U.S. to give ransomware hacks similar priority as terrorism, official says
reuters.com
reuters.com
I'm not surprised by this announcement because the way that the pipeline-company ransomware hackers beat a hasty retreat was noticeably unusual, and already seemed to telegraph that the state was getting involved more...actively. Good.
It is an absurd argument up to the point of "reasonableness" that it's the responsibility of the company to defend against 100% of theoretical security vulnerabilities, in my opinion.
There will always be a vulnerability, unless some truly secure-by-design technology exists .. airgap, not vulnerable to social engineering .. ?
Company private security and protection against these attacks is more than abysmal. Just take the pipeline hack as an example. There should be no way at all that infrastructure critical to the nations security is getting shut down because of a corporate hack.
If the private sector wants to earn profit from these things they need to show they're competent enough to handle it.
---
What you described is a zero day, which is very rarely used - most ransomware simply uses the absolutely low hanging fruit of companies lagging behind years in security updates combined with highly insufficient backups.
In the same way companies do not have sufficient HA for their critical systems or processes. HA means being actively resistant to events impacting availability by having (typically automated) redundancy to remove SPoFs. It doesn’t mean HA owing to luck the server hasn’t died in 10 years owing to lack of/poor maintenance. But both with HA and backups companies can dodge bullets (until a real emergency) and maybe never even have a major incident.
Ransomware kind of exploits this lack of organisation level sufficient backing up of all critical information assets.
It really is as you say, low hanging fruit.
Personally I find this just puzzling, in my home folder I loose files at least once a year and I also lost whole partitions. So having no backup at all is no option for me at home. I cannot understand how no or unmaintained backups can be an option at companies.
Encryption introduces it's own SPOF's. If you'very never had a power failure in the middle of a key rotation, you've never been bitten back by your attempt at securing everything with cryptography. Or worse, corrupted by sketchy hardware.
Defense in depth, and proper threat modeling is key. There is also the very real question of "Do you really need that Internet connected anyway?"
Or they invested, but not in the right areas, or there was a new attack through a zero day.
They can be extremely competent in managing oil and gas (and the physical and operational safety that comes with it), but not be competent in Cybersecurity.
It’s real, hard costs today for something that may or may not happen and paying for controls that might prevent an attack. In the best case, as a customer, nothing happens. Whether improving the likelihood that nothing happen is worth a $1 or $3 per barrel premium (or if that $2 is justified) is a hazy mess and hard to make a decision around.
That's why you have government and law to require it. The free market solving everything is a myth, and the USA is lucky that all the pipeline hackers wanted was money. Imagine if that was a nation state trying to immobilize the military in preparation for an invasion. No ransoms, instead bombs start falling while you are paralyzed.
It's impossible to prevent all attacks, physical or cyber, so at some point one needs to either submit to an order where attackers act with impunity, or otherwise invest in retribution.
For what it's worth, a couple weeks ago someone (according to a manifesto, an anarchist group) did exactly that in Munich - they set about 50 10 kV electricity cables that were laid bare due to construction works ablaze to strike against a military supplier and cut off about 20.000 households for over 36 hours until the utility managed to restore service: https://www.br.de/nachrichten/bayern/stromausfall-in-muenche...
Sabotage or plain old theft against utilities is pretty common, but it's hard to do something physical that truly disrupts service for longer than a day or two - the networks are designed with reliability against all kinds of issues in mind. An IT-based attack leaves no traces if done well and can have a week to month long impact, simply because back when these networks were designed, IT threats were not existing.
The ransomeware attack in question wasn't capable of shuttering the pipeline as a target, whether the hackers wanted money or not. That was a voluntary action by the company, a questionable precaution they chose to take.
The US military isn't directly restrained by that pipeline. They have their own fuel supply lines that do not particularly care about that specific pipeline. And even if they did, they can go to the source, they don't require that pipeline for fueling purposes. They have other means of mobilizing refueling, up to and including anything that is necessary from a transport, manpower and logistics standpoint (including commandeering approximately four zillion private fuel trucks and tankers to get fuel moving for defense purposes).
There is no scenario where that pipeline existing or not existing tomorrow would shut down the US military or prevent its ability to defend against an impossible and amusingly implausible attempted land invasion of the US domestic territory.
So, imagine if that was a nation state (uh, which one?) mobilizing for an invasion that can never happen, an invasion that could never get across the Atlantic or Pacific. No.
Bombs start falling? From where? China? Russia? Russia is doing what, invading the east coast? With what ships? With what air cover? With what magical clandestine capability to hide a massive military as they sneak across the Atlantic on non-existent ships. With what aircraft carriers? And with China, so the US sends bombs back the other direction. The ability to throw a thousand nukes at China isn't restrained by the East Coast pipeline, and they know that, as does every other nation on the planet. Again, your setup is so far outside of reality that it's absurd.
Baseline security standards? Sure. But what is the baseline? And how influenced by lobbyists is that baseline? You know the big security companies would love to have their product be a government requirement. Attackers do not have regulations. They know the regulations and work around them. Makes it more difficult, but eventually they develop new attacks.
So now you’ve got this government body making regulations that needs people who understand security to make the regulations, who then need some way to audit the companies to ensure compliance. The companies then have to focus on the audits and not on emerging threats, or do both, and it increases overhead.
I’m not against government regulations when it is a good fit, but there are a lot of unintended consequences. The government is made up of people, too, and they may not be as close to the work to understand the optimal allocation of resources to minimize security risk.
Further, would the same be true of giant pharma companies that create drugs that we ingest? ("Oh, skip those tests. If a few people get injured, we'll pay hush money.") Why don't we see it? Simple: Incredibly strong regulations in US/EU/Japan (the "big three" for global drug regulation & approval).
And the trick to making AML regulations effective is massive fines -- fines so large that they genuinely affect quarterly earnings and stock prices. The same could be done with corporate computer security regulations.
Regulations should not adopt a private company's baseline security standard; we should lean on the work NIST has already done and standards that already apply to (mostly defense) critical infrastructure.
[0]: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
Industrial civilization has been dealing with these kinds of tradeoffs for what, a couple hundred years now? Regulations seem to be the best option out there.
The entire reason the pipeline hack is such a noteworthy event is that (and I truly believe this), someone was dumb enough to take a job bigger than their head. I don't think a nation state would have burned that opportunity by signaling their technical capability that way.
Funnily enough, the pipeline hack and ransom wouldn't even be feasible without the advent of cryptocurrencies making the AML bypass feasible. As much as I despise those regulations in particular, I cannot argue with their efficacy.
It’s also easy to assume that everyone is incompetent. That doesn’t make it true. Like any hostile situation, a defensive position can always be overcome, you have to have an active offense as well.
That's the case with a lot of these companies who:
a) Have pitiful/non-existent bug bounty programs (or even worst, prosecutes white hat hackers who raise issues)
b) Prioritizing exec bonuses instead of investing in InfoSec
Sure, but as much as we might roll our eyes at the state of corporate security, this is a disingenuous metaphor.
It's neglect and incompetence. It's repeatedly forgetting to lock the door even after every neighbor has been robbed.
Sure, given enough time and motivation anyone can probably break into anything, but that isn't an excuse to let the password for the FTP server that pushes out updates be 'password123'.
Here's the problem companies have absolutely no incentive to care about Security. Several years back some hackers stole a bunch of my information from Experian. You know what I got out of it, a free $10 subscription to their identity service, along with lifelong worry of wondering if someone has opened an account in my name and racked up a ton of debt that I'll be held responsible for.
You know what Experian got, nothing, a slap on the wrist and now their stock is in the same place it was before.
I am doing my Masters in Information Assurance and Cybersecurity right now, and the whole mindset of all of my classes is "you're going to be pwned eventually so figure out how to move the risk to some other poor sucker to take the blame when it happens." pisses me off so much. The entire industry basically uses this as an excuse to avoid responsibility and just make sure they aren't the ones held responsible when the manure hits the rotary oscillator, and that bugs me to no end.
At the end of the day there are real people who are getting screwed and hurt by this, while the execs and security "consultants" spend their time trying to figure out how to make sure that when sh* hits the fan they can't be sued, and d** the customer and their well-being we've got to figure out how to make sure we keep the law away.
EDIT: Clarity and formatting
In a lot of cases the execs of these companies will continue to collect a large bonus, despite the fact that they utterly failed their customers.
Backups, and strict security, might be important? Put security right up their as important as their rediculious salaries.
The victims of these breaches are the end users. Companies are the beneficiaries of not having to pay for and especially not having to inconvenience themselves with much more secure systems.
That said, it's true you can't ask for 100% security. You can instead set standards. You can especially set standards of security for any enterprise that the public dependents on. Since, there are no coherent standards now, just liability isn't useful. And the standards should involve actual topology, what kinds of information is allowed in and out at all.
The thing I'm a bit tired of is IT people in these threads taking every incident that comes along as an opportunity to elevate their pet cause. These more serious incidents have more in common with mafia extortion rackets than computer security.
I'm in the improve the security camp. I think security can be improved if we impose good standards (meaning enforce inconvenient things like no backdoor updating apps, no critical infrastructure connected to the web).
The reason "treating this like terrorism" is useless is that there's always another hacker. It's hard but not that hard and anything doable today will be automatable tomorrow.
If the hack comes from a jurisdiction without extradition, how will you solve that? How foea a country know they are not allowing their citizens to be harrassed with trumped up charges? What if definition of hacking differs in two countries?
It is not just Russia and China, Denmans and Uk have refused to extradite to the US becausw pf concerns over inhumane treatment.
https://www.theguardian.com/world/2019/may/10/dutch-court-bl...
Note you are misquoting me: my comment: *"..."treating this like terrorism" is useless"
The right sort of the law enforcement action might be useful. But "treating this like terrorism" is just escalating penalties, threats and so-forth, which doesn't make sense for a very conventional property crime.
These standards (and PCI-DSS, and ISO, and NIST (and this one is by far the best)) have plenty of blah blah that never gets implemented. They rely on some magical risk assessment exercices with a nice risk grid that gives you answers.
The reality is that the top 5-10-whatever risks are very simple to assess and very difficult to address. Unfortunately such concerns do not exist for the writes of standards.
I have been doing information security for 25 years in huge companies. The more relevant the risk is, the more painful it is to implement.
Even the ones such as "awareness" that theoretically should be useful assume that people care or think. I get emails from people who went though 10 awareness sessions who wonder why someone wants to enlarge their penis. And yes, the awareness sessions wera like in the ads: short, to the point, entertaining, relevant, magical.
So now imagine rising a risk that endangers the key legacy system that cannot be isolated.
running power plants is expensive, if companies in competition don't have to run their own power plants then the ones that do will have higher costs and will have trouble competing
Obviously you're correct because impossible is a tall order, but it's possible to get close assuming the aspiring intruders don't have dynamite or artillery[1].
Things are actually getting better in some ways. Modern OSs with automatic updates are more secure than OSs have ever been. The days where clicking a link on an email or plugging in a USB could infect your computer are almost gone outside of rare zerodays which get patched for everyone pretty quick.
Things are getting even better with hypervisors, SELinux and secure languages rolling in. Significant portions of Android and in the future linux, will and are being rewritten in rust which wipes out entire classes of the worst bugs we are being faced with.
The problem is that the attackers are also getting more sophisticated and the targets are becoming more valuable with more and more getting put online.
It doesn’t feel like even Google are winning
(One exception to my solution is poor government and public institutions who run awful software. Not sure what we can do)
If I have a habit of burning down my house by being sloppy with safety, my rates will go up. There should be something similar
Let us take the case with Equifax mismanaging their servers, with running obsolete Java packages resulting in identity theft for millions of Americans.
Credit score is controlled by 3 companies. Credit score determines mortgage rate and hence it literally controls if a US resident can afford to buy a house or get a job (in some states). Don’t the companies need to take some responsibility?
Similarly dozens of companies leaving Elastic search installs and MySQL open to the internet. I mean.. how sloppy can one get?
Fine, be sloppy, just pay $$$$$ to your insurance company. That $$ amount will indirectly decide whether we go to war with Russia or pay software engineers.
Not related to the subject, but wow I wonder how alarming it is that "war with Russia" meme is having a strong comeback, as it's being casually brought up in online discussions about software.
They elected one of ours, we can unelect one of theirs.
Taken to an extreme, anyone can take down a house made of straw with their fist, but nobody can exploit hello world.
I despise seeing simple apps with ridiculous dependency trees (package.json with line counts in the 5-6 figures, for example) and other complexity that can't possibly be fully understood by whoever's responsible for operating it. But I suppose things would be in even worse shape if we reinvented the wheel instead of using well-known libraries and so forth.
Solid libraries are boring and done: old, stable and active bug fix support. Not new features weekly.
Java or .net vs the js ecosystem. In our client contracts we have responsibility for our deliveries; in .net and Java we use well supported libs of over a decade old which we can support ourselves if the maintainers quit. With js this is an issue. Things are generally just not set up for decades of runtime and yet, there we are: we now have node js projects of almost 10 years old with many libs we have to audit and support ourselves and they are not very good quality. I think modern web is only just seeing the tip of the iceberg security wise. It will get much worse.
If I may quibble over a technicality, hello world is just one layer of an already complex technology stack. Suppose someone was able to slip code somewhere deeper in the stack such as your printf implementation (which generally a programmer will, and should, trust just works like it's supposed to) that opened a C2 channel. Then when you run your innocent hello world program, you're pwned through no fault of the program at the top of the stack.
Your comment speaks to exactly how people underestimate the true attack surface. It's far more vast than most anticipate, and their conception of it tends heavily towards the literal surface.
I think you have cause and effect backwards.
Yes, if you want to build a more secure house, you will need more material than another house with equivalent functionality. However, a bigger building isn't magically more secure than a smaller building.
If you walk into my house, I will detect and kick you out almost immediately. If you walk into our office building all you need is a hardhat and a confident stride and you can get anywhere you like. Hell, people will probably even help you get there.
Which makes it similar to code. The smallest app in terms of total 'material' builds up its queries with string concatenation. It takes a lot of 'material' to prevent those kind of injection vulnerabilities. And yes, a data access library that helps you with that is also 'material'.
After following the lock picking lawyer on youtube for a while, it seems to me there is a fallacy somewhere in here.
The weak points of a structure are often underestimated to begin with and adding complexity to the building (eg. door badge system vs. a good padlock) doesn't necessarily add security.
I have a counter example about scale. The more material you put into a city (the more houses you build), the more vulnerable it is (more potential problems, more opportunities for crime, etc).
While the house is less vulnerable than a tent, it can be secured for only as long as the flow of people and material through this house is very well controlled. The bigger squat house is not necessarily more secure. On a city scale free movement of people and goods is essential, and thus any place can be potentially visited (used) by anyone. We want the same urban infrastructure to be re-used by as many people as possible. There is a huge attack surface.
Code is more like a city. We want the same code to be re-used in as many different contexts as possible.
Which is exactly why you don’t store your savings in your sock drawer, you put it in the bank.
Companies not taking appropriate backups is akin to keeping all of your money in a dish by the front door. Sure your house may never get broken into but nobody is going to have sympathy for you if it does.
Making it a criminal offence to pay a ransom would eventually stop criminals ransoming the data they take to the company they took it from, but it wouldn't stop attacks and data breaches if there's some other way to profit. For example, attackers could sell the databases they steal. Or they could ransom individual's data directly to the individual. Or they short the stock of the company and then release the stolen database publicly to make the share price fall.
It's important not to over-simplify the problem. There is no single, simple solution as long as there are many ways to profit from data thefts.
You're listing a bunch of things that are almost assuredly already happening. If a company was dumb enough to keep social security numbers unencrypted in a database or spreadsheet, that data is going onto the dark web whether they paid a ransom or not.
It's a LOT harder to find a buyer of proprietary data that will likely put the buyer in prison for a long time, than it is to get a ransom from one individual trying to keep the whole thing quiet. Once you advertise "I have Apple's top secret next gen laptop details!!" - when someone releases a strikingly similar laptop, or "leaks" the details on an Apple focused fansite, the feds will be all over them.
Of course you can "break into" a typical computer system by gaining physical access to it, for example by breaking into the house that it's in and unscrewing the computer's case; but that's only metaphorically connected to what's going on here, which is that criminals are sending data over the internet to the computer systems in question. The software the owners previously installed on those systems then responds to that data by giving the criminals complete control over the system, as long as they care to maintain it, or unless the system is destroyed. This is dumb.
Writing software that does not behave in this fashion is not only physically possible; it's actually the majority of software. Even in typical software, there is only one deployed exploitable security hole per thousand lines of code or so, and, until only about 25 years ago, it was reliably possible to recover from such an invasion by reinstalling the OS.† The best software, like seL4 or qmail, has orders of magnitude less, though we can quibble about whether the actual number is 0 bugs or 1 bug.‡
The problem is that our systems are architected so that even one exploitable bug anywhere in hundreds of millions of lines of code enables total and irreversible subversion of the system; our system complexity is growing much faster than existing code is getting audited and fixed; much of the code is not even open to auditing; and the people with the power to fix it have no incentive to do so, instead spreading pernicious misinformation claiming that usability and security are unavoidably in conflict (a concept obviously absurd to anyone who has had to use an OS without memory protection) and bulletproof security is impossible anyway. So, at any given time, there are somewhere between thousands and hundreds of thousands of exploitable vulnerabilities in our systems, any one of which is sufficient to enable the implantation of a persistent backdoor that cannot be reliably detected or removed.
The solution to this has been known since the 01970s. At the systems design level, minimize the complexity of the trusted computing base (the hardware and software whose integrity every program in the system relies on) in complexity, audit it rigorously, and freeze it. At the hardware level, provide an easy incorruptible way to restore a known safe state. At the social level, ensure that the people who rely on the integrity of the computer system have the authority to audit it and fix any problems they find, and the technical competence either to do this themselves or to delegate these tasks to people who are competent to do it, rather than to charlatans. At the user-interface design level, ensure that users can understand the information they need to assess the risks they are taking in relying on any given piece of information, and decouple the system to eliminate their incentives to take risks, for example with memory protection and petnames. We know a lot more about how to achieve these things than we did 45 years ago, and in some ways we have enormously more resources. We have seL4, Bitcoin, ssh, Monte, elliptic-curve cryptography, BLAKE3, NaCl, LUKS, decades of SOUPS proceedings, RISC-V, yosys, and 16-MIPS microcontrollers§ that cost 3¢.
But that future is not merely "not widely distributed"—it has become inaccessible except in isolated cases like Trezor, as economic incentives have driven our hardware and software down a path of boundlessly ballooning complexity and diminishing alternatives, while proprietary software licensing eliminates any possibility of assessing and controlling the risks. Meanwhile, the shallow pop culture of computing reduced users from creators to mere customers, and then "eyeballs", while conflating hacking—the only way out of this mess—with computer invasion.
So, I fully expect that if I live long enough to need a pacemaker, I won't be allowed to secure it against ransomware, which will be rampant at that point.
It doesn't have to be this way. This can all be made better.
Ready? Begin.
______
† In fact, shortly before that, on most PCs you could recover from any kind of system corruption just by taking the floppy disk out, resetting the system, and inserting a new, uncorrupted floppy disk. Better hope that one's not stoned too...
‡ You might argue that the possibility that there's an undetected security bug in seL4 means that complete computer security, even against carefully crafted data sent over the internet rather than some dude running off with your cellphone while it's unlocked, is still impossible. But in fact I think there's a very real difference in kind between the possibility that I might currently have presymptomatic covid, and the certainty that I have a small amount of covid. Systems like qmail are analogous to the first case, because they might be secure or might contain an undiagnosed flaw; systems like Linux and Chrome are analogous to the second case, because they are certain to contain a small but fatal fraction of flaws, which are inexorably multiplying.
§ Unfortunately the whole line of Padauk microcontrollers is out of stock this week at LCSC.
A modern jet airliner uses about 1,500,000 bolts and screws. Imagine if they were designed so that a failure of any one of them could cause a catastrophic failure of the entire aircraft. Then imagine if people were defending it by saying “This is a metallurgy problem. There will always be the occasional improperly cast bolt or over tightened screw. To expect that to never happen is victim blaming”.
(Yes, fuzzy metaphorical reasoning is what misled us in the first place, but the problem isn't that the "this is victim blaming, you can always break into a house" people are using fuzzy metaphorical reasoning; it's that, like physics crackpots trying to build the Grand Unified Theory out of styrofoam models, they are only using fuzzy metaphorical reasoning.)
Negligence.
Of course there are always 0days. There are always sophisticated attacks. There is always human error.
Then there are people in leadership positions being given accurate information about basic security problems and possible outcomes over long periods of time flatly refusing to make security a priority or spend any time fixing dangerous situations.
Many of these ransom situations aren't the result of targeted attacks, but "hey we have this exploit and ransom kit, let's scan the entire Internet and see if we get anything".
Or the ever popular (ok maybe not so much any more) unsecured elasticsearch server on the public internet. I'm sorry but if you put your production data on a public IP on a standard port with zero security, it is positively your fault when your data gets stolen. (not much to do with ransom, but an example).
There is a difference between being the victim of a sophisticated attack and being the victim of your own negligence (and a lot of grey area in between).
Both are truthful and full of good will.
What you're describing isn't (shouldn't be) the end of discussion. The trick is to get management to explicitly acknowledge the liabilities.
And then others say: " if we do that, we will have to redesign too much of the airligher" i.em break production.
Youve got to have your priorities straight
If this is a real plane then there are consequences for the company and people (jail). Suddenly it makes sense to fix things.
The software industry is in the former case - new code being diarrhea-ed down without any consequences if it is hacked.
Victim blaming is a framing that makes it sound like it's about moral and ethics. But it's about practicality. There is a causal chain leading to a bad outcome and we simply break the weakest link. Sometimes it's easier to lock up the treasure and sometimes it's easier to lock up all the thieves.
Consider the case of computer security. Locking up all the thieves is super duper hard, because they are located in places like Russia and China that wont cooperate with law enforcement.
Oh, they do. With their local ones. Those thieves can operate with impunity as long as they don't hit their fellow countrymen.
With software systems, instead of demanding a perfect defense against the root password being compromised, think "if the root password is compromised, how do we prevent that from bringing it all down?"
In other words, think in terms of redundancy and isolation between systems.
And the largest piece of hubris and madness in critical systems is allowing over-the-internet updates.
I've worked professionally in both industries; they are not fundamentally different. Software practices can learn a lot from aviation practice, but they seem determined to spend decades rediscovering the methods the bitter, expensive way.
For example, software is still stuck in the dark ages where the idea is better training / better programmers / more punishment will prevent these sorts of failures.
What is your source on this? This goes against what anyone at any company where I have worked at ever believed.
No-fault root cause analysis, process improvements, inherently safer practices, languages, libraries is what every place aimed for. I don’t even know what you might mean by punishment?
See "Trust the programmer" https://beza1e1.tuxen.de/articles/spirit_of_c.html
Also, a general belief among C++ programmers that better training is the answer to programming bugs. This belief is slowly fading, but it's got a long way to go. Scott Meyers' books on Effective C++ represent a lot of effort to educate programmers out of making mistakes. For example, from the table of contents: "Prefer consts, enums, and inlines to #defines". If C++ was an airplane, #define would simply be removed.
> I don’t even know what you might mean by punishment?
There are several calls for punishment in the comments on the article.
The question is whether both sides are doing their best, within reason, to mitigate issues. The programmer doing everything right while the admins forget to patch for years won't change a thing. The opposite is true, patching or configuring correctly won't do a thing if the system is full of "built-in" holes.
It's not a stretch to think of a setup where specific conditions that define this "within reason" are established for software developers and administrators. It's what an audit should normally uncover: weaknesses in the process, points for improvement, etc. Only this time it would be in the form of general and specific guidelines that get progressively stronger as time passes. It's not a sure thing but it raises the bar enough for most ransomware attacks to become cost prohibitive for the attacker.
So would that make D the airplane version of C++?
https://dl.acm.org/doi/abs/10.1145/3386323#:~:text=The%20D%2....
BTW, I practice dual path in my personal life. If I'm doing something risky, I have a backup. For example, when I work under my car, I put the car on two sets of jackstands, even though I use stands that are rated for trucks. I'd never rely on a single rope/piton if rock climbing. I cringe when I see climbers doing that. I carry an extra coat in the car in winter, and water when driving in the desert.
I like much of the way D's designed. It doesn't try to be flashy, gimicky or different for the sake of being different. It gives you a set of practical tools and doesn't try to be too opinionated on the way they should be used. It mostly makes it hard to shoot yourself in the foot. But if you really want to you can. You gotta really try though.
The simpler they are, the easier they are to learn. The easier they are to learn, and less "opinionated", the less resistance they tend to build up against adoption.
D is interesting, because it seems, from my experience, D, like Ada, has been a hypeless language. Though I haven't checked on licensing encumber meets that might be behind that.
You can frequently see them come out in Rust threads, they're generally against it, coming from C/C++, it seems a common attitude amongst low level devs in my experience (there's a thing with "hardware" sounding "hard" which I guess makes them feel more "hardcore").
It's obviously not universal, but it's super easy to find if you search for some programming language discussions.
When the docs exist, and are accurate they can somewhat hide behind "get better programmers"; when they aren'the some can be even moreso, because there is nothing worse than trying to drive poorly documented hardware. It either works or it doesn't.
T. QA guy amongst a bunch of dev types who regularly points out how they do a great job implementing the wrong thing on a regular basis, and helps shape process to make that harder.
The fact they come out in Rust threads has more to do with Rust's evangelist types running afoul of the long standing love of "things that work". Somewhat in the cowboy camp's defense, none of theach no guardrail's type ever turns down a good static analyzer or test suite once you figure out how to get it smoothly integrated into their process. That's where I think Rust gets their outreach wrong.
Don't try to sell development on a brand new lang to learn and replace what they are using. Use the lessons you learn with making that lang, and improve the tooling they are familiar with. We don't have an infinite capacity to learn a new lang and library ecosystem every 6 months to just keep doing what we do. Once you get savvy enough with C and where the spec holes are, you've gotten to a point where you've gotten insight into how things actually work many levels more accurately than just about any other programming toolchain, and also onenjoy of the only languages completely divested of licensing lock-in on the planet.
There is also the point that you can'take really argue against C's effectiveness. It's always the first code to be made functional on any new silicon. I'm interested to see if Rust supplant's it, but I'm weary of any language that's heavily reliant on LLVM as I'm getting more savvy on how licensing risk tends to play out in the long run.
You can't beat the immortality and ubiquity of GPL. It is as close to the unrevocable toolbox from the public domain you'll ever get.
All of the things you mention are great, but they don't really address the problem. You need developers who know what the issues are and are willing to do the work to fix them even though they don't add anything to the feature list. In my experience, I don't have much reason to believe that today's developers are any better about that than yesterday's. There is a lot of security cargo-culting going on, which probably does improve the situation, but there's also a lot of "bootcamp" developers without the background to know that there are issues.
You'll never build a better tool than the one that eases your own pain. Make the user's pain your own, and beautiful things happen.
The software industry is to responsibility roughly as surgeons are to checklists.
Historically the choices were made to spend billions (and trillions) of dollars to invade countries harboring terrorists and use the situation to project power against other adversaries, advantageously control the price of oil, work trade deals, etc.
I predict the same path will be taken with cybercrime. The U.S. defense apparatus won't be giving subsidies to non-tech companies to boost security. Rather, they'll be waging war and using overlapping objectives and narratives to further other goals.
We might seem some special forces go into action under cover. However it would be assassinations done in such a way that Russia either won't know who did them, or is willing to look the other way (the later implies something diplomatic).
But there are other options: assassination for instance like Israel does with nuclear scientists.
Airliners are now pretty resistant to engine explosions, once thought to be impossible to do.
Keep in mind that a bunker will never fly.
Nobody is suggesting not going after criminals who attack software.
Though the prevailing logic on a bunker taking flight is that the engine size will be too large to be economical, which you probably factor in, Walter, but the uninitiated in the aerospace industry tend to simplify away.
Securing a company is like saying that you have to chnage all of the wiring in a country without impacting power supply. ALL of them - the house wirings, the cables transporting power, everyting. At once.
Security in a company is not a single system, it is a messy interaction of unknown dependencies nobody understands. And this mess runs a business.
Of course, there are plenty of things one can do but even for simple tasks such as "let's reset all the 100,000 accounts to make sure they are long/complex/whatever". This is asking for apocalypse.
How it is difficult is visible when you work in information security and have to balance the "we MUST NOT be hacked" and "we MUST NOT impact the business".
It didn't start out that way. It took a long time to figure out how.
> But this is not a good comparison.
I can't agree with that. I don't see any rationale for either airplanes or software systems being special.
> Security in a company is not a single system,
An airplane isn't, either. For example, part of airplane safety is the air traffic control system. Part is the weather forecasting system. And on and on.
If this was something done for fun and without impact on people then nobody would care.
Suddenly, a Monday morning, someone says "woah, this cannot be - you have to fix this". But this is not fixable, you have to build a new plane from scratch, or completely review the existing ones. Planes would be grounded.
Now a software company: typically your old plane flying by more or less miracle (when it flies). You cannot fix it, you have to rebuild it. Either you ground the company and force them to build something new, or you will always have legacy.
The legacy is not fixable - it simply is not. You need money to redo everything and if you do not have the proper pressure then it will not happen.
Then, building a new company/software can be done the right way. This is not even difficult, I would even say that having these constraints will help in the overall quality. But this is a new software, not a "fix" of the old one.
Just like software.
And now only FAA/EASA etc. certified companies and individuals can build a commercial aircraft.
And they can only build the aircraft they are certified to, using the same certified components, and the same certified tools. They cannot change any aspect of the construction without another round with the authorities.
Let me know when the CIOs of listed companies are up for that kind of lifestyle for their email and word processors.
And its precisely those methods that keep the planes in the sky.
Its not orthogonal, is a necessary prerequisite.
I think you're absolutely right that this kind of rigidity is not part of our tech culture, but maybe it should be if that tech is running power grids, [oil] pipelines, and other critical infrastructure.
In summary - maybe we should spend more money so that we get systems which are reliable and resistant to this kind of attack. (_I_ think that's probably a good investment for power/transit/core network/safety systems)
Yes and no. "No" because there are best practices and bits of midleware that although may still get improvement over time, receive nevertheless fewer and fewer changes (and have logarithmic looking dynamic of development). They mature. Advising strongly things that passed the test of time and broad use scrutiny just makes sense, regardless if that may look "rigid". (Not that many implement their own double linked lists nowadays.) Then "yes" because the our "tech culture" pool is big enough to also accommodate fashion, hype, and a whole lot of other psychosocial can of worms...
And that level of rigor is appropriate for the stakes that selling mass produced commercial aircraft implies. The discussion context was critical systems. But then you threw "word processors" in there. Why?
The point is, failing to secure those general use computers has bad consequences.
I just hope we don't take it too far. Many young and talented people in the CS and IT space cut their teeth testing the limits of legitimate access without pushing into the full on destructive regime these attackers have.
I'd hate to see things cracked down on so hard we lose a good signal for talent because we decide that the integrity of cyber systems must be defended at all costs. However, there needs to be a much more pronounced reaction to the types ofor blatantly malicious activity that has been escalating for the past decade or so.
What would you suggest in its place?
You'd need to replace the internet with something - postal mail, Fedex, courier deliveries, etc, or just have things that never get upgraded. Every one of those options has significant limitations, and in many countries, I'd trust SSL over postal mail every single day.
I think if you alter the wording to be "more-secure internet deliveries" then you'll have me agreeing with you, but unless I've missed something, your comment seems poorly aimed (which is odd, as your previous example of the root password is spot-on).
Do you really want a missile guidance system update-able over the internet? How about the auto drive system on your car? What about the code that keeps track of accounts in your bank? Don't forget the code that keeps the pipeline running!
The Internet has a two-fold issue.
A) It's fundamental ideation was an interconnected network of trusted nodes, with a self-healing capability to facilitate C&C continuity in case of nuclear attack. All protocols have underneath them that starting assumption.
There is an entirely unexplored depth of "authorization/security first" computer networking practice out there waiting to be enumerated, instead of trying to bolt-on security mechanisms to what is already built without an ideation of distrust built in from the get-go.
It's just so wildly impractical to implement, and undesirable to at least the Western philosophical foundation to free by default expression that it's not a natural thing to wrap one's head around.
B ) What are you gonna do to me? I'm behind 7000 proxies in different jurisdictions that work fundamentally different from yours and are unlikely to cooperate with your projection of power!
In short, it's a people problem, not a technical one. To the degree it is a technical one, the middle-boxes hold everything back <shakes fist>.
Specially if an entity with a nation's resources is trying to get in.
Why? Many of the companies who got hacked had massive IT issues of their own fault, the most common being:
- full access for everything across the whole network, no subnetting with strict firewalls that limits the scope of an intrusion
- outdated software/firmware stacks leading to avenues for compromise
- no/ineffective/outdated virus scanners
- no meaningful backup infrastructure and regular testing if said infrastructure is already working
- lack of 2FA on administrative credentials
- lack of monitoring on central file servers to detect if a compromised machine is encrypting the file server's contents piece by piece
> It's physically impossible to build a house that can't be broken in to
Indeed, but a burglary insurance will likely refuse service or jack up rates if you don't lock your door or not have an alarm system installed.
I really, really hate reasoning by metaphor, but you do lock your doors, right?
Uh, there was no retreat - the company paid the ransom the day after the hack.
https://www.theguardian.com/technology/2021/may/19/colonial-...
I'm a security specialist and I honestly wouldn't know where to begin.
You ask a very wise question. Unfortunately, I think it's unknownable. The best we know is that the answer is more than none and less than all. The more you get towards "all" the more prevention measures cost to implement. For instance, managing a mature backup and imaging operation at scale may be conceptually simple but is both complex in practice and far from free.
Hospitals in particular are the scene of some interesting conflicts between security and usability. There are a lot of stories about health staff doing things like jamming open medication dispensing machines so that they could get on with the job instead of dealing with security measures they experienced largely as obstacles.
Can you imagine throwing yubikeys into a scenario like that, where people already have an adversarial relationship with IT and security measures? What do you think is going to happen when someone forgets their key and can't send an x-ray to the remote radiology center? I have my guesses.
If user will have to enter 16 charter password each time after HW key (like Yubikey) will be connected to a computer to unlock it, then users will leave it always inserted. Or password will be saved in a text file. If HW key will just work once inserted (or will require 4 digit pin) most users will comply. It is already 2nd factor in addition to some other password, it doesn't necessary need a strong password to use it.
Depending on the precise scenario, that may or may not represent an improvement. If the key is used as a second factor to authenticate to the network, then an infected Excel document will trivially ignore the involvement of a Yubikey as it uses the logged-in user's Kerberos ticket to spread.
You're completely right, though. Even this would definitely cut down on phishing attacks that send users to fake websites pretending to be internal systems.
I'm not suggesting we should declare anything impossible. Far from it! I'm merely trying to suggest that we should appreciate that not all things as easily fixed as they may seem at first blush.
As all of us in software know, complexity can lurk in unexpected places.
Typically, these attacks start by compromising a regular workstation by some office drone via Office macro. Then they start escalating privileges by exploiting Kerberoast, RCEs (think BlueKeep, Eternal Blue, Tomcat servers with the default password, etc.) and other quick wins. When they get a clear text password, password hash or kerberos ticket of a privileged account, there is nothing to stop them. Windows doesn't care if you have MFA at the workstations or at your VPN interface. With the hash or a ticket you can perform network logons to any system where you have local admin permissions. Otherwise, this would destroy the entire single sign on feature that Windows and its users love - logon once, access everything. Kerberos is deeply built into the Active Directory.
Backups are fine, sure, but typically you want to figure out what exactly the attackers did and at what point they started doing it, so you know how far back you have to go with your backups, because you want a backup without back doors. So you need to hire special consultants and they take at least a few days, maybe a few weeks to figure this out.
If you don't have offline backups or took some other special precautions, the attackers might have deleted your backups.
After all that, you still need to apply the backups. A process that probably varies widely in length depending on the quality of the admin team and the size of the organisation.
It’s reasonable to tell companies to lock the doors. It’s reasonable to tell them to follow accepted best practices in tech too, but not that they be experts prepared for everything.
It's getting close to having China and Russia either start cooperating with us to flush these guys out, or we start having "fleet exercises" in their seas again. I think it would be prudent of said nation states to wash their hands of these folks.
> We need preventative care and treatment and everything in between.
Not to mention the fact that the cybercriminals who do these attacks also get involved with state-sponsored offensives. The ransomware stuff might just be "training wheels" or resume bullet-points for something far worse in the future.If we're going to get serious about stopping the state-sponsored stuff and even bother to have the "US cyber-command" it makes sense to go after the relatively petty criminal elements as well. If they can't make a dent with these, why should we think that can go up against the FSB?
Corporations can only ever view cybersecurity as yet another compliance exercise (and all the incurious checkbox tickers that entails). The smart ones will play "cops and robbers" (red-team/blue-team games) but they can't offensively go after cyber criminals. Unfortunately, that's what needs to be done to get ahead of this stuff.
Ship owners invested in arming their ships to the point where the pirates would hopefully pick softer target which is exactly what they did. Incrementally over the 16th-18th centuries the profitability of piracy was highly reduced because the goods had fairly fixed relative value and the risk kept going up and it more or less went away on its own in the Western hemisphere over the course of the 18th century. Crime rarely pays at scale when every instance carries a high risk of a firefight. A few may make a good living in such an environment but it caps the maximum industry size at a very low level.
Piracy persisted in the Mediterranean where it was more or less a state sponsored activity. They mostly avoided harassing the commerce of major powers (Britain, France, etc). Which worked well enough until the 2nd tier powers got pissed off enough to stomp them a few times (with the blessing of the first tier powers, think of it like a reverse Falklands). They still didn't tone it down sufficiently and they wound up speaking French for that mistake.
If anyone has any good resources on the history of Indian ocean or east Asian piracy I'd be interested in reading them.
As an aside, old school high seas piracy is an surprisingly good parallel to the variations of criminals in the current cyber-crime environment. You've got state sponsored theft of money and goods (privateers). You've got under the table cyber criminals who would be prosecuted by their home jurisdiction if found (traditional western pirates, the kind you typically see portrayed in pop culture). And you've got locally approved as long as they pay their dues professional cyber-criminals (north african pirates). The former groups mostly steal things of value they can use or fence. The latter mostly takes stuff hostage for ransom.
The US fought them in the Barbary Wars as well - https://en.wikipedia.org/wiki/First_Barbary_War
I think the statement I was hinting at was that essentially all these companies are on their own (vs pirates and hackers) until the problem is too big and dangerous and then the state steps in.
But at least the risk of suit will loom over their heads.
My point is this If vendors were liable (at least in part) for security faults in their products, then they would be more diligent about closing those gaps.
Software that runs critical infrastructure (or could cause injury or death if it malfunctioned) should be required to use formal methods and that certainly would include everything to make it run also used such formal methods. (From the OS to shared libraries and even the compilers)
"Microsoft and the device manufacturer and installer exclude all implied warranties and conditions, including those of merchantability, fitness for a particular purpose, and non-infringement."
You'd have to outlaw that or breed a more discerning consumer. One way to do that would be to blame the company using it, which would make them take more care in what they choose to use.
It just gets broad and vague after a point. Can the software that schedules trains use Linux or MySQL? People could die if it puts two trains on the same track. Note that GP never mentioned safety either. Just being hacked.
But yes I'd hope that anything bespoke should be covered under a contractual agreement with SLAs and penalties.
The software that schedules trains can do what it likes, because there are several, independent safety layers below it: the signaling system itself, and the software and hardware locks within the signaling system, and formal methods usedto prove their integrity.
Any signaling failure will fail safe (all trains stop).
Any trusted actor (controller, train driver, sometimes passengers etc) can also stop part or all of the system. (On many European railways, if the driver sees a problem, like a car crashed into the railway, they press a red button and all trains in that region are halted.)
I've gotta ask: has the US's stance on terrorism been effective? Or did they merely use it as an excuse to militarize the police and erode human rights? Because I want the government to take effective action around ransomware, but "similar priority to terrorism" just doesn't fill me with hope.
The news is PR fluff.
>We need many angles of defense against these criminals.
Whatever you're comparing airbags to would be one of the defenses that blast is saying we need.
Not dismissing doctors but making fat people (or drug users etc) pay more is not that silly and happens.
There need to be standards (ISO, PCI) for all companies. And if you get hacked, you get fined if you did not adhere to the standards.
And yes, go after the criminals as well, but bit to easy to just ignore ancient Windows installs and users with passwords 1234 who have admin access etc. All these issues are stated in both ISO and PCI compliance: we just need to have all companies comply, not just banks etc.
Not exactly. Executives are choosing to hire el-cheapo offshore middlemen to manage security, software development and to save money (latter is more important - more money in their own pockets) - and we all are on a hook for this behavior. Criminals and hackers are like viruses - they are always there. But we need to maintain the health of the whole body (country and it's entities) to make sure we're resilient.
Execs and politicians selling our security and freedoms for profits and bribes need to be dealt with appropriately.
No it is like increasing price of cigarettes and giving those money to the health system.
>That's silly. We need preventative care and treatment and everything in between.
No, we need secure by default. These things are already criminalised, this does not seem to stop anybody.
Why is a child on a default Windows 10 account able to install a program by clicking a link ? Why is this program able to install itself as a service ? This is not security.
So faced with a deficit of expertise, and a constantly changing IT security landscape, it makes perfect sense for governments to support and co-ordinate cyber security efforts. We need to get maximum benefit from the resources we do have and that mans pooled effort, clear best practices, strong security standards, etc.
Personally I see an additional significant benefit coming out of all of this. If governments and politicians skill up in understanding the seriousness of cyber security at a national level, hopefully they will come to understand the deep folly of insisting on backdoors and secret keys to everyone's systems for security and law enforcement agencies. Politicians keep talking some really dumb crap on this topic, but if we can get them to take the security of businesses and citizens seriously, I'm hopeful this will change.
And shifting from one to the other appears to be happening, to some degree: https://breakingdefense.com/2021/06/dod-budget-appears-to-cu...
The way the Air Force specializes in the air.
It is just incredible how we are always fighting the last war. From 9/11, instead of learning we need to constantly stay on top of a shifting battlefield we learned to fight Islamic terrorism. Not good.
Which is it?
This discussion is more policing, which is out of scope.
Why do you think China or Russia prefer to hack foreign private competitors rather than sending a bunch of missiles on their infrastructure?
And security via threat of retaliation does not sound like a practical or effective solution either: we already have plenty of capabilities in that area, and it didn't stop east coast oil & gas infrastructure from going down or a sizeable portion of the nation's meat processing from going the same way. These attacks are escalating rapidly, and relying in the free market to find a solution doesn't look like it's going to happen fast enough.
This needs to be a national, not (just) a private corporate issue because of the enormous national security implications involved in cyber attacks against infrastructure. When a single company's security failure can cause national chaos, there needs to be a nation-level approach to this.
I don't see what the public could do better than private entities, besides absorbing their costs. The only way I can see it practically working is if the private sectors would allow government entities full access to their IT infrastructure, submit themselves to random controls, audits and checks, and bear sizeable fines if they're found to be negligent.
Unlike "real war", cyber defense also gets to design the battlefield, everytime time. There will always be social attacks, but the stupid C and Unix stuff that is the bread & butter today is completely preventable
Tbh I trust the FAANG companies to run better security. Government is incompetent in this area.
The fact is that the correct and secure working of computer systems and networks has been severely neglected by companies in favor of their profit. If we are to have state response to such neglect, it should be funded by a huge tax on every copy of Windows.
Are you sure about that? A lot of this stuff is way more than just some bored kid. For the company I work for, there is almost certainly a group of well paid people who sit around every day trying to figure out new ways run scams using our site.
When there is financial motivation, people go through great efforts to get that $$$.
"Security" isn't some catch-all box you can check. It's a non stop game of whack-a-mole where your adversary spends each day getting around whatever you put into place.
The software industry should be ten times bigger than it is, but the economic incentive has been to make it cost less, rather than to make it safer.
I feel this deeply within my soul.
I think it's actually harmful, because people that don't know any better thinks a Qualys scan means something.
I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping foreign states.
Rather than compare it to armies, I think we should compare it to spies. If this is truly at the army level we could send a couple dozen missiles and the attackers would get the message. But there are reasons we don't do that though. First, we're not always sure who did what. Second, it's a political quagmire. Armies don't come to your house and help secure it from air strikes. Armies understand attack asymmetry and they hit back.
But when it comes to dealing with foreign spies there is a different playbook. The government helps organizations that are critical to national security secure their entry points and resources. They help, but they don't do everything.
This only works if the parties involved are interested in working with the government. Long after Nortel was first told of the Chinese hacking / stealing of their IP they were still woefully insecure. They went from being a third of the Canadian stock index to bankruptcy in a couple of years.
I don't actually think cybersecurity is possible. I've tried very hard to get governments to change, and there is some progress on the most fragrant violations, but the space is growing too fast and the domain is too maneuverable. I don't think it is possible. All we can hope for is some combination of more defence and realignment of incentives of the actors involved limiting the eventual damage.
They can publish best practices, research vulnerabilities, provide educational support, and generally do all the kinds of things governments do to encourage the right behaviors. We have some of this, but at some point, switched to the sexier "the best defense is a good offense". Likely because defense is hard.
How are we going to handle the calls from very angry officials in Ukraine, Belarus, Poland, Hungary, Slovakia, the Czech Republic and Germany?
In meatspace we expect the government to use kinetic force to stop people from attacking us. Like if I leave my door unlocked and some person comes in to start stealing my stuff, the cops really will respond and come stop that person (I have had a home breakin they responded quickly to). They didn't blame me for having bad locks. I pay a lot of taxes so my walls and locks don't have to be perfect.
In cyber land, it's an anarchy. The government offers no defense. But there's no reason someone can't offer a deterrent. Like if you knew who broke into your servers, and there was a goon squad that went and broke down their door either kinetically or electronically I think a deterrent strategy could eventually work. Like it literally does for meat-space security.
(Not totally sure I want that, but I'm just saying it would probably work and we haven't really tried it yet.)
What do you do ? Sending a single missile/drone wont work because Russia has air defense (probably - with them you never know how on top they are, but they will after the 1st one). Sending multiple might work, but Russia might fire back and start a war.
Sending special forces, or whatever would probably work better first few times, until Russia deliberately set's a trap for them.
How about if they are form China, or maybe France or India and you don't relay have prof that would stand in court ?
And then what, it's not like USA doesn't have its own hackers that do shady stuff internationally. Other countries have spacial forces as well.
I am not sure we want to go this way.
In practice that means US doing whatever they want in poor countries (where they already do whatever they want), and not doing much in powerful enough countries where most of those criminals actually are.
Most of the time we don't even know definitively who is behind the hacks, so it's kind of a moot point.
It's not that uncommon.
Spy-craft is notoriously laughable in its effectiveness. InfoOps, on the other hand...
I guess I’m saying comparisons to both Air based warfare and to the propaganda machine are both the most useful analogs, imho.
I love the smell of marginally improved security practices in the morning.
(If you want to argue that this is a realistic response, please explain how doing so would not be acts of war, inviting both retaliation and much worse acts then justified by ours.)
I don't expect the US to start handling this that way any time soon, but I'm not sure it'd be irrational for a nation to decide a cyberattack is, in fact, an act of war.
Even once that's all decided, we'd need to figure out if war would be a reasonable response. I'd propose that one of the main reasons the US hasn't ever escalated the situation with North Korea, even if we ignore China's likely response, is that actually subduing the populace and occupying the country would likely be extremely difficult. It's unlikely that a thoroughly bombed North Korea would be any more stable and friendly than the current North Korea.
War is extremely inefficient at bettering the lives in any of the countries involved - there are times when it is necessary, but it should be avoided whenever possible.
China is literally the only reason the US tolerates North Korea. And China solely tolerates North Korea because it causes all sorts of irritation for the US. Arguably, it would be better off for everyone living in North Korea if one of those two powers annexed it outright, but geopolitics loves backwater proxy wars.
Closer to the active phase of the Korean War, the USSR was also a factor. Today, the US distaste for instability, and naiton-building, and North Korea not having a hoard of oil or something similar to overcome that distaste is also a reason, today.
This is an unpopular opinion, but I feel like we should generally accept nation-building doesn't work well, countries we leave tend to go back to being horrible in a number of years after we set up a new nation there. And accepting that, and accepting sometimes that countries are completely failed, harmful to world security, and larger countries need to intervene: Annexation isn't actually a bad concept. It's absolutely frowned upon today, but I'm not sure is worse than what we've done to half a dozen countries in the past couple decades alone.
The barrier to war should be high, but at the point you obliterate a nation's governing structure, defenses, and likely civic infrastructure, you should accept you have a permanent responsibility for the civilians there. And maybe the best way to be democratic about it is to establish a process that states one annexes can petition and vote for secession after they've reached a more stable position.
> North Korea not having a hoard of oil or something
There's that. North Korea is a property that literally only Kim Jong Un wants. And major powers seem perfectly fine to let him have it as long as he mostlyish behaves.
If US government authorizes the NSA/CIA to infiltrate/attack all bitcoin exchanges that accept payments from wallet ID with ransomware, the problem likely be solved very quickly.
How many people are you ready to kill over ransomware?
And weren't we just splitting hairs the other day over whether or not Belarus forcing an airplane flying over Belarus to land is excessive use of force? Apparently, ballistic missiles targeted at office buildings aren't?
If this continues to happen we are looking at a really bleak future. There is an -insane- amount of money at stake here. How many meat/farm futures got affected by just taking out the meat industry this time? How much money can these people get not just by the ransomware attack, but by also knowing how fucked an industry is about to be and cashing out.
When they can do this shit with impunity it's a problem. And there's potentially a lot of money available.
This is all just ignoring the fact that some of this might be state sponsored.
I think it's time to start getting some sort of cooperation from said nation states and allowing us to help take out some of their trash.
Because the other option is to treat this like state sponsored attacks on our infrastructure and no one is going to like that.
Cyber warfare, whether ransomware or espionage, is largely asymmetric. Why would these other countries want to play ball when they have everything to gain?
The answer tends to be that you make them cooperate by attaching additional costs to the actions, in order to make them less attractive. These costs come in two major forms, which we might want to categorize as passive and aggressive.
Passive costs might include: - Sanctions - Investigation/Arrests
Aggressive costs might include: - Offensive hacks - Military response
The issue here seems to be that the passive responses aren't likely to be strong enough to dissuade the other actors, while the aggressive responses are too costly. Aggressive counter hacks might just normalize cyber hacking and espionage, and the US is on the wrong side of that asymmetric gamble. Normalizing the behavior would be likely to make it worse than it already is!
Military responses go too far. You can't reaaalllly militarily respond to another nuclear power. Not directly. The potential outcomes there are almost uniformly bad. If you want to play the longer game maybe you do some poking and prodding by supporting third party combatants (IE: Soviet support of Vietnam against the Americans) or political opponents. But there aren't really that many great options on that front today for Russia or China.
So that leaves trying to increase the cost of the passive responses. This is kind of troublesome with China, since they'll just throw identical costs right back at you. It's a bit more possible with Russia, but Europe's entanglement with their power sector screws everything up. And it's not like we're lacking on Russian sanctions as it is.
You can try to play a strong defense, but that's kind of like putting a bandaid on a gunshot wound at this point.
Yadda yadda yaddad, I don't know what to do but I think it's an interesting problem!
Edit: Maybe I shouldn't say European entanglement with Russian power sector. I suppose it's more appropriate to say gas sector?
Realistically even with government support, effective cybersecurity is going to require significant private effort and investment as well.
We should regulate and punish, not subsidize. The same way we have dealth with corporate recklessness for decades.
As the parent comment said, I'd like to see the NSA working to get zero day vulnerabilities fixed as opposed to hoarding them for future exploitation. At least this is my perception, to be honest aside from a few examples I've heard of I don't actually know whether I've correctly characterized their activities, they may already be doing this.
I agree to a point, but to continue the physical-security analogy: while private businesses should not be negligent in securing their property, a patrolling police force should also exist to discourage theft and vandalism at large.
I think the private and public sector have both been negligent when it comes to cybersecurity. Both need to improve. (Like you, I'm willing to bet the private sector is hoping to sit back and let the taxpayer foot the bill for everything. This is a problem too.)
If you could claim compensation for data lost, if businesses had to foot the bill for everybody who's security and privacy is impacted by data breaches, then it would quickly become something they would have to insure against, then the insurers would demand they take reasonable precautions. A system of fines would work well, for instance - an aggressive enforcement of the GDPR or similar, for instance, could create this kind of virtuous circle.
Tax laws are a different issue, even though I agree some megacorps aren't paying their fair share of "private security" right now.
They say your systems are vulnerable as hell. That you're very likely going to be breached in a quite expensive way very soon. It could shut down all the pipes on which Big Pipeline Co depends!
They offer to patch your systems for you. Do you accept, knowing that your staff will have to hand over hundreds to thousands of credentials? Knowing that the employees of the NSA care more about patching than if your systems work afterwards, and you have no real recourse if they screw up?
If you don't accept, what would you prefer the NSA do to secure your company's systems?
The alternatives are a regulatory system for information security or offering advice and hoping companies implement it. There's a lot of advice on offer.
There's already branches of cabinet-level departments that try to do this. In my opinion they're having about the same level of efficacy as one might expect in any other set of large-scale changes in very large old companies with a wide variety of internal systems and needs. If you look you'll find a plethora of government-led attempts to secure various critical industries.
You'll also note that entertainment companies and hospitals are routinely breached. There's perhaps room to question if they are indeed practicing good cybersecurity.
The NSA seems to agree with you. So do the Departments of Energy, Commerce, and Defense, all of which have various efforts to provide independently verifiable high quality security advice, best practices, and guidance. In some cases, they've been doing so for years.
But let's skip the NSA bit. Let's say you, CEO of Big Pipeline Co, have been called up by someone at The Office of Cybersecurity, Energy Security, and Emergency Response within the Department of Energy. They offer you all the advice and guidance you could wish for. Now it's up to you to budget resources. What do you do?
Realistically, you probably hand that advice off to your IT or software staff and hope for the best. Though I realize that reasonable people may differ on this point.
Realistically, I find it not credible to believe that nobody in big infrastructure companies with IT departments is aware that they have vulnerable systems. I find it far more likely that people are aware and people in positions of leadership making decisions about risk have decided that these risks are acceptable.
Do you think getting an email from the NSA telling IT what they already know is going to change those calculations? My experience with bug bounty programs is that leaders who make risk decisions are more likely to shrug and say "I know, we're OK with that risk".
I realize that this is a personal judgment, and other people may have had wildly different experiences.
No, that's not what the email from NSA would say. It would not say "there is a risk of your systems being compromised by cyberattack" in general terms, which is what IT already knows. It would say "your systems are vulnerable to these specific attacks", which IT does not know. So yes, getting this new information should change the risk-benefit calculation dramatically.
For example, a hospital IT department might get an email telling them that their MRI is exposing remote desktop to the internet with default credentials. They know that. They don't change it because if they do, their vendor will drop support. This is a real thing that real medical hardware has to deal with, and it's only slowly getting better.
A big industrial company might easily have it worse than a hospital. Fixing the specific CVE on a specific port on a specific machine might mean having to retire a whole series of obscure, niche bits of SCADA hardware that don't support anything modern. It's like all those IoT gadgets that don't support 5GHz, writ large.
https://en.wikipedia.org/wiki/SCADA#Security_issues
Somewhere between those two, you have your well-run Windows network. It's probably a month to several months of patching behind. IT has a whole process to test any new patches for stability and compatibility with line-of-business software to ensure that nothing breaks. Knowing that their systems are vulnerable to the CVE that's fixed by a patch they're testing - or tested and found broke something important - might not always help them very much.
That is certainly not how it works. See the links others posted for context. NSA is more likely to inform you of the vulnerabilities and associated mitigations.
They say your systems are vulnerable as hell, and they told the CEO about it, but he did nothing. He didn't allow the NSA to come in and fix anything; he also didn't take any action on his own to have people internal to the corporation fix it.
What's your obvious response? Fire the CEO and install a new one who will direct the appropriate resources to fixing the problem.
None. That's part of my point: the root problem is not actually security by itself, it's bad corporate governance. CEOs should be fired for such things, but they're not.
> If the "free market" doesn't care
Corporate governance is not a free market nowadays. It was more of one in the past (although an argument can be made that there were important non-free market forces even then), when most stock ownership was in the hands of individuals who at least had some incentive to hold boards of directors accountable for long-term stewardship, since they were investing with a long time horizon for their own retirement.
But now most stock ownership is in the hands of large mutual funds (since that's where most people's retirement funds are now), which don't care about long-term stewardship; they only care about short-term earnings. So corporations have a positive incentive to overlook things that, to be fixed, will require sacrificing short-term earnings for long-term stewardship. Individual investors never even see this; all they see is the overall rate of return of their mutual funds. So they don't realize the long-term consequences of what is going on and aren't able to apply free market incentives to correct things.
That's probably a rounding error on their quarterly report. Heck, it might have cost them more money to hire more people to provide adequate security to prevent such attacks than to just suck it up and get attacked.
It may actually be economically favorable to stay insecure!
If that were the case, the market would actually encourage CEO's to spend less money on security, not more.
They have a report with a list of vulnerabilities. If you don't fix them to your satisfaction, you will be fined in 2 months, 2 months after that you get fined and publicly reported as negligent, and 2 months after that you get fined again and your outstanding vulnerabilities will be published for everyone to take advantage of.
How much effort are you going to put in to securing your infrastructure?
Do you want the NSA to send agents out to every Fortune 500 with a blank check so taxpayers can pay for a sane backup strategy to stop a problem we solved 30 years ago?
Are Russia or China going to react any different from Iran or Pakistan? They currently think they are untouchable. That needs to change.
Not true when they are also blackmailing companies to not release their internal data.
Even something as simple as a companies customer base and contracts with them can do a huge amount of damage to the company if it's publicly released. So paying a 2 million dollar ransom is the more profitable choice for the company.
Even if the company isn't doing anything illegal or that it's ashamed of.
The NSA's charter is foreign signals intelligence (including computer networks), not law enforcement -- They can't spy on Americans in America except under extraordinary circumstances (Must have a FISA warrant and that person must be talking to one of a few thousand foreign bad actors). And even then, the collected data is not court admissible. Only the FBI and other law enforcement agencies can spy on Americans in America in legally admissible ways using court orders.
The real issue here is when exploits should be weaponized or shared with industry. Should we prioritize the protection of our networks or should we penetrate the networks of our adversaries? This is a tricky political question that needs to be seriously addressed, the status quo is broken.
It needs to be a double edged sword though where companies are just as afraid of facilitating ransomware attacks as they would be of the consequences of facilitating terrorists. In other words, this will only work if it means company's are taking the threat more seriously, not less.
Is that the best USians have at this point? Hope? After "useless wars, TSA and all the security theater" the best you have is hope it will not repeat itself?
The US has a huge anti-terrorism operation in being, and it's not that busy. Islamic terrorism against the US has been confined to minor local nuts since the US wiped out Bin Laden. And, before that, being "#2 in Al Queda" meant having a rather short life expectancy.
Now, all those people in northern Virginia and southern Maryland may be getting new targets.
Over the past few years, threat actors have shifted to much more targeted attacks that net higher Bitcoin payment returns for their efforts.
https://blog.cloudflare.com/targeted-ransomware-attack/
Edit: Commonly mentioned in the same breath:
- the move from just demanding a ransom for the key, to threatening publication of sensitive info
- trawling through the data to look for anything especially sensitive, as well as clues to what number to ask for in financial records
outdated Windows software
This rings a little disingenuous, since (IIRC) the shutdown wasn't caused by the hack, the interruption of service was a deliberate choice by Colonial because (in brief) they wouldn't be able to charge their customers until they got their accounting systems working again.
The company, providing arguably an essential service, chose to stop the flow instead of estimating / approximating / using past averages to bill their customers. They likely lost much more revenue this way.
Do correct me if I got this story wrong.
https://en.wikipedia.org/wiki/Government_negotiation_with_te...
https://foreignpolicy.com/2014/06/03/the-u-s-does-negotiate-...
I expect more precise language than this from Reuters. This makes it sound like the ransomware was responsible for shutting down the pipeline. The billing system was compromised. Colonial shut the pipeline down themselves so they wouldn't have billing inaccuracies.
That is the problem right there. Someone just made 5MM tax free. Time to make paying ransomware illegal and that will stop the potential criminal market for ransomware attacks apart from political motivations.
Every ransom paid just funds and encourages the next hack. The social damage is deserving of a large fine (i.e. 10x the ransom).
"The decryption software provided by the hacking group DarkSide, notes Bloomberg, was reportedly 'so slow' that Colonial Pipeline 'continued using its own backups to help restore the system.'"
Source- https://mashable.com/article/colonial-pipeline-paid-bitcoin-...
Realistically, yes, the hack would still happen. Because there will never be a world where people don't pay ransoms, especially if they have no other options / backups.
> More importantly, would the hack have happened in first place if they knew there was no chance of being paid?
Why wouldn't it? They could easily been paid by another group to perform the hack, used the hack to manipulate stock prices, sold the stolen financial data, or, most likely, the ransom would have been paid indirectly though some other means, like hiring a "cyber security consultant."
Continuing to let them do this with impunity is going to lead to escalated attacks.
Would posting a paper by the german federal police on a practical home heroin manufacture be doing the criminals job? https://www.unodc.org/pdf/research/Bulletin07/bulletin_on_na...
Irregardless the groups that pulled this off already know this and have machinery like that which was revealed in the panama papers and crypto mixers ready to launder the money.
What is now needed is to give real consequences to US-based companies and institutions that pay any sort of ransom to the state/non-state actors that are perpetrating these hacking events. This will remove the profit motive, and I don't care if it's Colonial Pipeline or UCSF, this behavior needs to stop and the criminals behind it need to know that there is not any money to be made.
I don't think that's going to fix anything. I'm 100% sure companies will just pay quietly and not talk about it. Which makes this infinitely worse.
The government invests a crap ton in defense, this should be part of it.
Now, I'm all for treating ransomware, and generally all the large scale and/or state-sponsored hacks with a much higher priority, send the drones and whatnot. But this MUST be accompanied by more accountability on the commercial entities.
You're too small to secure sensitive data of hundreds of millions of people? Maybe you shouldn't have amassed this data in the first place. You're too big to secure everything? Well, did you secure ANYTHING? Did you follow reasonable procedures, did you, crazy idea, make sure you can't access critical systems from the internet and/or with a default password, etc.?
And if you fail, and fail you will, there's no perfect system, I believe there should be penalties not for failing, but for not doing enough to prevent it. To refer to all the plane analogies, if your wings are made of cardboard and everybody knew but pretended it's OK, because otherwise it would slightly diminish shareholder value, well, there will be consequences.
In aviation, you could go to jail for signing off on something that you know is not secure, if it causes an accident and people die. Specifically not for accidents, but for neglecting your duty to make sure that you've done all you could. For lying, deceiving, ignoring, faking, for being too lazy or too greedy to do things properly. Sounds familiar?
With large scale infrastructure under constant attacks, people dying because someone couldn't be bothered to do things properly is not an "if" any more. And better hope those autonomous trucks are very, very hard to hack.
Genuinely curious, would love to see others' thoughts.
A nationalized ransomware team would.
I'm serious. Just like how NSA said "we can't beat em so we'll join em" and started buying zero-days with both fists. If, back in the 1990s, you tried telling people this would happen you would get shouted down by everyone in the room. But it did happen.
If you get owned by Team Fed you get a phone number. You call the phone number, get informed that you got hacked, and get the decryption key immediately. The ransom is added to your company's next annual tax filing. Ransom levels are slowly jacked up until morale^H^H^H security improves.
What's the current official policy, is this still on the table (probably only for massive attacks)?
But yeah, in a game-theory sense, its the cheapest option, to have a nuclear counter strike, instead of building all cities like underground bunkers. Security, by strike team. That would actually work, if all countries agreed on that.
Or the internet is expected to break into allegiance-sized parts. The server only connects to country, who will extradite cyber-criminals and adhere to this connection contract.
It was a nice dream, while it lasted.
2) Are you arguing that the actual Great Firewall, a real thing we see actually working on a massive scale, does not make it much harder for foreigners to cyber-attack China?
3) See my other post on this thread—there's work toward re-designing the Internet to make evading state- or bloc-level origin control, including communicating with existing compromised nodes inside a state, remotely, way harder than it is now. I'm talking at the node-to-node routing and backbone level. It's interesting/terrifying stuff.
4) Couple 3 with some other minor and fairly obvious tweaks to how Internet access works, and even getting a foreign device with its own infinite-range radio into the target state would be reduced to step one of several to gain access to a target state's network, and that access would likely not last long if you start doing anything weird with it.
(Just don't equip your army with only nuke missiles because they destroy all of the good stuff and psy attacks would cross the streams.)
*Back when I was obsessed with this in the early 2000s I'd never heard of Elerium-115, it was always Element-115. Looks like the origin of the name is actually a game in 1994, but may not have become common until around 2013/2014.
Ominous music plays
:big hair band emoji:
:hairbear (too much hairspray) emoji:
:big feline pants emoji:
:leather pants emoji:
:excessive silver jewelry emoji:
:loud motorcycles emoji:
:mosh-pit emoji:
\m/
Looking back with 20/20: clothing styles back then, even for the rockstars, were damn basic: 99% long-haired, half-naked paler-than-I people in jeans, jean jackets, and wifebeaters. xD
https://en.wikipedia.org/wiki/Extraterritorial_jurisdiction#...
In fact, I would be surprised if we *didn't* have extraterritorial enforcement of any ransomware laws.
Hackers in Russia extorting Americans is illegal under U.S. law; that's extraterritorial jurisdiction. The U.S. government going into Russia (or Pakistan or Ethiopia) to punish those hackers without the home country's permission is extraterritorial enforcement.
We have a lot of precedence with the former. The latter's use is more limited, for obvious reasons.
https://www.goodreads.com/book/show/41436213-sandworm
And here's an interview with the author
https://www.theverge.com/21344961/andy-greenberg-interview-b...
I don't mean that government shouldn't be engaging in these talks and try to regulate these markets, my only concern is the pace of these two entities. Instead of using the same old frameworks of regulations and same old mentalities, unorthodox approaches can better address these issues.
P.S Link to The Harvard Gazette article: https://news.harvard.edu/gazette/story/2019/02/government-ca...
[1] - https://upload.wikimedia.org/wikipedia/commons/thumb/1/10/Hs...
The federal government has been pushing to ban different encryption standards for years, or at least require a governmental backdoor. If we get a 9/11 size cyber attack, they will ruthlessly weaponize it, and whatever semblance of internet privacy we had will be gone.
Do they hear about evaluation of the problem ? a) un-Internet that damn infra; b) replace M$ system with Linux or other for of nix excluding Apple products (too user brain replacing and limiting for building on them).
Now you say nixes have bugs too and hackers already have malware versions running on them ? But there is at least one difference: admins have control of that systems parts and can do what they please - including components upgrades. Not so much with 40's years M$ big-ball-of-mud.
And why I'm so so anti M$ ? Remember Ukraine electric-factory problems ? M$. Hydro-dam in US ? M$. Lastly something in Brasil ? Guess what.
Do the evaluation of base problem.
And build more fibers for infrastructure handling !
What should be solved via safety-conscious engineering is going to be solved by Murican War Machine.
or https://web.archive.org/web/https://www.nytimes.com/2021/06/...
All of those were known threats or repeat instances of similar previous threats.
It's the likely threats for which there've been no earlier parallels that I'm truly terrified of.
Response to terrorist-equivalent cyberattack from Russia: Invade Russia?
I hope not. I don't want World War 3 to be in my lifetime.
Shared computing becomes a thing, and the need to have a better model of security is realized as a lesson from Viet Nam, and the Capability Based Security model is born.
Microprocessors again exponentially decrease the cost of computing, and Capability Based Security isn't required because all of the installations tend to have one or a handful of users.
The internet is born, and the cost of networking becomes exponentially cheaper, now all of those low security end users are connected together.
Systems become more powerful with the continuing drop in the cost of processor, memory and storage, so they become more complex. Nobody writes their own software any more, almost all coding is outsourced in some fashion. Security is only a concern if it trickles back to the original source as a problem.
A culture of "move fast and break things" pervades Silicon Valley, and the internet, and thus newer is always seen as better.
The lack of a security model at the base of all these systems is exploited for financial gain. Band-aid layers are added to try to patch the obviously inferior operating systems that pervade the land.
Because the lessons of capability based security were ignored for decades, and not taught, the common consensus is that computers can never be made secure, and your best hope is to hire the smartest people in the world, at less than the average market rate, to secure your systems.
And we repeatedly blame criminals, corporations, programmers, users, and now other countries, instead of solving the problem by properly implementing security.
What is properly implemented security?
I presume the OP is a fan of capability-security and while I'm not an expert on capabilities, I agree they can go a _long_ way to mitigating risk. Unfortunately, none of the mainstream OSs even offer a smidge of a way of actually working with capabilities. Google's recently laughed Fuschia _does_ support capabilities out of the box, but they have a long way to go before they're regarded as mainstream.
Yes, Fuschia and Genode both have a way to go before they are good enough for general purpose use.
I'm not a "security expert", I have no encyclopedic knowledge of the ways of criminals. Let's agree that is well established.
I do know how computers work, down to the transistor level. I've been playing with them since 1978.
Rules I would impose:
Industrial control systems would be isolated from the internet by a unidirectional network. Data could get out, ONLY. You can have helpers on the inside and outside to handle things like buffering logs, etc.
If you need remote control of something industrial, it has to be on a physically separate network, airgapped from the world.
In Government, I would have NEVER connected the Office of Personnel Management system to the internet, except to allow data INBOUND through a data diode. All outbound queries would require passing through a human with the proper security clearance.
All sensitive or classified systems would be similarly isolated, and only allow ingress of data.
Multilevel secure computing would be required for all government systems. Red Teams would be used to test security periodically, run by the Inspector General.
Capability Based Security would be the norm. Most users wouldn't see much of a difference in their day to day interactions.
Bug bounties would be required for any commercial software vendor, with public disclosure after 1 year of all payouts. Bugs submitted that aren't paid would be disclosed in 6 months.
The NSA would shift roles from spying on everything just because they can, to first making sure nobody can spy on us, and only then spying on everyone else.
Also:
Email would require authentication on send
Null terminated strings would be abolished
Broadband would be nationalized and free to all
Things will continue to get worse. Google's Fuchsia and Genode are two capability based Operating Systems that are likely to be good enough to hack in the next year or so.
I expect 3-5 more years of this before enough experience is gained with Capability Based systems to finally cause mass adoption.
In the meanwhile, it would be nice to have a Raspberry Pi based data diode setup that can buffer all the standard stuff, as well as SCADA.
Also in the meanwhile, there is non-zero danger that Congress will use this as an excuse to purge the nation of general purpose computing available to the masses.
Also, the Military Industrial Complex will push for more funds from this.
Also, many a Startup will sell more security snake-oil.
And distributed systems, at least for the web, are _finally_ starting to put capabilities in place. Embedded is a different world sadly.
If I were going to pitch something, it would be a kit consisting of 2 servers and a data diode, useful for getting data to move only in your direction of choice, guaranteed by the laws of physics to be un-hackable. (LED/Photodetector pair)
Any tips or ideas?
There are a number of cybersecurity folk here (tptacek, nickpsecurity, etc.)
And a few earlier threads: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
I get it, this is serious stuff.
This is an adjective derived from a noun, so hole -> holey. It could be hole + ly -> holely but it isn't.
Now, we have the word pinned down. How on earth do you pronounce the bloody thing? For me (en_GB): hole-ee. The dash "-" is not a pause, I would run the word hole straight into the ee sound. The ee phoneme is quite short.
Edit: I blame running out of coffee and almost falling-asleep at the keybbbbbbbbbbbbbbbbbbndfjhkngbc
A valley company that takes security seriously will: Hire experts. Scope attack surface/risks. Implement direct mitigations. Implement policy. Implement defense in depth. Develop a system capable of discovering indicators of compromise (IOC's). Verify security via bug bounty and pen testing, both internal and external.
Clearly most of these things are not "features" and therefore are a cost. Furthermore, since every company must impeliment these, the cost of security for society at large is an O(N) problem.
We must set up a system that mitigates the unpayable O(N) cost of security.
Pen testing/Bug Bounty/verification is probably the most easily scalable problem to solve. Whether you unleash hackers on companies by indemnifying them or specifically pay for Project Zero like entities or turn our own nation-state attackers against US companies with the weight of the US government behind it, it seems quite feasible to create scaled cybersecurity monitoring which can then better inform both technical solutions and policy solutions.
Once companies know they have poor security and once a business can see being breached as a certainty rather than a potential risk, I think the free market can probably solve the problem.
Most drug users are never prosecuted. But the threat of prosecution does very little to affect the quality of their purchase, relative to what it would do to BTC market as a whole.
Outlawing Bitcoin (or cryptocurrency generally) would cause a huge demand reduction. Some coins might adjust supply to compensate, but total crypto "market cap" would surely plummet.
I thought I smelled authoritarianism! Here we see the ultimate purpose of this entire desultory exercise. Having problems online? No backups? Don't fix your pathetic shit; just be the excuse for the USA military-enforcement-imprisonment-industrial complex to oppress everyone on earth. Good grief.
Nations make laws against bad things. People who violate those laws go to jail. A ban on cryptocurrency (or rather, exchanging it for dollars) will be a hell of a lot easier than banning popular intoxicants.
We're done putting up with this particularly pernicious iteration of tulip mania. Time to pull the plug before it does any more damage.
It’s really bot unusual for the law to treat things differently based on the purpose for which they are used when they are “just a database, in essence”.
See? I can do it too.
But yes, everything can be banned eventually. We'll just go back to living in the cave.
What if society determines that cryptocurrency also has negative externalities? You're free to disagree but I just stuck my finger in the air and it's pretty clear which way the wind is blowing.
Here's a thought experiment: If you're a political party that had taken over the government through criminal means such as election fraud or more coercive methods such as a disinformation/propaganda campaign or a coup, the first thing you will do is to make sure that you have control of the money. Since cryptocurrencies are too transparent and undermine the absolute control of state-issued currency, these will be seen as a threat to the criminal government and will be the first thing to get banned.
We can quickly see that the world's worst criminals at the highest levels hate cryptocurrency, and prefer to use the existing paper-based technologies instead, that allow them to be more opaque and retain absolute power.
Good luck pushing that line anywhere other than technolibertarian friendly HN or the various ancap subreddits.
By pointing out that crypto is banned for regular North Korean citizens, did you not just prove my point that it's a worthless tool for countering authoritarianism?
If you don't see how this mean the price will crash, I don't know what to tell you.
Drugs are renowned as a special case when it comes to states' enforcement power. Currency control is not.
Outside failed states, capital controls and foreign currency restrictions have been historically well enforced and followed.
The U.S. banning cryptocurrencies, sanctioning connected individuals and firms and committing to leveling repeated 51% attacks would functionally destroy most cryptocurrencies. (There is zero indication this is being contemplated.)
Are you confusing this with the debate around encryption? That wouldn't surprise me coming from someone who uses the phrase "nocoiner".
Shutting down Coinbase, however, will have no effect on bitcoin or the people who use it. That's the point of bitcoin, and it has been since the protocol was published.
You all are more than free to continue to associate with each other. As long as you're not breaking any preexisting federal laws (let's be honest: most of you are). It's the normie and Wall Street market we are targeting. Good luck maintaining the bull run, sweetheart.
The most precious thought is that one might think to reign in authoritarian capitalists by attacking the one thing created in the last century that has a chance of actually undermining authoritarian capitalism. You don't actually think that, because ITT we see plenty of evidence you're on the other side of this conflict.
You keep focusing on the enforcement itself rather than the goals we hope to accomplish via enforcement. I infer that you have a special fascination for enforcement, but please understand that many people do not share this special fascination with you.
I'm inclined to say Jeff Bezos is no better. But then I remember he and his companies have actually produced some innovations that are legitimately beneficial.
Heck, even in American history we once tried to ban private ownership of gold bullion. The black market price of gold rose substantially.
That's a nonsense comparison. When governments impose capital controls it means their currency is already sinking and it's a last ditch attempt to prevent this inevitable scenario.
BTC valuation is entirely based on narratives about how it's going to replace standard currency in whatever story is popular, and from what I can see right now it's being pumped up by funds who can't find other good investments in this markets and are willing to play with crypto. If it's illegal for US funds/citizens to hold it/be involved with it - the selloff alone would kill the market instantaneously.
There's no reason to think that, say a Japanese pension fund, that's invested in Grayscale is going to say, "oh shoot, guess there's no possible way to allocate to this asset class now". They'll just reinvest that same allocation in a UK or Caymans domiciled fund.
If anything the 85% of crypto investors who aren't invested, will most likely hoard in anticipation of the policy being reversed. For better or worse the US government has extremely low credibility when it comes to long-term policy consistency. Almost any US policy can simply be waited out until Congress/White House flips parties.
Holdings would seem to be more reasonably assumed to be proportional to wealth [0], not GDP. The US has a significantly larger share of global wealth than it does of GDP.
[0] or maybe more-than-linearly related, since less-wealthy people will have more of their wealth in directly-used assets like tools, vehicles, and homes.
Bitcoin market swings on Elon Musks tweets, a full scale ban in the US would obliterate it.
While BTC may burst, it wouldn't go to $1/BTC. it would go to a small percentage of what it is now, but still retain some value.
I haven't bought any Monero, but I saw this website the other day: https://localmonero.co/
If that's legitimate, it seems pretty easy.
I buy Monero by buying Litecoin at any exchange and then swap it for Monero using blocktrades.
Notably, Binance allows buying Monero directly.
Bitcoin is easier than hard cash to track. There's no need to make it illegal. I suppose you could argue that government is heavy handed enough to simply ban the mechanism by which ransomware payments are so easily conducted by. My intuition is that government would prefer to regulate it rather than outright ban it.
Terrorist financing is illegal. Cash is not.
So there's a lot of reasons the US government just may find themselves happier without it.
[1] https://www.elliptic.co/resources/typologies-concise-guide-c...
[2] https://ciphertrace.com/2020-year-end-cryptocurrency-crime-a...
[3] https://blog.chainalysis.com/reports/2021-crypto-crime-repor...
There's a ridiculous amount of volume on Bitcoin and it's mostly moving to and from exchanges. There's no way a majority of those are illegal.
Barely. The portability usually ends at country borders.
> Bitcoin is a problem in search of a solution.
Don't you mean "a solution in search of a problem?" Nice Freudian slip, though :)
Coinage used to be more portable in the days of precious metal coins. But honestly I’ve had very little barriers in converting cash. It’s a solved problem.
but the computational power is nessisary for the network to function in a manner that is provable to new nodes. Because you can use a digital signature to confirm a transaction happened after some time, but not before some time.
I don't think cash is a solved problem within the context of computer networks. If I could transfer money using a program by using a digital signature, I would be satisfied, but anyone who can get access to my credit card numbers (and name, billing address and other open source info) can make purchases in my name. And you of course must rely on the fractional reserves of some central entity.
If ransomware gangs are directly or indirectly targeted by OFAC, that would have massive ramifications.
Doesn't existing anti-terrorist financing (ATF) law cover this?
What happens when a company is a victim of a ransomware attack and OFAC puts the extortion wallet on an exclusion list?
That wallets gets tainted? Its coins become less valuable? Marked wallets have been an obvious thing coming down the pipes.
So now, know your customer turns from “be sure I don’t send USD to a specially designated national” to “be sure I never accept crypto from a burnt wallet.”
You have to declare it. You’ll probably get follow up questions on how you got it and why a wire doesn’t work. But otherwise, large quantities of cash transit the U.S. border all the time.
Rather it's been the banks that have been clamoring to get a piece of the bitcoin action, not the other way around.
Fuck these guys - cluesless morons.
That's not the case for terrorism.
This is like tut-tutting arson victims for using wood in the construction of their buildings.
I'm okay with encouraging reasonable levels of security while also making life horrifically miserable for people engaged in criminal enterprises that attack those victims.
[0] https://ourworldindata.org/grapher/fatalities-from-terrorism...
(You can't do this if you want on-prem Active Directory or a good open-source cross-platform file sharing service like Samba, which means 90% of companies can't do this. And there are of course actual security things you can do [like blocking hard mapping of network drives in Windows] instead of the cowards way out I speak of.)
When hackers start to interfere with American food and energy supply chains, it rises to the level of national security, IMHO.
With all due respect, it seems like you might be jamming this story into a pre-chosen narrative.
Many of these companies that get hacked haven't even done the bare minimum, so it's not even remotely comparable to a robbery imo.
At the height of the Roman Empire a citizen could walk the length of it without fear, because if they where attacked and killed the legion would burn the city / village to the ground that was responsible.
We had the Cold War and not a Hot War because of mutually assured destruction. I fail to see a reason not to bring that balance to hacking by state actors.
Bla, bla, I am a bad person. No, I am suggesting a reasonable measurable set of steps that force the companies to do better while imposing great risk to the criminals and state actors.