Twitter Link
Wonder if this might be the kind of problem that might benefit from global, coordinated efforts.
Twitter Link
Wonder if this might be the kind of problem that might benefit from global, coordinated efforts.
"One day, we shall die. All the other days, we shall live."
Cui bono. Blame Modi.![]()
Hope is the denial of reality
Can't stop thinking about this plausible and 100% proven hypothesis now
In all seriousness, these attacks are getting more frequent, more severe, and more costly. Even without attacks, the costs of mitigation are substantial. Everyone is vulnerable, but not to the same extent, and it might be worth putting more effort into establishing global or at least national standards for security, similar to building codes.
"One day, we shall die. All the other days, we shall live."
Forget global, we need some national standards in the US. Companies have little incentive to either pay for sufficient security or to hand that task over to the government. So we get more and more of these attacks, while these companies opt to pay ransoms.
Hope is the denial of reality
It doesn't help that it's become easier and cheaper to mount these types of attacks.
Hope is the denial of reality
Sounds as though you 3 want to give up on freedom altogether.
Faith is Hope (see Loki's sig for details)
If hindsight is 20-20, why is it so often ignored?
Being please explain. How is strengthing internal systems against cyberattacks and training staff on cyber security go against freedom?
"In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."
People are idiots, absolutely. But it shouldn't be rocket science to assume that one's continued employment means following cyber security protocols.
"In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."
Afaict much/most of the risk—both wrt. the risk of an attack occurring in the first place as well as wrt. the impact of a successful attack—can be mitigated if companies and those responsible for the IT side of ops are able to follow industry best practices, ie. without stupidly cutting corners. If a single regular employee can fuck up your entire system so badly that you are left entirely at the mercy of a ransomware gang, it's possible the system wasn't compliant with those industry standards. I mean, some of the stories I've read about the stupid decisions that ultimately left companies vulnerable to attack... *shudders*
"One day, we shall die. All the other days, we shall live."
Faith is Hope (see Loki's sig for details)
If hindsight is 20-20, why is it so often ignored?
Same in plenty of other fields, e.g. I've worked in medical device production. Human errors are a potential problem there too. Only there, regulations require you to set up everything in a way that an operator can't fuck up. And that includes IT. It might be a bit more work, and a boy if a hassle, but it's certainly possible to make something effective.
Also, a random employee should not have enough access to fuck up your system, and logs should be able to point you at that employee. But that requires setting up and actually following IT policies. Which most companies can't be arsed to, because there's no regulations saying they should.
Keep on keepin' the beat alive!
The ransoms are paid by their cybersecurity Insurance companies, right? Maybe the insurers should beef up their client compliance requirements and start denying claims. That might get companies to actually pay for better IT security instead of relying on Insurance to cover their fuckups.![]()
You cannot make anything idiot proof. Making automation systems as idiot proof as I possibly could was my career for 40 years. Yes, improvements can be made. But the question that O.G. shrugged off I ask you now, how effective do you believe regulations mandating idiot-proofness can be.
Faith is Hope (see Loki's sig for details)
If hindsight is 20-20, why is it so often ignored?
They can't be.
Especially when people are working to find new methods to exploit issues.
The other problem with trying to idiot-proof issues via regulation is you end up with idiots in charge of meeting the regulations (since the intelligence has been taken out of it) and it becomes a box ticking exercise without any thought as to why those regulations were put in, in the first place.
Whereas giving good advice and training and ensuring that idiots aren't dealing with it works much better.
You have a tendency to fixate on the least interesting and salient aspect of a discussion. In many major sectors, half or more of all businesses are at an increased level of vulnerability to attacks simply because they aren't compliant with industry best practices. What that means is that half are compliant—ie. there are established standards that companies can reasonably be expected to meet, and that they can in theory be incentivized to meet through regulatory requirements. There's a lot of low-hanging fruit. As for your example, making automated systems "idiot-proof" may contribute to increased vulnerability—both wrt risk of being compromised as well as wrt the impact of being compromised—eg. through increased automation and connectivity with fewer human safeguards in place (important factor in eg. the Florida water hack). It may literally be the problem rather than the solution. But, quite apart from this, there is potential for improvement wrt reporting requirements—so that a timely response can be mounted, and third parties who are at risk can be notified quickly—and potential for improvement wrt mitigating the consequences of attack—eg. adequate backup & restoration procedures, as in the case of the JBS attack.
But sure, even though it's not directly relevant, what kinds of potentially risky corner-cutting decisions have you seen your clients opt for? What would you have preferred they do?
"One day, we shall die. All the other days, we shall live."
Looking at other fields where this is done? Fairly effective. Even just forcing companies to enforce their own IT policies (or actually have one) would already be a big step forward though.
.. that's how a lot of these type of regulations work, actually. At least the type I referenced in the beginning, e.f. medical devices. They don't prescribe what exactly to do. They set a standard, and most importantly require you to have, for example, IT policies, and a rationale why you have the ones you have. They require you to test it, and to follow your own policies. They require you to do a risk analysis and take action, if needed, and to monitor performance. And they require you to train your employees. So, basically what you say it should be is already how these type of regulations work.
And the standards for this already exist as well. Just a lot of companies don't follow them, even when they should.
Keep on keepin' the beat alive!
Mandating how IT systems are safeguarded for companies with government contracts is relatively easy, do it this way or loose the contract. Please tell me how enforcement will work with companies that do not depend on business with the government for their livelyhood. What could the FDA, EPA or any of the thousands of government agencies do to force JBS into IT system compliance (or their IT contractors for that matter)? Threaten to shut them down? Fine them out of business? Force them to use a different IT contractor.
Faith is Hope (see Loki's sig for details)
If hindsight is 20-20, why is it so often ignored?
Huh, that must be why I get no responses. The least interesting is often the most important.
edit : kinda like my burn pile thread, if our military burns their shit in third world countries why shouldn't we sanction those countries doing the same with all their shit? Sure the article is about Americans suffering the consequences but doesn't even question the impact to locals.
Faith is Hope (see Loki's sig for details)
If hindsight is 20-20, why is it so often ignored?
Yes those style of standards are good, though they're not what I'd call idiot-proof.
As an example of were regulations fail: In the late nineties Gordon Brown changed many of the financial regulations in the UK to be more "idiot proof", the result was a long complicated list of box ticking exercises rather than sensible regulations like you described. The result within a decade was to feed into the Global Financial Crisis. Businesses and regulators were working towards the box ticking to ensure that happened for the sake of it, rather than for the sake of ensuring the provisions actually worked.
Following the crisis much of the nineties-era reforms of Brown were reversed resulting in a smarter, more sensible regulatory system that relies less upon box ticking and more upon expertise.
Experts and idiot-proof don't belong together.
"One day, we shall die. All the other days, we shall live."
"One day, we shall die. All the other days, we shall live."
Sweden got hit hard? When the computer registers don't work everyone is screwed, and even cash is useless.
Maybe all this hacking and malware would be easier to manage/prevent if we banned cyber-currencies, and cracked those codes first?![]()