing Russia alone would have a massive impact.
And, the solution-set becomes vastly different when fighting domestic criminals vs deterring state-sanctioned attacks from foreign adversaries.
But, here you are working hard to absolve the U.S.'s foreign adversaries again, "mate". Very curious.
>Ita like if someone is always stealing stuff from your house, and I tell you maybe you should try locking the door.
Another straw man. I've acknowledged repeatedly that we should lock the door. That discussion is over. What we're discussing is your position that we should not attempt to deter criminals (especially if they are foreign). Instead, they should be able to try breaking your locks with impunity and, if they succeed, then it's your fault.
Reality is not a single-round game.
> Doing it retroactively with mountains of technical debt is even harder.
Building mountains of technical debt is precisely the behavior companies need to stop.
> The reality is we need to stop thanking the criminals and support/protect our companies/agencies with a "layer" above their own security, including via deterrence at the nation-state level.
You can’t accuse someone of being idealistic and then turn around and say this.
The problem is the criminals can be anywhere in the world and can not be removed. When criminals are a constant, security is the only variable.
Perhaps, but we tend to trace the lion's share to one of very few places.
>When criminals are a constant, security is the only variable.
Security also comes through deterring would-be attackers. Security is not simply a posture of attempting to deflect as many attacks as possible. Ever play Missile Command?
In fact, that's disastrous policy. And, even if it were possible to get every company/governmental agency to immediately invest in massive security overhauls along with all vendors, OSS, etc. with near instantaneous results, some attacks will invariably get through.
Seems pretty obvious that we don't want attackers with 100% upside and no downside.
I predict that it is going to be used to get rid of privacy and anonymity features of the web and they aren't going to harden anything!
We dont need the internet to express ourselves freely but it sure sucks ass when you credit card is gone. I d trade your anonymity for my money back.
There's a reasonable balance to be struck. That's essentially the tradeoff we make with the state - trade some freedom for some security.
Personally, I view the opposite as closer to Law of the Jungle, that is our current system of policing that gives a small fraction of society access to self defense but denying it to the rest of the group.
well originally of course it was survival of the most fit (assuming we derive our aphorisms from evolution here), that can mean smartest, fastest etc.
There is no such thing as a level playing field, Harrison Bergeron has not been implemented.
Speaking from my vantage in the United States, I can't believe how quickly the population has become knowingly accepting and complicit with a mass surveillance culture. I'm equally concerned with how quickly ownership of purchased goods has been undermined by the server-client model of the internet. These two things are linked and fundamentally disagree with the basic premises the US believes itself to be founded on ...
It's hard to draw parallels historically in a way that gives hope. There is quite a lot of middle ground and reasonable solutions that just don't get mentioned in the political theater of today's corpocracy.
I know all this has basically become a meme on HN, but every government not following the EU's example and iterating on things like GDPR is implicitly supporting authoritarianism (if not explicitly) and setting up an oppressive future that their children will be trodden down by.
Also, I have not seen evidence that its effects have been nullified with its expiration, but I'm willing to learn.
They think it won’t be used against them, until one day it does, and they are horrified when a divorce attorney is talking about the GPS movements from their “connected car” or their bank closes an account and locks out their funds because they attended a political protest. Unfortunately for them the realization comes way too late.
Not to mention those horrified at finding out that even though they deleted their tweets and videos, the feds have shown up at their doorstep because they were in a rampaging mob in the Capitol, searching for elected officials to murder.
I wish there was a nice, easy answer on where to draw the line with surveillance. I'm actually glad that the insurrectionists left a zillion-mile wide electronic trail, but I'm all too acutely aware that these capabilities can be turned against anyone, and I'm dead-set against backdooring encryption. At least (US-specific here) there are nominally limits on what the government can do, but those limits are often ignored, and private corporations have much freer rein on what they can do with your data.
Why else would they bring smartphones?
Part of liberty is cleaning up the mess when some people take it a bit far, and moving on.
Yes, this'll be used to undermine anonymity (for example try getting a phone plan in many western countries without an ID - it's hard), however I believe there's still going to be a large push from governments and legislative bodies to push better security processes within private enterprise.
The Red Dawn style of hostilities is a relic of the past.
Meanwhile, the Chinese hackers and those directing their Information Operations are laughing their asses off that nobody points the finger at China first, despite numerous high-profile incidents of military-industrial-political espionage [1][2][3][4], the buildup of a gigantic blue-water navy, and tacit long-term goal of rivaling the US as the global superpower (and unlike the Russians, they've got the economy and manpower to make that happen). Nope, couldn't possible be them. Must be those dastardly Russians.
[1]https://www.justice.gov/opa/pr/former-ge-engineer-and-chines...
[2]https://www.theguardian.com/world/2016/jul/14/chinese-thief-...
[3](PAYWALLED) https://www.japantimes.co.jp/news/2015/01/19/national/china-...
[4]https://www.forbes.com/sites/nicholasreimann/2020/12/19/here...
> The U.S. meat industry is so consolidated that with JBS basically offline due to a cyberattack, the USDA can't publish wholesale price data without potentially revealing proprietary information about JBS’s competitors
The greater the consolidation, the greater the damage from bacteria outbreaks, or in this case cyberattacks.
This is the kind of statement where I need to ask this even here on Hacker News: source, please?
Before this latest blow to the supply chain I have already seen a 66% increase in brisket prices in the past 4 weeks ($2.99/lb about a month ago, current price is $4.99). The restaurant industry is already running on low margins so it will be interesting to see how this is all going to shake out.
There is a certain price (which I have generally found is $4.50 - $4.99/lb, that is when my food cost for a brisket sandwich hits 50%. Target food cost should be somewhere around 30%) where it just isn't worth it to sell brisket. BBQ is somewhat unique in that you have to estimate your demand ahead of time - you can't just throw on another brisket if you run out and I don't reheat/re-use leftovers. So even if I raise my prices $2/sandwich to cover the increased cost my risk is still higher because any unsold product is now a higher loss.
As long as they are safely handled I've found no quality difference at all when freezing stuff that is cryo-vaced. More often than not it has already been frozen at least once before it gets to me.
I don't ever sell anything that has been re-heated after cooking though. You can also do that with little to no quality loss but I try to position myself as a premium brand so everything is 'cooked to order'. There are also a lot more food safety concerns (cooing it fast enough, re-heating it fast enough, etc.) that I don't want to worry about. I vacuum seal cooked BBQ at home and it's just as good as fresh but you can't do that in a commercial setting without special permits that aren't available to food trucks (at least not in my area).
Matt's BBQ is the best Texas style bbq in Portland by a considerable margin. I've been a customer and friendly with him since he started out in a pawn shop parking lot with zero foot traffic and almost no road visibility. He charges $13.50 for a 1/2 lb of brisket, similar prices for other meats. Sides are typically around $3.50.
He's up to multiple locations and his own commissary kitchen that's like 2000 sq feet.
He sells out every single day.
It's been really fun to watch his business blow up. It's all been from the strength of his product, and his personal hustle to get the momentum. His customer base is loyal and willing to pay a premium.
He even has a side hustle selling smoker rigs, via a partnership.
It's a mixed race neighborhood. For the first couple years his neighbor in the pawn shop parking lot was a soul food cart. The clientele at both looked basically the same in terms of demographics.
While you won't find as much good BBQ in Portland as say central Texas, the Carolinas, etc, it's not some sort of exotic novelty.
I don't know why you are so determined to stereotype this stuff, but it is not helpful.
It is a statistical impossibility that any given group in Portland is the same as any given group in Texas on the metrics I mentioned, so your claim is really that these metrics don't influence price sensitivity.
It's statements like this that are revealing:
> People do value authenticity in my town. The big corporate chain restaurants are a lot more sparse here, exactly because the local places are just as cheap, far higher quality, locally owned, and using local ingrediants, etc.
There's no trade-off between chain restaurants and locally owned? The latter is just an unalloyed good and other regions of the country are just making mistakes for no reason? So no, I don't find your analysis convincing, but as I already said I appreciate your input in the discussion.
Just. Stop.
I never made any claim about blanket superiority, just described factually what this place is like. You'll find plenty of people and even data supporting that characterization if you want.
Likewise I did not claim anything about equality with Texas, just that your utterly naive assertion that the customer base for the food cart I mentioned must be slanted a particular way, based on literally nothing. It is not.
In any case, it's clear continuing this line of discussion is pointless.
People in Portland and other liberal cities will paradoxically pay a premium for "poor people" food. When you are wealthy enough to consume whatever you want, the rarest commodity is something that feels like an authentic, meaningful experience. Cuisines that come from poor areas carry that sense of authenticity with them and can charge appropriately.
I don't think you can assume that pricing model will work well outside of a few places like Portland, SF, NYC, Seattle, LA. People that aren't wealthy enough such that they do care about food prices aren't going to pay extra because a brisket is served on a just-so-cute-and-"real" metal tray.
Food carts in Portland are extremely informal and very much a thing for everyday people, including people with low incomes by local standards. In fact it's one of the main drivers of their popularity here.
It's not a matter of wealthy people adopting "poor people's food" as a novelty. It's just good food no matter your situation in life. Matt is charging on the higher end, and a complete meal is still under $20. The best burger in my area is a double bacon cheese for $4.50 that uses really quality ingredients.
I've talked with customers at Matt's that live out in the country and make an hour plus drive to come by every once in a while.
People do value authenticity in my town. The big corporate chain restaurants are a lot more sparse here, exactly because the local places are just as cheap, far higher quality, locally owned, and using local ingrediants, etc.
The genesis of the food cart scene here was the city has some smart policies about making it affordable to start these businesses. Many people who dream of someday having a restaurant start out this way. You can make a serious shot at it with just $50k or so, which is tiny even by small business capital standards. They price their food accordingly.
It's true this place is getting more expensive, but I assure you, if you go out to any of the pods, you'll see a roughly even mix of people who are middle class, and young people that probably make barely enough to cover rent at a service industry job. Everyone will be hanging out, friendly and chatting.
Please don't project your own assumptions onto this scene if you've not been there. This town is pretty grossly misrepresented by a wide swath of media.
I don’t have any plans to go full time with BBQ anytime soon but that’s exactly the model I’ve looked into.
Perfect yesterday BBQ meat! Coming from USSR/Russia with its food shortages in 198x-first half of 199x i still kind of mentally shudder reading such things even after 21 years of living here.
I’m only open once or twice a week so secondary uses (beans, chili, etc) unfortunately don’t work for me.
This is really not true anymore. BBQ has become a high-ticket item thanks to “Craft BBQ” and growing demand
https://www.khou.com/mobile/article/news/brisket-prices-are-...
When a thing becomes trendy among moneyed demographics there is now stupid money to be made selling a caricature of that thing to people with too much money. BBQ is one of those thigns becoming just another experience for yuppies to talk about in the break room on Mondays. When you're running a BBQ joint you're not selling meat cooked in a particular style, you're selling an experience. People don't care about whether your BBQ is a career long refinement of what grandma made. They care about whether it's something they can brag about. They're looking for an experience and if you want to stay in business you're gonna sell it to them. It's not about doing your thing well, it's about presentation and show. Many of the people running these restaurants hate bastardizing their craft and leaning into an image/stereotype like this but it's what pays the bills.
Maybe I'm just jaded from growing up in a tourism economy but money uncritically thrown at something tends to ruin it.
When I go looking for a restaurant I go for <censored>, <censored> and <censored>, because those three genres aren't trendy right now and any business specializing in them has to succeed on its own merits, it can't just print money by looking the part.
I generally consider BBQ competitions overblown affairs that are arguing how many angels can dance on the head of a pin. To me, after a certain point it is quite good enough, and any further optimization for "better" doesn't pass my personal cost-benefit filter, and I'd rather spend the cognitive effort on my dining companions.
It is either that, or I possess a philistine palate. The latter is quite possible because I hold a similar opinion of many of the fine dining establishments I've eaten at, from quite fine kaiseki, omakase, Chinese, Michelin-starred French, various fusions, steak, and other restaurants, some with pretty eye-popping per-diner prices. That's mostly because I believe that we're at the nascent, fragile stages of achieving post-scarcity (by no means assured, and still many generations away), and part of that journey involves the elevation of increasingly finer experiences (perhaps some requiring ever-greater cognitive effort to appreciate that I'm not aware of) to a mass market.
Was this just a joke or are you genuinely censoring your own opinions on what food you like because you're scared of them becoming more popular?
Huh? The cuts are tough, yes, but they're also the most flavorful. There's nothing bad about them.
Go try and use a ribeye to make a cheeseburger sometime. It's incredibly bland compared to the flavor you're used to getting from chuck.
From: https://commoncog.com/blog/cash-flow-games/
"Food costs money. But the way that everyone (in the F&B industry) looks at food costs, and paying for food is very weird. When COVID started, every famous chef that went on TV said, “This is the kind of business where this week’s revenues pay for bills from a month ago.” So when we started to bring in money from deposits and prepaid reservations, I suddenly looked and we had a bank account that had a couple million dollars in it — of forward money
"I started calling up some of our big vendors for the big, expensive items — like proteins: meat, fish; luxury items: like caviar, foie gras, wine and liquor, and I said, “I don’t want net-120 anymore, I want to prepay you for the next three months.” And they had never had that kind of a phone call from a restaurant before.
So how much should they discount it? So let’s say we’re going to buy steaks. We’re going to pay $34 a pound wholesale for dry aged rib-eye, we get net-120 (normally). So I call the guy and say “I’m going to use 400 pounds of your beef a week for the next 4 months, for our menu, which is about about $300,000 of beef, what (would) we get, if we prepay you?” And he was like “what do you mean?” I’m like “I want to write you a check tomorrow for all of it, for four months.” And he was like, “Well, no one has ever said that.” So he called me the next day, he said “$18 a pound” … so … half. Half price.
I went, “I’ll pay you $20 if you tell me why.” And he said, “Well, it’s very simple. I have to slaughter the cows, then I put the beef to dry. For the first 35 days I can sell it. After 35 days there’s only a handful of places that would buy it, after 60 days, I sell it $1 a pound for dog food.” So his waste on the slaughter, and these animals’s lives, and the ethics of all of that, are because of net-120! Seems like someone should have figured this out! As soon as he said that, everything clicked, and I went “We need to call every one of our vendors, every time, and say that we will prepay them.”
Scale matters.
That is an excellent idea (having more than just a transactional relationship with you food vendor is a good idea in general) but my volume is way too low to have that type of leverage. The best I can do (and fortunately what I did when I saw the prices increasing) is pre-buy and freeze as much as I can to lock in the then-current pricing. Right now food supplies aren't even able to fill many wholesale orders because they don't have enough supply so I'm not sure pre-paying would help if they can't even get the product. For example one major vendor has changed their order cutoff time from 11PM to 5PM so they can spend that extra time allocating their available stock across all the orders because they don't have enough for everyone.
BBQ is my side hustle so I'll be ok either way - but if I was paying my mortgage via food service I would be alot more concerned.
Also, just thinking aloud, during normal times, if you happen to know other hobbyist BBQ folks, I'm wondering if there might be opportunities to enter into an informal group-buying situation where you pool your collective brisket demand and bulk buy at a discount. That wouldn't work right now but perhaps it might during normal times. There are websites based around this idea. Best of luck.
https://news.yahoo.com/nick-kokonas-pivoted-hard-onset-19010...
COVID is weird in that it doesn't have a uniform effect on everyone.
I still have my tech job and don’t plan on going full BBQ anytime soon. I do it enough that it keeps me busy but I can always say no to a catering job or event so it’s still enjoyable and not a chore.
The right opportunity would have to come along for me to jump onto the restaurant world. It’s definitely something I’ve looked into but one thing I have learned is that the BBQ is the easy part of running a BBQ business - it’s everything else that is tricky. Right now I don’t have to worry about employees, rent, etc. so someone with those strengths would have to make a pretty good pitch to get me to open a restaurant.
I’ve being doing BBQ professionally for 10+ years. It started out just done some small catering jobs and has grown from there. Through BBQ I’ve been able to do lots of cool stuff that I would have never imagined when I started. I was heavily involved in competition BBQ for several years and through that I’ve worked with several big brands . Currently I’m focused on my food truck and rub and sauce products. I’ve also done several BBQ classes and hope that as we turn the corner on COVID I can start that up again soon.
https://www.statista.com/statistics/198206/share-of-leading-...
https://shippingwatch.com/carriers/Container/article12930338...
[1] https://www.reuters.com/article/us-cyber-attack-maersk-idUSK...
https://www.wired.com/story/notpetya-cyberattack-ukraine-rus...
But the lack of backups is just a symptom. From the article:
In 2016, one group of IT executives had pushed for a preemptive security redesign of Maersk’s entire global network. They called attention to Maersk’s less-than-perfect software patching, outdated operating systems, and above all insufficient network segmentation. That last vulnerability in particular, they warned, could allow malware with access to one part of the network to spread wildly beyond its initial foothold, exactly as NotPetya would the next year.
The security revamp was green-lit and budgeted. But its success was never made a so-called key performance indicator for Maersk’s most senior IT overseers, so implementing it wouldn’t contribute to their bonuses. They never carried the security makeover forward.The local delivery may lose on end price, but they also provide a ton of structural benefits. Usually the cost savings the customer is pretty marginal compared to what has been given up.
Centralization leads to systemic risk, as we see in this case.
Oh wait
Consolidation gives you consistency, network effects, and economies of scale. But it also gives you monocultures, stagnation, and overfitting.
Heterogeneity and competition gives you incentives to optimize, innovation, and robustness. But it also gives you redundancy, knowledge loss, and inefficiency.
Essentially, we have a very weak correction incentive. Until capable hackers are endemic and ransomware hits everyone, there is little likelihood of change. Next week it could be RJR Nabisco, or Synnex/TurboTax/DuPont, or just 10,000 variants of {tiny $20m company that makes software for auditing sewerage pipe and is used by 370 of the 3000 counties in the US, and every client gets the DB corrupted}.
For much of human history, consolidation was natural but the relative simplicity of technology kept barriers of entry low which enabled competition and new entrants. Also, poorer logistics and transportation meant you have many smaller semi-independent markets instead of fewer monolithic ones.
Industrialization and powered transportation upended that and gave a lot of power to consolidation. That led to the era of robber barons.
That power concentration was so bad for society that eventually the labor and antitrust movements came around to somewhat correct it.
I think now we're seeing another oscillation. Software creates huge network effects and economies of scale. If a business writes a single program once, they can run it on as many servers or sell it to as many users as possible. Services that let users interact benefit exponentially from network effects. AI generates a lot of value, but requires extremely large datasets that only the largest corporations have access to.
We are essentially in the era of digital robber barons right now. Six of the top ten richest people in the world according to Forbes got there through software. (Arguably seven if you consider Musk's wealth to be software-driven.)
We are clearly nowhere near the optimal point on the consolidation continuum. With luck, we'll get something like an "information labor movement" and more teeth in our antitrust regulation to correct that.
But that's different from other problems where you can simply try to optimize the result itself directly. For example, we probably don't need to have hard discussions of trade-offs when it comes to, I don't know, infant mortality. There's almost no upside to babies dying (assuming you aren't heartless enough to consider less overpopulation to be an "upside").
But with business size, there are many desirable factors and improving any of them reduces another directly opposed but also desireable factor.
Competition is good. Cooperation is also good. Increasing one by definition lowers the other.
I very much enjoy the fact that I can go to nearly any city in America and they'll have a few dozen well-known stores with recognizable product.
There are certainly bad forms of consolidation, but it's easy to overlook the good forms.
Many attacks aren't truly targeted, they're blanket ransomware attacks trying to hit any entity they can.
Also, meat packing isn't critical infrastructure. It's important, sure, but nobody is going to die if they don't get meat. Food overall, yes, but meat is a luxury good.
There's a lot of calories in meat.
By volume I think there are quite a few types of food that are richer in calories, and a lot of times meats are rich due to how they are prepared (fried, or drenched in butter, etc.)
271 Beef
265 bread
247 Roast chicken, skin on
130 black beans
110 rice
57 Apples
35 Broccoli
The meat industry is a strain on the food pipeline, losing it would free up other parts of the pipeline and feed more people. https://en.wikipedia.org/wiki/Environmental_impact_of_meat_p...
I eat meat, but the parent is correct, it's a luxury.
*edit: confused by all the downvotes. Am I incorrect, or being somehow offensive?
Unless you've discovered a very neat chemistry trick that would also make fuel much cheaper.
Maybe worth mentioning that poultry feed is grains and "mostly" edible in theory (though maybe not in today's practice), and poultry is the largest segment of meat in the US?
Also relevant are that per-capita meat consumption in the US has gone up dramatically in the last 50 years, and so has the average caloric intake. Looking at history, it seems like we have room to downsize some, right?
Yeah, some of them definitely. We fed our chickens a fair bit of wheat, which of course makes good bread. Plenty of field corn too, which... I guess if you like corn chips as much as I do... okay! Poultry and eggs might be better for you than loading up on grains though.
> per-capita meat consumption in the US has gone up dramatically in the last 50 years, and so has the average caloric intake
Perhaps as little as double those fifty years ago it would have been unthinkable that even the poorest among us could be troubled by obesity. We live in an age of riches and I guess we're still figuring out how that works. What a problem to have, though!
> it seems like we have room to downsize some, right?
This is perhaps the most amusingly uncontroversial thing I've read on the Internet lately. Thank you
https://wwf.panda.org/discover/our_focus/food_practice/susta...
You could completely strike meat from everyone's diet and still feed everyone.
Plants are mostly cellulose, not sugar.
To satisfy our consumption of beef using grass-fed grazing, we'd need surface area of like 2.5x of earth just dedicated to that. Most beef is not grazing, it's kept in intensive farms and being fed factory produced feed, made with lower quality crops, i.e. corn and some processing by-products.
But most meat is not beet, it's chicken and pigs, and they can't digest cellulose - they eat same stuff we do.
So for 95% of meet, the OP is correct, it's is a luxury and a strain on our food system, with a giant carbon footprint.
This is like saying "nobody is going to die from making 10% less money". In a sort of literal sense it's true, but in a more useful sense it's going to increase mortality at the margins (via nutritional deficiency, in this case). Meat is a luxury in the same way that bathing water or enough sleep is a luxury.
Meat is relatively new in terms of accessibility to the global population. Especially in the size of portions and frequency in consumption.
So is the Flynn effect and low infant mortality.
And many companies probably don’t consider themselves a likely target until after it happens.
I agree with the rest of your comment but this strikes me as a strange question. Programmers if anyone should realize that you can't always 100% selectively give "good guys" access to something easily without also opening up potential weaknesses for "bad guys". Especially when it comes to large transfers or other essential information, it has to be secure and private for the participants and the participants only.
We can't add selective control to allow just government agencies to stop cryptocurrency transfers, it'll eventually be used by others, one way or another. The only way of stopping anyone from being able to straight up manipulate the chain is to disallow anyone to manipulate the chain.
To get over the hump, there’s a large amount of cost center and infra spending, and then basically exclusive focus on tech debt-like activities for a few quarters to get everything in place. If the cost was manageable, imagine being on the receiving end of the attitudes you, or hopefully not you but some of your coworkers put towards helping implement these changes as the infra fixes cross so many departments.
That’s snark aside, just a candid take.
If it was fixable like that, the other issue is IOT doesn’t really have a standard platform to build on that’s secure. The equip leaves a factory in Shenzhen and like who is patch managing that? The producer in China? That activity goes on behind the scenes at company by a security team.
Good news is MSFT and AWS are starting to deploy COTS IoT operating systems to help fix.
So: crazy tech debt to fix, hard patch/support problems, and then (unmentioned) is ICS pay for security engineers is a About half of market, so talent problems abound.
First you scope out attack surface. If you can physically penetrate security there are all manner of attacks you can accomplish and connectivity you are able to achieve. You might go to a search engine like shodan (https://www.shodan.io/) and discover some internet exposure that is attackable. You might find e-mails and start phishing/landing trojans. You might be able to execute a supply chain attack (ala solarwinds). You might be able to compromise an employee. After you compromise the corp network you might figure out how to escalate into the infra network.
Now you are a company. You have limited resources. Security is not your business. Security is only a "cost." Tech isn't your main business so you need to hire a security minded person without a strong ability to vet them. That security person needs to scope the attack-able surface, model the above risks and more, and implement preventive measures. That person will probably be hired well after infrastructure is already established. That person will have to justify the potentially large resource expenditures involved in solving problems and hiring more security engineers. That person will be a very limited resource and therefore very expensive since our universities don't pump out a lot of security experts. This person will probably have a market rate of well over 300k a year. That person's competence will likely directly correlate to time spent in industry, so new grads probably wouldn't cut it. Maybe you decide to see if companies will sell you solutions to this problem. How do you separate those selling security theater from those who will legitimately solve your security problem?
So, if you are the business owner at what point do you decide, "wow, we need to spend a lot of resources (time, attention, and money) on security." After some number of employees? After some dollar cost in business? After some position in industry? When a competitor is breached? Unfortunately the de facto answer appears to be after the first major [embarrassing] incident.
Imagine you appear to have had impeccable security and are spending 10 million a year for it. How do you know you are making good on your investment? How do you know 5 mil isn't good enough? How do you know you haven't already been deeply breached by a very competent APT?
Unfortunately, the reason we haven't solved the tech problem is that it is an arms race. This stops the problem from fundamentally being a tech problem, but instead a problem of incentives.
Taxing poor security via government run pen tests with fines (forced bug bounty), that grow as the number of vulnerabilities are found is a system that might change incentives. Indemnification for (maybe only accredited) white hats might change incentives. Regulating all companies to be part of a bug bounty program might change incentives. Legally requiring breach insurance might change incentives. Alternatively there are probably small fortunes to be made to the first entity able to solve corp net as an economies of scale problem (AWS for corpnet).
To answer your question directly. We currently have a system where the average business owner is either uninformed, ignorant, or has calculated cost to be greater than risk, resulting in lower resource expenditure than required to solve these technical problems resulting in poor security that directly puts national security at risk.
That isn't, of course, to say that there shouldn't be precautions regardless. But it's not the internet, and it lets you transmit information at a distance.
Overly dramatic and inaccurate as far as I can tell.
Something like a contagion introduced into the facility might warrant a "Wiped Out" description but "Production Paused" seems more accurate and informative.
I'm now starting to think that it's necessary.
I know a lot of people will just say that these companies just need to pay attention to security, but the problem is asymmetrical.
Focusing on security is like being a pacifist when dealing with a hostile bully. You get your butt kicked a lot.
Honestly, "business-focused" decisions like cost-center accounting, and various schemes to save money, are really how we got into this mess. A lot of our appalling lack of computer security basically comes from the equivalent of a hospital administration refusing to allow surgeons the time to wash their hands.
As "reductio ad absurdum" of a metaphor as that seems, that was actually the huge culture battle that got fought when germ theory came out - tons of medical practices refused to waste time on such "silliness". Over time it became a cultural norm, and then became a protected practice through professional guilds, and through law, so that even if hospital administrators push for surgeons to hurry up and fit more patients into a day (and they do), their prerogative to take their time and do it right is institutionally protected.
We don't have anything like that in programming.
1. Has enterprise-grade auditing and report generation. For what? Doesn't matter, nobody reads them.
2. Has an account manager for every open port.
3. Has IBM/Oracle style exponential cost increases for locked-in customers.
They exist. Radianz, BPIPE and several more.
It doesn't do any good if your secretary needs access to the "business focused internet" and also has to get mail from the "normal" internet. The transitive nature of networks makes things very hard to isolate in practice. People and businesses are going to have to accept a lot more inconvenience to isolate things better, and that inconvenience is real money, too.
The problem is you end up with yet another manifestation of a common business problem; if you take the time and money to build a secure business, that carefully isolates everything correctly, that hires good security engineers, that accepts higher costs of doing business, you'll be in a position to handle a cyberpocalypse better than your competitors and you will reap the benefits when that day comes. The problem is, you'll never survive to see that day come because you'll have been utterly outcompeted by your competition that cut corners and carelessly, but effectively, integrated their systems, and over-optimized their internal systems to function more cheaply day-by-day. You may have taken the time to build on the rock while they threw shacks up on the sand but they end up killing you before the storm comes.
Not of everything. Just the important stuff. Maybe a snapshot of the whole business once a month in addition to transaction backups.
Any business doing financial transactions should be backing them up to something like Blu-Ray disks. Preferably the blanks with the 1000-year lifetime. US banks are already required to do something like that, by the FDIC.
For one thing backups are no use if you do not test them. How often are you going to bring your systems down to test restorinig from backup? If you do not how do you know they work?
Those systems aren't simply deployable overnight, and I would presume that for at least half of these systems the enterprise never ever had the capability to deploy them, the initial install was and configuration done by a combination of vendor engineers and outside consultants and took six or more months. Sure, you'll recover the data eventually, but you'd rather pay a ransom to avoid as much downtime.
A lot of these businesses have been around for decades and are working on mountains of technical debt. They built ad-hoc systems over the years (before security was "a thing"), employ tenuously-functioning integrations with acquired company systems and more. To make matters worse, much of the technical knowledge has walked out of the door over the years.
In my consulting days it wasn't unusual to find that no one in a company really understood how systems worked (or even why). And, in some cases, they actually didn't work. I've seen billing systems that were unpredictable and relied on customers to call to report billing errors. Not a single person in the company even understood how it was supposed to work.
And, these were sizable companies. Agile has only exacerbated these issues as more software is built more quickly and with scant documentation.
All of that to say that it's difficult enough for many companies to build functioning software, let alone to secure it. And, the number of people who truly understand what it takes to secure networks/software is tiny relative to demand for engineers.
Throw in OSS, zero-days, social engineering attacks, etc. and it starts to become clear that any realistic solution includes a regime of deterrence through aggressive responses at the nation-state level. Sure, we should require companies to do more to secure their networks/systems, educate on best practices, etc. But, it's easy to issue an off-handed "they should've been more secure" response. The reality is that many companies simply aren't. We need to appreciate the difficulty and the protracted timeline over which any hardening might happen (if at all), and deploy a multi-faceted approach that also treats the problem as the national security issue it represents.
That sounds a lot like "do not connect one's valuable and vulnerabe machines to the open internet" which is something one should aready be doing in the first place and one can and should be doing it right now with the current internet we have.
Further, this should be a wake up call. If you're a business harden your network and make backups.
There’s a reason people hire these intermediary “consultants” to pay the ransoms.
Edit: doubly so if the company is question is part of important infrastructure (including food supply).
Ugh. So you get attacked through some old wordpress install, freak out to get your company online, pay, now you also go to jail for paying a ransom. Not a fan of this plan.
But yeah, companies should stop viewing security and IT as a cost center and start paying up for good penetration testing every few years.
They don't need ransom if they can buy put options.
Buying puts in this fashion will generally be a remarkable, traceable event. There's a reason ransoms typically go through cryptocurrency.
Yeah that's a nice fantasy. "Hands up, Russky bastards, the Navy Seal Bin Laden crew is here to take you out." Shoots up a row of laptops while bearded Russian hackers cower in fear.
Except for that to happen the Seals would have to have reliable intel from inside an uncooperative foreign state, and the ability to move freely, carrying guns, in that foreign state; and if they raided in it without permission, that would be an act of war.
Thanks god we have nuclear weapons, otherwise we'd definitely experience another incursion like Iraq or Afghanistan, that were made under absurd pretexts and only led to great numbers of civilian casualties and some economical gain for the US and/or US government officials tied to the military complex.
Or to sell routers, wifi printers, cameras and smart TVs with known security flaws, and to leave it without updates.
Then respond with force, arresting people, targeting however you can.
After a few minutes of ineffectually pondering the occurrence, we restored our latest database backup which was maybe half a day old and then beefed up our passwords and network security. The ransom note went straight into the trash.
So I wonder, does "ransomware" refer simply to an attack like the one I experienced or something more sophisticated. Do all these companies just not have secure backups?
Today, I was finally able to incorporate the "Where's the beef!?!" catch-phrase into daily conversation! But, it just didn't land as funny as I was expecting in my mind.
(First thought was for the poor IT folks stuck in this mess and the second was remembering a sensitive machine that was open to all of AWS because the vendor’s servers “needed access to push frequent updates.” and “nobody has ever pushed back on that requirement before.”)
These hackers sure are progressive. I wonder what they'll target next: plastics, flights, or ammo?
I wonder if a similar sort of reaction will happen here or if the attackers will move more quickly?
From a technical standpoint, why was JBS' backup chain a workable solution for JBS and not for the pipeline operator? Was it incompetence on the part of the attacker or just a better defense, or luck?
There is still no clue as to why these disruptions happened but the educated guess mentioned in the article is ransomware. The one that is almost always forgotten is how they they escalated privileges through compromised passwords because most of these organizations don’t use multi factor authentication everywhere.
https://en.wikipedia.org/wiki/Bovine_spongiform_encephalopat...
Still a form of information warfare attack, perpetuated by none other than Neil Ferguson, operating in plain sight. If he was a hacker he would be in prison but he does incalculable damage again and again and gets away Scot free every time!
Can that really be called an "attack" ?
JBS said:
not aware of any evidence that any customer,
supplier, or employee data has been compromised
So the "attackers" didn't steal anything. Give them the finger then, restore from backup, get upset about losing 25 minutes of data and keep going.How are ransomware "attacks" still a thing ? Why is any of the software that controlls meat-cutting/oil pipeline hardware not air-gapped under normal operations? How is there no plan on how to continue operating when losing power, so that stuff still works?
One of these "attacks" pops up every three days and I get that if data is exfiltrated then the problem is not the same.
BUT
"someone encrypted all my data" and "oh shit, my harddrive crashed" have almost the exact same recovery plan and we have dedicated a complete international holiday called World Backup Day[1] over ten years ago to remind people of the principles of how that works that were known since at least when harddrives where invented.
It's not an attack, it's pure negligence.
It's not special IT SuperHighTechnologyKnowledge either. It's a simple principle:
Things need to exist in at least three places in case one of them breaks and the other explodes/tornadoes/earthquakes.
The slightly advanced corollary is: Make sure that the thing in the three places is actually the thing that it should be.
... It's not like I do not understand how organizations fail at this that or the other and that maybe the tradeoffs here were made correctly, but it still boggles the mind.[0] https://townhall.com/tipsheet/leahbarkoukis/2021/06/01/cyber...
It is cheaper to build a shoddy system out of the pre-made parts that software companies sell. A shiny very capable system can be built quickly, and cheaply.
To build a robust system, segmented, properly backed up, maintained professionally... costs a lot more.
To have staff on your payroll who understand your systems, who can maintain your systems and recover your systems in a disaster means having expensive professionals on the payroll who look like they are doing nothing.
When your whole business goes into a paralysis because of the costs you saved, there will be some one to blame. Some clerk in a office that "clicked on a attachment" - it is their fault....
Yes, it is cheaper in the long run to build robust maintained systems. But in the long run we are all dead, and our bonuses will be paid before the catastrophe, and anyway it is "some body else's fault".
It's always a weird phase. A proper one would be "we have no records of data exfiltration, so we hope it didn't happen". Attackers had the access, otherwise the data wouldn't be encrypted.
> restore from backup, get upset about losing 25 minutes of data and keep going.
Unless you want to be owned again in 30min, you need to first analyse how did it happen the first time and how to mitigate it, before getting everything back online. That takes time.
> Why is any of the software that controlls meat-cutting/oil pipeline hardware not air-gapped
None of those were affected. The pipeline hack took their billing system down, not the operations. I haven't seen the details here, but it's not like the meat saws and trucks just stopped - more likely the stock/communication/billing system was stopped as well.
It is interesting how many companies end up paying $30M for pre-packaged garbage when they could get something a lot better by hiring a competent IT/developer for a few years at 10% of the cost. I think the biggest impediment is finding the small fraction of people who could actually pull it off; there's a huge opportunity there for anyone who can figure out how to connect top-tier devs to companies who just need to hire one person and don't have the domain expertise to know who/how to hire.
Even exfiltration seems less dire in these recent cases than it would in other industries. If anything, beef carcasses seem less likely to require HIPAA or PCI compliance than gasoline deliveries...
EDIT: ok bad idea, lets take it easy on my poor account :)
I'm sure the various 3 letter agencies (NSA, CIA, etc) are already involved to a degree that's not publicly known.
How would you feel if they decided to declare some enemies on US soil and start hunting them on your patch?
Unless your assumption is that Russia/China would agree to the hunting of course, but that does seem unlikely.
Anything has risk of course, any hunting need be covert and expertly done.
>How would you feel if they decided to declare some enemies on US soil and start hunting them on your patch?
I would assume they already did that.
Reminder: Memorial Day was yesterday and this thread is discussing killing human beings in yet another war because of holes in some stupid software that SV won’t lift a finger to fix. If you offer such a suggestion to fix the woes of vulnerable infrastructure, I’m assuming you’re volunteering to go pull the trigger, right? Or were you expecting someone else to do that for you?
Put down the assault keyboard and Clancy novel and get some perspective, subthread. Sheesh. Diddling around in the network of a company you didn’t know existed until five minutes ago is suddenly a capital offense because...Whoppers might run out?
However, it is also not merely about the Whoppers running out - this is just this morning's example.
When even major "security" vendors can be turned into serious NatSec attack vectors, and much more critical infrastructure can also be attacked with ease, and they are doing it, it becomes a bona-fide NatSec issue.
Like any other NatSec issue, this requires both serious hardening actions at home, and serious threats against bad actors abroad. Whether that involves, some kind of diplomacy, economic sanctions, targeted software attacks, targeted covert actions, or overt drone strikes, is up to the experts in those domains, but we do need to treat this as a serious NatSec issue that it is.
It absolutely is and must be a viable component. Those increasingly connected people are also increasingly vulnerable in real-world ways that go well beyond tech. And, it is near impossible to completely secure networks/systems with their near limitless attack surfaces.
Treating it as a game of cat and mouse in which you know the mouse will invariably lose with some regularity, then consigning yourself to ever playing the mouse is disastrous policy.
Very few. So few that they literally encode checks for RUS language / keyboard installs and skip that machine, and doing such install is at least for now a legit security measure [1]. This isn't just from RUS legal structure and no extradition treaties, but their very intimidating response to anyone acting up internally (I've read of at least one instance where a hacker was found dead at his keyboard with missing hands). RUS security doesn't eff around, and we shouldn't either.
Many people will not play at the pointy end of the NatSec game because you are risking your life, and some do because of that. It is definitely a useful measure, among others, to make it known that trespassing with such intent on western computer systems is also getting you into that risk category.
[1] https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...
We know the stakes are much higher. We all know there have been attacks on hospitals, law enforcement systems, government agencies, infrastructure companies, etc. And, we know that none of us have a clue where the next attack will be.
>and stupid legacy cruft that is modern software development
Yes, modern software development is stupid, crufty and all of those things. But, these are actual attacks by actual actors, not some self-imploding poor designs. In many cases, these attacks are state-sanctioned, if not outright state-sponsored. So, of course they should be treated just as we treat other attacks. And, under what other scenario do we respond to an attack by declaring "Oh, you got us. We should have better protected that".
These are clear national security threats and should, accordingly, be subject to the full range of responses as any other threats. That includes deterrence. It doesn't necessarily mean dropping bombs. But, it does mean more than blaming ourselves.
>Diddling around in the network of a company you didn’t know existed until five minutes ago
I'd wager there are many companies that the average person has never heard of that, if knocked offline, would result in considerable disruption, economic costs, and even physical danger to a significant portion of the population.
How fragile are we as a nation if a group of profit motivated hackers can shut down oil pipelines and food production?
What happens when a hostile nation state or terror organization actually wants to do some damage and isn't interested in negotiating with insurance companies for a few BTC.
Maybe if the DHS was focused on actual threats instead of cosplaying as SS we would be prepared for what everyone knew was coming.
This is the kind of false narrative that spreads like wildfire because it rests on a morality play we all love about how a small number of those people are ruining it for everyone else.
In reality, the toilet paper shortage was caused by people using their home toilets instead of office ones. Office toilets use different toilet paper (those giant rolls of pretty scratchy paper). Those rolls are manufactured on different lines, shipped through different supply chains, and sold in different stores. Paper companies have incredibly thin margins, and it took a while for them to retool and shift over to the new reality. The shortage was just the dip while that was happening.
Basically, sales of product A (residential TP) skyrocketed while product B tanked (office TP). No surprise that it became hard to find A in stores.
Hoarding didn't have a significant impact. (Think about it, how could it have? The shortage was a few weeks long. Think about how much toilet paper a small number of hoarders would have to have to cause a shortage of that scale. Did they literally fill their entire house with rolls?)
In this case, too, rational people will substitute other proteins for beef. As a beef producer, I'm glad most Americans aren't completely rational consumers.
If this were a movie, I'd suspect climate terrorists.
I still see things attacks on open SMTP ports to relay spam email, installing crypto mining software on PCs and servers, scanning for insecure VoIP phone systems and racking up long-distance phone bills..
The ransomware attacks makes a lot of headlines I think because it's somewhat easy to sensationalize without a lot of explanation of boring IT stuff, but there are still plenty of other things happening regularly to compromise insecure systems.
2) Terrorism. Really, I consider this the same as warfare, just coming from "terrorists" instead of "countries". With this broader base of attackers, I think there are groups that would be willing to do so. The only question is if they have the technical know-how. Given how cheap these ransoms can be ($4.4 mill for the pipeline hack), and the fact that a payed randsom probably a good profit margin, in terms of raw funding, these hacks seem within the range of terrorist groups.
We can see this by the fact that just a few years ago they would take down the same types of companies they are hitting now and ask for a ridiculously low sum of like $10k, but now they are asking for a much more reasonable, but still low $1M. Nothing changed about who they were attacking, they just slowly realized that they underestimated how much companies would pay for their "services" by a factor of 100x. That is a classic mark of a business amateur who has no idea just how much money is involved in B2B deals.
But to your underlying question, yeah, it is probably ransomware.
And now Bloomberg is reporting it was a ransomware attack -- "It’s unclear exactly how many plants globally have been affected by the ransomware attack as Sao Paulo-based JBS has yet to release those details."
> A CNN White House correspondent reported on Tuesday afternoon that JBS told the Biden administration it had received a ransom request from a criminal organization “likely based in Russia.”
It's clear that they're no longer a minor threat and that the vague boogeyman of countless techno-thrillers over the last few decades where hackers bring down massive pieces of infrastructure is no longer fiction, it's here.
What's more, these cannot be considered simple criminal acts: If these were (or are) state-sponsored attacks, they are pretty close to acts of war. Short of that, they are quickly rising to the level of terrorism. That takes the decision to pay off these hackers out if the hands of irresponsible companies and puts it in the hands of those who handle national security.
It's easy to post a pithy critical response to a comment. Deciding to take the time to understand the subtlety involved takes more time. Maybe next time you should keep in mind the community guidelines that set the tone for how to interpret comments and make substantive replies that are not simply low-effort one-liners. Especially on my comment that fully acknowledges the crap we're in but sees the latest development as a possible catalyst for change. It's easy to criticize, it's much harder, but more productive, to engage in an actual conversation. I'm sorry you chose the low road, many on HN are better than that.
On your second part, I was hoping to clarify your point as maybe you had some other reason it was the "bright side." Additionally, please refrain from personal attacks.
Usually I am hyper careful in how I address solely the merits of an argument rather than an emotional response or ad hominem comment. I'll say-- not as an excuse, but an explanation that does not excuse the comment-- the fact that I was winding down after working without sleep into the mid a.m. hours, and my self-reflection was clearly lacking. I'll do better, and again I am sorry for what I said.
Does this fall under violating the First Amendment, or the Second?
RAM and disk capacities will also have to be limited for similar reasons. As will their speeds.
It could also be many other countries or even private entities that get excited about extracting money from big US companies. The list of possibilities is very long.
As with the "lab origin" situation, it's probably best to avoid whatever the mainstream media is saying and try to find the few rogue experts who aren't being paid to say the right thing (or nothing at all) and thus have no incentives other than the satisfaction of offering a frank assessment (with any luck, you can find them before they're banned from all social media platforms for "misinformation" (ie, disagreeing with the party line)). It took years for any official confirmation of Stuxnet being a state-sponsored attack. But if you were paying attention to the right people, you knew it had all the fingerprints of such an attack pretty early on.
* Non-tech industry belatedly starts prioritising cyber security; security gradually gets better while costs increase and infosec consultants enjoy a Y2K-style boom.
* Tech-competent startups outcompete non-tech industries through avoiding ransom costs.
* The international internet degrades into mostly-closed national networks with end-to-end government control and monitoring.
* The US government starts treating these attacks as national security threats and goes all War on Terror, probably triggered by a hit on critical infrastructure that costs lives. Heinous collateral damage.
(Probability of cyber attack per year) * (cost of ransom + costs of downtime) = X, (Overhead of additional cybersecurity personnel)= Y
If X < Y, it's basically just a no brainier to just eat the costs and pay the X million if it happens. If Y > X, they hire security personnel and it "gets better".
If the government makes paying the ransom less attractive (via basically labeling it as a financial transaction with a sanctioned entity making it illegal) OR the probability of the cyber attack goes up (as this becomes more lucrative), risk calculus changes, security is improved, and it "gets better".
/s
I hope this is because of a self hardening mechanism and not what it looks like, continued assault by adversaries.
Permissions should be able to be set in a fine grained way, capability security needs to become much more well known: https://github.com/void4/notes/issues/41
I don't think that "re-write everything in Rust" is the final solution in terms of security, but in terms of something like the Linux kernel one can at least see how such a (difficult and unlikely) project might at least address many of the low-hanging fruit so developers can shift their focus to fixing higher-level vulnerabilities.
Most applications need to be able to read:
- files that the user drops into them or opens through a file picker (which could be OS-controlled, giving access to only the selected file)
- their own storage/config directories
- read-only system libraries
- temp files (again, isolated per app)
Just moving everything into this model would already go a long way.
We see kernel exploits on phones because you need them to bypass the sandboxing. We don't see them often on computers, because why would attackers bother?
USE OF MCAFFE INTENSIFIES
>One-Fifth of U.S. Beef Capacity Cooked by JBS Cyberattack
It wasn't clear to me from the headlines that this is about meat plants.
One could speculate that those are climate activist attacks.
Or maybe it's just a general attack on US food production, and meat is the most vulnerable sector due to its complexity.
Otherwise..
There are thousands of cattle in transit to just one of these facilities every hour of every day. Most are not equipped to feed incoming cattle - they arrive hungry and with minutes to hours to live. If you’re annoyed about the climate, forcing a manufacturer to throw out and waste hundreds of tons of perfectly fine beef does what, exactly? Send a message?
This isn’t spiking trees. You’re dealing with live animals. I have a hard time believing an activist environmentalist would be fine with exacerbating an animal welfare situation they already don’t like. Putting thousands of cattle through even worse experiences than usual. Yeah, no.
Source: One degree removed from a foreman at an impacted plant. What I’m describing is already happening - plant I’m aware of has 14k head on hand with about 24 hours to figure it out or kill and discard. The administration is already involved and aware of the details, too, and everyone should be vigilant regarding speculation as to who’s behind it (this is likely misdirection, given who it actually is).
Animal rights activists aren't always known for thinking about the consequences of their actions.
https://www.independent.co.uk/news/freed-mink-bring-death-to...
https://slate.com/technology/2017/07/thousands-of-minks-die-...
No one would be particularly choked up if this affected the cigarette industry or the alcohol industry.
People often take pride in recycling or doing other carbon footprint cutting measures like driving a prius, switching off the lights, and so forth. But I could drive a Hummer every day to work and have less of a carbon footprint if I don't eat animal products.
It may not be reasonable for everyone to cut meat out of their diet due to food desserts, society, and so forth at this point, but that doesn't mean that it makes any sense from an environmental, ethical, or health perspective to keep factory farming. There is no question that it should be on its way out - if you believe in anyway that coal/oil should be phased out, look at the data on what factory farming contributes to global warming and tell me there's any justification for that not to be phased out as well.
I can be against factory farming and also against human trafficking and sweat shops. Both are bad. It's not a good argument to say that since there's exploitation in the food chain regardless, it doesn't matter. It's a question of harm reduction.