Yes it's painful and interferes with the economy, but ultimately this will harden up potential targets. And boy do some of these guys need hardening up.
Yes it's painful and interferes with the economy, but ultimately this will harden up potential targets. And boy do some of these guys need hardening up.
I predict that it is going to be used to get rid of privacy and anonymity features of the web and they aren't going to harden anything!
We dont need the internet to express ourselves freely but it sure sucks ass when you credit card is gone. I d trade your anonymity for my money back.
There's a reasonable balance to be struck. That's essentially the tradeoff we make with the state - trade some freedom for some security.
Personally, I view the opposite as closer to Law of the Jungle, that is our current system of policing that gives a small fraction of society access to self defense but denying it to the rest of the group.
well originally of course it was survival of the most fit (assuming we derive our aphorisms from evolution here), that can mean smartest, fastest etc.
There is no such thing as a level playing field, Harrison Bergeron has not been implemented.
Speaking from my vantage in the United States, I can't believe how quickly the population has become knowingly accepting and complicit with a mass surveillance culture. I'm equally concerned with how quickly ownership of purchased goods has been undermined by the server-client model of the internet. These two things are linked and fundamentally disagree with the basic premises the US believes itself to be founded on ...
It's hard to draw parallels historically in a way that gives hope. There is quite a lot of middle ground and reasonable solutions that just don't get mentioned in the political theater of today's corpocracy.
I know all this has basically become a meme on HN, but every government not following the EU's example and iterating on things like GDPR is implicitly supporting authoritarianism (if not explicitly) and setting up an oppressive future that their children will be trodden down by.
Also, I have not seen evidence that its effects have been nullified with its expiration, but I'm willing to learn.
They think it won’t be used against them, until one day it does, and they are horrified when a divorce attorney is talking about the GPS movements from their “connected car” or their bank closes an account and locks out their funds because they attended a political protest. Unfortunately for them the realization comes way too late.
Not to mention those horrified at finding out that even though they deleted their tweets and videos, the feds have shown up at their doorstep because they were in a rampaging mob in the Capitol, searching for elected officials to murder.
I wish there was a nice, easy answer on where to draw the line with surveillance. I'm actually glad that the insurrectionists left a zillion-mile wide electronic trail, but I'm all too acutely aware that these capabilities can be turned against anyone, and I'm dead-set against backdooring encryption. At least (US-specific here) there are nominally limits on what the government can do, but those limits are often ignored, and private corporations have much freer rein on what they can do with your data.
Why else would they bring smartphones?
Part of liberty is cleaning up the mess when some people take it a bit far, and moving on.
Yes, this'll be used to undermine anonymity (for example try getting a phone plan in many western countries without an ID - it's hard), however I believe there's still going to be a large push from governments and legislative bodies to push better security processes within private enterprise.
The question is whether the pains we’re currently feeling are enough to cause a change in the industries affected.
That's not the case for cyberattacks. Solarwinds was attacked many months before it was detected, Stuxnet was hidden for years. We have attributed some attacks but not most and attribution often succeeds only years after detection. And the attackers aren't as vulnerable to cyberattacks simply because their economy is "less connected" - for example, North Korea is at the extreme end of that scale and they really don't care much about what exploits you have; you have a digital economy that's wealthy but vulnerable to attacks by those who don't have it.
Considering downthread there are honest suggestions to send special forces after the ransomware gangs, I’m gonna go with “probably not”. That type of denial is pervasive.
The F500 and companies like JBS just need to move essentially dataframes around from automation to automation, but somehow the software ecosystem is still building that with the same tools used to write Google. The next answer is usually “they don’t invest in a security team, clearly,” and I’m waiting for that subthread to kick off, too, to continue the denial.
Software complexity is the enemy, not the malicious actors exploiting it. Fix one, fix the other.
See the recent post on why the Uber app is so large: https://news.ycombinator.com/item?id=25376346
Either that or the cost of attacks will remain lower than the benefit of being able to sell bits and bytes to your adversaries. I do not expect this to be the case, but maybe.
The open, global, semi-anonymous web is what's not going to survive this fight, I'm afraid. I give it 20 more years, tops, and maybe a lot less.
Also IP-level blocks will never be perfect. See Hong Kong proxies. Or people in traded IP ranges classified as coming from another country.
Yes, some relatively slow, difficult, and expensive attacks would of course still be viable. That does not mean that, "it wouldn't change anything in practice."
> escalation through residential connections, existing international botnets
Right—so how are you going to talk to your botnet from outside the target sub-Internet when it won't even route packets you send it, except maybe to some hardened commerce-and-propaganda-only subnet that may have limited or no connection to the rest of the target state/bloc's Internet (and again, even that part existing is a maybe)?
I don't believe a complete separation would ever be possible. We'd have to put banks on the commerce side. But that means every single business entity would also have to have access to them. But most businesses also need access to the other side and will not do perfect separation.
In malware research labs you can find rooms literally painted in two colours to separate the isolated part and prevent joining networks by accident. Normal companies do not care that much. Most single-person entities will just plug both ends into one computer and go on with their life.
Two things that are surprising me in this thread: 1) "there are ways to work around this, so it's completely useless" (yes, that's... any security), and 2) either not a lot of people are paying attention to future-Internet development, as in actual, technical development and research, or they're not seeing what I'm seeing in them, somehow, as, for example:
Even if you physically firewalled every connection into a country all it takes is one little node connected via RF (satellite, HF, etc) dropped near an open WiFi hotspot.
There is nothing that guarantees the Internet will keep working the way it does now, and if an open Internet causes enough problems, it will be reigned in. How it works now is a choice, not a law of nature. I'm not happy about it, but that's just how it is. Either these kinds of attacks won't get much worse, or they'll get a lot worse and something like that will be what happens.
Again, I reckon it's either that or this problem never gets much worse. Given trends, I expect we're gonna lose the open, global Internet.
The real problem is that here, like so many other places in modern society, we've allowed consolidation to proceed far beyond healthy levels - when a single company is responsible for 20% of beef supply, it's time for antitrust action! (Yes, I'm looking at you, too, Internet, Tech, Media, Pharma, Aerospace/Defense, etc. companies...)
Maybe just allow one merger per decade, only available to companies with less than 10% of their market?
I expect the problem to be addressed with technology, treaties, extraditions and putting a lot of people in prisons before the fragility of consolidation is addressed.
The primary problem here is criminals and criminal organizations parading as nation-states. The secondary problem is systems and networks that are insufficiently secured.
Or it will just be home grown criminals doing the same thing.
Further, I think states are likely to use this both to prevent beyond-their-reach nationals from attacking infrastructure and citizens, and to curtail foreign astroturf propaganda efforts.
The ID stuff is something I don't think all states will adopt, but some might, even in Democratic states. I think adjusting backbone routing to allow easy network-wide black holing based on verifiable origin, though, is very likely to become widely adopted over the next couple decades.
awaits with bated breath
Great marketing, Equifax - they created the problem and tried to sell you the fix.
No thanks.
This is a 21st century hot war that we are losing badly.
Or they mop up, get bailed out, and then maybe make some minor changes that don't really solve the problem that their insecure corporate culture begins to undermine immediately. We need companies to essentially go into a perpetual cyber-security war-footing. I don't see that happening without business being impossible to conduct without it.
The Red Dawn style of hostilities is a relic of the past.
Meanwhile, the Chinese hackers and those directing their Information Operations are laughing their asses off that nobody points the finger at China first, despite numerous high-profile incidents of military-industrial-political espionage [1][2][3][4], the buildup of a gigantic blue-water navy, and tacit long-term goal of rivaling the US as the global superpower (and unlike the Russians, they've got the economy and manpower to make that happen). Nope, couldn't possible be them. Must be those dastardly Russians.
[1]https://www.justice.gov/opa/pr/former-ge-engineer-and-chines...
[2]https://www.theguardian.com/world/2016/jul/14/chinese-thief-...
[3](PAYWALLED) https://www.japantimes.co.jp/news/2015/01/19/national/china-...
[4]https://www.forbes.com/sites/nicholasreimann/2020/12/19/here...
Voluntary pentesting is a good thing. Costly attacks executed by criminals is not.
Now that there's an actual financial motivation for random non-tech industries to have decent software, they might start to do so.
I get it, but that's a bit of a false dichotomy. That is, there's also valid pentesting and that's the good thing, as opposed to being attacked by criminals (bad thing). And, the purpose of standing up defenses would be to prevent successful attacks. So, if it's the successful attack that prompts those defenses, then it's already too late.
The bigger point is that, in general, I'm puzzled by the constant stream of people thanking the criminals and blaming the victims after each of these attacks.
I think people underestimate the complexity that has evolved over time in many company systems. Securing systems/networks is hard. Doing it retroactively with mountains of technical debt is even harder. The reality is that some of these companies don't have the wherewithal to do it and, even if they did, the timeline to getting them there would leave them vulnerable for some time.
So it sounds great, but very idealistic to say "hey this will help them harden their security". The reality is we need to stop thanking the criminals and support/protect our companies/agencies with a "layer" above their own security, including via deterrence at the nation-state level.
Like how we protect them from all legal consequences of loosing private information of millions of people time after time, such as recent Equifax and Facebook cases?
Or like how we allow companies to sell vulnerable routers, IP cameras, internet enables printers and phones with knows vulnerabilities at the time of release, and leave it without updates?
they are getting away with murder and you are asking for more protection for them? Maybe it's time to accept that this industry is greedy, arrogant and negligent in a way that's unmatched by almost anyone, except maybe hedgefunds.
"This industry"? Which industry is that? I mean, it's a tempting narrative: a big greedy industry, etc. But, this is not isolated to any one industry or any one company. These are attacks by foreign actors on a variety of our companies, government agencies, infrastructure, etc. And they result in real harm to our economy, infrastructure, and people.
>allow companies to sell vulnerable routers, IP cameras, internet enables printers and phones with knows vulnerabilities at the time of release, and leave it without updates
Again, this sounds like a compelling narrative, and sure, there need to be improvements. But, the reality is that the attack surface is vast and includes zero-days in well-maintained software, social engineering, OSS, custom software, network configs, etc.
In general, it seems like there's a lot of anger in your post, but none of it directed at the actual criminals (or their national sponsors) who are actually responsible for the attacks. That's really puzzling to the point where it almost reads like defending the criminals.
We have plenty of our own hackers and ransomware, i am not seeing how foreign-angle adds anything to the debate
"none of it directed at the actual criminals"
There will always be criminals. If a bank was robbed by two kids armed with a banana, then the real fault lies with the bank's management for being negligent, and every court will recognise it.
As it stands, most data leaks and hacks are not unpreventable zerodays, they are people being negligent and irreaponsible.
Large organisations need to change, and ignorance of the issue needs to be adressed. This is not just "there need to be some minor improvements"
The overwhelming majority of the recent, most notable attacks have been traced near-exclusively to foreign actors, including the one that is the subject of the actual thread here.
>i am not seeing how foreign-angle adds anything to the debate
Of course, it has everything to do with the debate. Specifically, with how we respond/deter.
>most data leaks and hacks are ... people being negligent and irreaponsible.
The attack surface is vast.
>If a bank was robbed by two kids armed with a banana
We're literally veering into cartoon territory here. Not sure I understand why you're working so hard to exonerate the actual criminals.
Most criminals are "foreign" because most of Earth's population is foreign.
"The attack surface is vast."
Because we made it vast. It could have been small.
"We're literally veering into cartoon territory here"
Yes we are, because spying on millions of people and then leaving that data unprotected is childishly irresponsible.
Ordinary citizens are the injured party, not companies. They have given up privacy and control over their devices. Even the software that runs on voting machines is copyrighted and secret, and when inspected, it turned out even the basics of security have not been followed.
Now that the chickens are coming home to roost, why are you so vehemently looking to absolve them of all responsebility?
It's breathtakingly hypocritical.
Here's the "foreign" part of the discussion from our "sub-thread" to make things clearer:
Me: These are attacks by foreign actors on a variety of our companies, government agencies, infrastructure, etc.
You: We have plenty of our own hackers and ransomware, i am not seeing how foreign-angle adds anything to the debate
Me: The overwhelming majority of the recent, most notable attacks have been traced near-exclusively to foreign actors, including the one that is the subject of the actual thread here...It has everything to do with the debate. Specifically, with how we respond/deter.
You: Most criminals are "foreign" because most of Earth's population is foreign.
Some hardcore goalpost-moving there. You went from "it's domestic and doesn't matter" to "it's foreign, but only due to a statistical artifact". You're talking in circles in your effort to absolve the attackers. And, it's made clear here that you're not just trying to lay the blame on U.S. companies; you're actively working to absolve/divert focus from the foreign adversaries who are attacking us.
Maybe you can explain why you find it so important that we blame only U.S. entities, whether they be companies or criminals. It's that criminal bit that gives up the game. This isn't just about a crusade against negligent companies. Your narrative seeks to lay blame with U.S. actors and absolve foreign actors.
But, FWIW, a disproportionate number of these attacks come from one country with a population less than half the size of the U.S. It's a country that has been engaged in asymmetric warfare with us. So, you're wrong there too: the foreign nature of the attacks is not a statistical artifact.
>Because we made it vast. It could have been small.
No. It's vast because it's vast. Complexity + interconnectedness.
Fallible humans are responsible for this and it's a problem that's grown over time. Probably every person who's written any significant amount of production code can be said to have contributed to the problem.
And, of course, there's no degree of effort that can defend with 100% efficacy, which is why we also need a deterrent approach.
>why are you so vehemently looking to absolve [companies] of all responsebility?
I've specifically stated that companies need to do better. You, on the other hand, have not assigned an iota of culpability to the actual criminals who attack us. Instead, you've worked against all-logic to absolve them (or, failing that, to place the criminals in the U.S.). It's a simple thing to say "criminals are doing bad things and should be held accountable". Odd that you refuse to say it. Odder still that, to the extent that you even acknowledge criminals exist in this problem-scope, you find it necessary to relocate them to the U.S.
Firstly, thats not an argument, its a tautology.
Secondly Attack surface is vast because we have shipped several billion locked down phones with known vulnerabilities and priprietary binary blob drivers, meaning they can't be updated. We could fix the problem overnight by voiding copyright protection on all software where vendor has abandoned uodates for a year or more.
It's not american companies, its the entire shithead industry.
"You, on the other hand, have not assigned an iota of culpability to the actual criminals"
Mate, they are criminals, they are culpable by definition, its in the Oxford dictionary. They have always existed and always will.
Whats the point of banging on about them like a broken record?
Even if Russia and China magically dissapear tomorrow, the problem will remain: if you have vulnerable systems someone will hack them.
Ita like if someone is always stealing stuff from your house, and I tell you maybe you should try locking the door.
No, it's a correction. You suggested that "we made the attack surface vast". The point is that you're wrong. It's vast due to actual complexity and interconnectedness. It's vast by definition.
>Secondly Attack surface is vast because we have shipped several billion locked down phones...
This again illustrates that you don't understand what the attack surface is, thus you believe fallacies such as "we made it vast". It's not a phone or single entry point. It's every bit of software that a system touches or is comprised of, including custom, commercial, and OSS. It's firmware and hardware and networks and configs. It's social. And, to some extent, it's those same vulnerabilities in systems that connect to a system.
Again, it's vast by necessity b/c our modern world depends on software, technology and interconnectedness.
>Mate, they are criminals, they are culpable by definition, its in the Oxford dictionary. They have always existed and always will.
So, this is your grand rationale for focusing all ire on the targeted companies vs the actual criminals? Your overall position then is that we should have no deterrent (why have laws at all?) and just lock our doors/secure our systems. If the inevitable criminals get you, then it's your fault.
>Whats the point of banging on about [criminals]?
Pretty obvious: to acknowledge they exist, are the actual cause of the problem, and need to be deterred/punished as part of any comprehensive solution.
>Even if Russia and China magically dissapear tomorrow, the problem will remain:
Actually, the problem would be substantially reduced to relatively nil. Just removing Russia alone would have a massive impact.
And, the solution-set becomes vastly different when fighting domestic criminals vs deterring state-sanctioned attacks from foreign adversaries.
But, here you are working hard to absolve the U.S.'s foreign adversaries again, "mate". Very curious.
>Ita like if someone is always stealing stuff from your house, and I tell you maybe you should try locking the door.
Another straw man. I've acknowledged repeatedly that we should lock the door. That discussion is over. What we're discussing is your position that we should not attempt to deter criminals (especially if they are foreign). Instead, they should be able to try breaking your locks with impunity and, if they succeed, then it's your fault.
Reality is not a single-round game.
> Doing it retroactively with mountains of technical debt is even harder.
Building mountains of technical debt is precisely the behavior companies need to stop.
> The reality is we need to stop thanking the criminals and support/protect our companies/agencies with a "layer" above their own security, including via deterrence at the nation-state level.
You can’t accuse someone of being idealistic and then turn around and say this.
The problem is the criminals can be anywhere in the world and can not be removed. When criminals are a constant, security is the only variable.
Perhaps, but we tend to trace the lion's share to one of very few places.
>When criminals are a constant, security is the only variable.
Security also comes through deterring would-be attackers. Security is not simply a posture of attempting to deflect as many attacks as possible. Ever play Missile Command?
In fact, that's disastrous policy. And, even if it were possible to get every company/governmental agency to immediately invest in massive security overhauls along with all vendors, OSS, etc. with near instantaneous results, some attacks will invariably get through.
Seems pretty obvious that we don't want attackers with 100% upside and no downside.