U.S. to work with Big Tech, finance sector on new cybersecurity guidelines
reuters.com
reuters.com
It's totally ridiculous. At least it will boost the economy by adding thousands of security officer jobs and pad the pockets of any security vendor, and drive system administrators nuts by having to deal with shit like Microsoft Azure GCC High
Yeah not going to happen. Might happen to government, but not banks.
Banks are incentivized by profit, and being offline pose extreme risk to profit. Government are just mostly self promoting bureaucracy until something goes really wrong, and then it's still the same bureaucracy.
Capitalism isn't magic pixie dust that makes everything good.
Maybe there could be two login flows - one that generates a unique pseudo-identity for each service, and another that actually beams over your PII for identity verification purposes.
It makes me wonder how long it would take a true national ID system with digital verification, maybe something similar to Estonia's, to take to actually implement. It would have to be something not left to each state to handle, or it'd suffer the length and per-state disparities of Real ID.
Not really. There was some discussion of it during the period of the Bush Administration which turned into Real ID (2005 was well before Obama was elected), but it's a stretch to call even that, much less any murmurings during the Obama Administration, an “attempt”.
> It makes me wonder how long it would take a true national ID system with digital verification
If you mean a mandatory one, mandatory ID faces Constitutional issues that are central to the US conception of liberty, so probably a collapse of the Constitutional order.
If you mean available standardized digital ID with digital verification, well, TSA had an RFI that closed in June preparatory to a rulemaking on adding digital ID, including digital verification, standards into the Real ID standards, because a number of states have digital ID efforts and there is a demand for them to qualify as Real IDs, because of the uses for which Real IDs already are (and the more that thet will be in the next couple years) mandated for l.
It's not much different than our military and contractors protecting domestic oil company interests abroad.
Here's the plan: invade Afganistan, and eventually find the guy years later in a compound in Pakistan.
Within a country, the same methods would be enforced. If for example, T-Mobile allowed unfettered abuse of its pre-paid wireless cards as they do then the countries they reside in would de-list them from BGP advertisements. The government would have legal immunity in doing so. Or if AWS, DigitalOcean, Linode, OVH, etc... allowed people to abuse their VM's, same deal. De-listing might start with a region then become global depending on the level of abuse and how seriously the company responds and takes action to take out the trash.
In my humble opinion, anything short of this would just be meaningless political posturing and the problems would continue to grow and escalate.
Work with law enforcement agencies in those countries to apprehend the person. If the country won't cooperate or shields the attackers, then sure, a drone strike could work.
Second, there's no moral absolutes that dictate how a nation should act. I value the lives and information of my family and friends more than I value the lives of someone attacking them. Don't like it, don't attack... :shrug:
You said it, not me.
What's your obsession with my penis? This is your second comment about it. I ignored it the first time, so you try harder the second time? You're a creepy dude.
For computer security, I'd want to see liability on results, and not just on the methods and the checklists. If a company has a data breach, then that's something for which they can be held liable. That might mean that it becomes much more expensive to maintain large databases on users, which would be a good change.
You kind of run up against that old English Common Law principle that a defendant is innocent until proven guilty with that idea.
In simple situations, outcomes can work. If you intentionally cause someone to die, you're guilty of murder no matter how you manage to do that (but a chain of causation still needs to be proven, a rough correlation is patently arbitrary and unjust). But complex situations where causation is complicated require standards - proving someone intentionally killed someone in traffic would be hard if there were no traffic laws.
None of the three had any clue if what we were saying was even true. Or what it would mean if it weren't.
To make myself more clear: checklists might be ok, if the checker can scour the code and prove such things. I've never met one that does or even seems to have the ability to.
Some thoughts:
1) Certain infrastructure should be off the net automatically - pipelines, water treatment plants and similar things (or online with hardware guaranteed one ways connections).
2) Standards for testing backups.
3) Standards for IoS devices (a million insecure Internet light bulbs, what could possibly go wrong).
4) Standards for not having a hundred companies auto-updating onto the systems of critical infrastructure companies.
For backups, not only do they need to have it, they need to be tested, kept offline and encrypted - this doesnt apply to all its split by revenue bands/industry/mix of other logic.
IoT devices - they get notified in Control if we find any on the internet and told to not have them directly exposed
* Do you know if there are any follow up meetings planned? Did they discuss some kind of process?
* what were the main concerns discussed?
* interesting to find out about the coalition (I was briefly involved in a similar insurance setup in my home country). Is your ‘baseline’ derived from some standard? Can I find it online?
Yes the group will continue to meet and I believe more will come out overtime as we start to better define how we as private entities can help the gov.
Ransomware and attacks on critical infra were the big ones - Joshua our CEO wrote a bit about it here https://www.coalitioninc.com/blog/coalition-meets-with-presi...
- our baseline is internal. We are with our customers end to end. From selling the policy to scanning them, notifying them and we have our own incident response team which means that we learn a lot with every claim. So when we add a vulnerability in critical state in Control you can assume it came from learnings of losses combined with our cybersecurity expertise.
I look forward to a summary report on incidents somewhere in the future ;)
Doesn't sound so nice when you put it like that.
Sadly, incentivizing people and organizations isn't always good enough--technical hiring is difficult for most orgs to begin with, the market for technical security specialists is smaller than that of software engineers, and good security is an ongoing business function.
Fixing this at a systemic level will take a broad variety of initiatives: some governmental, some driven by insurance/liability frameworks, and initiatives (government, industry, or social) to encourage more people to get into security.
So a new banner has been hoisted, under which some lobbyist interests will be serviced, and if this results in any security improvements - it will be a happy accident. Here, I'll fix the problem for you Biden - here is what you say: "Today I've been directed to announce that... I've directed the Department of Justice to investigate the negligent actions of companies that have contributed to the growing trend of identity theft and associated crimes." Boom, problem solved. This solution is well known, and has been for as long as I can remember. If somebody fills their orphanage-for-the-blind adjacent warehouse full of TNT, and a chain smoking burglar breaks in... the warehouse owner isn't the victim.
Deleted comment
What systems can do that?
We had computer security. Not because MS-DOS was such an amazing piece of code, but rather the hardware was simple enough that you couldn't hide a trojan in it.
The job of an operating system is to protect the hardware, and allow the user(s) of a system to use the resources without risk. NONE of the current crop of operating systems we use 40 years later is suitable for the job, not Linux, Windows, MacOS, iOS, Android, the cloud.
Now that even the cheapest persistent storage is likely to have multiple levels of firmware, it's up to the operating systems to virtualize the hardware, and keep applications from directly touching it. NONE of our current crop of systems do that.
All this "cybersecurity" spending is just a grift if it doesn't deliver actual computer security.
I rest assured knowing that I will never be locked out of any one of my accounts; should I get on the wrong side of any of them, I'll be locked out of both the financial system, the internet ecosystem, and be on the wrong side of the law, for my own safety and digital health.
Building a better future, together.