7 ms·
If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They c
by EQYV 6y ago
If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgates. Time to find out how seriously the US takes its own cyber doctrine.
https://www.reuters.com/article/us-usa-defense-cybersecurity-idUSTRE7AF02Y20111116 https://www.reuters.com/article/us-usa-defense-cybersecurity...
- xvector 6y agoIf US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.
- fnord77 6y agowhat if the state actor who did this has nuclear weapons?
- ardit33 6y agotreat them as terrorist, and eliminate some of the leaders until they get the message
- irjustin 6y agoI mean that sounds simple and all.. But historically that hasn't worked well for us long term.
- asdfasgasdgasdg 6y agoIt's true. Attacking random countries that follow the same religions as a particular bad guy is not a recipe for long term prosperity.
- ponker 6y agoWho? I don’t think Russia is killing off senior citizens. North Korea? Nuke the shit out of them.
- Razengan 6y agoCrying for mass destruction is despicable.
- door99 6y agoHorrifying mindset that led to the disastrous war on terror in the aftermath of 9/11. Our foreign policy should not be based on an animalistic thirst for blood.
- supertrope 6y agoAttribution for cyberattacks is hard.
- nobrains 6y agoThe problem with this is that other bad players within US can "hack" this attempt to blame a state/group that had nothing to do with this. Has happened in the past.
- meowface 6y agoOf course; it happens all the time. False flags (in the form of routed connections and much more) are extremely common in cyberwar and among cybercriminals, naturally. But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? It may have happened, and I wouldn't be shocked, but I haven't actually seen a publicized case of it. From having some knowledge of some investigations like these (though not on behalf of any government), the investigators and forensics experts are constantly asking themselves "is this a false flag? is this piece of evidence deliberately planted, or an actual mistake?" Investigators obviously want to get the right people and not get the wrong people. And in the case of nation-states, they also have classified information they can use (like from NSA global spying, etc.). [1] (I shudder at the term "cyber" as much as anyone else reading this, but that pretty much is the official term the government uses.)
- tpolm 6y ago> But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? Absence of evidence is not evidence of absence.
- meowface 6y agoOf course. It absolutely may have happened, and if or when it has, I want those instances known. But if someone were to have been arrested wrongly, or some government blamed wrongly, this would be a huge deal, and I'd expect there to be a lot of public controversy and discussion about it. Everyone should be subject to due process. If some organized crime ring in Ukraine is blamed for some particular ransomware attack and they get tricked into traveling somewhere that lets them be extradited and tried in a US court, the prosecution still needs to prove beyond a reasonable doubt at trial that they're the responsible party. Things get more complicated when an entire nation-state government is accused of launching ransomware attacks, but so far I think only North Korea has faced that (someone please correct me if I'm wrong), and they're kind of an outlier among all the other countries. We should always be skeptical any time any government accuses any entity of a crime, of course. There should always be a presumption of innocence. But that's what the legal system and due process are for. The onus is on the government to prove their case.
- tpolm 6y agoAnd how are you going to identify the state/group that did this? Believing "experts"? Oh, that worked just fine previously https://en.wikipedia.org/wiki/United_Nations_Security_Council_and_the_Iraq_War https://en.wikipedia.org/wiki/United_Nations_Security_Counci...
- mikelyons 6y agoWhatever makes us feel better, right? Reality is essentially unverifiable at this point, so ... nuke Russia? It's not that that's what I want, I just can't find a way to know what's real.
- chairmanwow1 6y agoThis is honestly the scariest part of living in 2020
- rapnie 6y agoAccording to the media hackers are either Russian, Chinese, Iranian or North Korean, so that limits the group of possible culprits somewhat. /s
- FpUser 6y agoI would advise taking a deep breath first. How the f..k will you bring "full might of military" on some group located everywhere? Invade few countries? I sincerely hope that by now people in congress have little bit more of that gray matter. And what exactly does that "no mercy" mean?
- crispyporkbites 6y agoYou’ll kill thousands, maybe millions of innocent lives by going down this path. Are their lives worth less than US citizens? Why?
- wheresmycraisin 6y agoAnd how many innocent civilians will die in the process, assuming they can even identify the group responsible?
- conanbatt 6y agoWhat if the responsible is the government?
- marvin 6y agoI was about to say that this is practically an act of war. You could make a good case that military intervention is justified.
- 1_player 6y agoAh the usual American response: for every US citizen that dies, kill 5 foreign soldiers and 15 civilians. Then you wonder why everyone is burning US flags.
- deleted 6y ago[deleted]
- Dahoon 6y agoSo war against the US government who is to blame for the 1990's IT infrastructure of the whole health system?
- rudedogg 6y agoWhat about management? What about the sysadmins/developers that left a security hole somewhere? Are they held responsible in some way? It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?
- eggsmediumrare 6y agoDo you blame the dev? Do you blame the HR system that hired them? How about the manager that pushed them too much? What about his manager? Is it the VP of IT's fault, even if he didn't know the technical specifics? Nothing is any one person's fault. Blame is a stupid waste of time.
- inetknght 6y agoAt some point we will sit down and recognize that calling programmers "engineers" was a mistake. True engineers make guarantees within clearly specified limits and take on liability for those guarantees. Modern technology companies claim many things while owning little, if any, responsibility.
- eggsmediumrare 6y agoI agree, although I also think civil engineers who miss things (Elliot Lake mall collapse, for example) are mostly just scapegoats and don't deserve to shoulder so much of the blame.
- rudedogg 6y agoThis is what I was thinking with my comment. I don't like the idea of being liable for software I make. I love that the MIT license has a clause saying whatever happens to your computer is not my fault. It's comforting when you're just trying to share something. But.. there are certain classes of software that I think should be written differently. I feel like we made a lot of bad decisions. There should be a completely separate stack for hospitals, power plants, etc., including a custom operating system. Why is Windows running on every machine? Isn't this a national security issue at this point?
- ryanmarsh 6y agoFloodgates... TGD
- haram_masala 6y agoYou're talking about the mass murder of easily 20 million people.
- ryanmarsh 6y agoI don't condone it. I'm saying it's been discussed.
- haram_masala 6y agoOh! I'm really sorry about that, my mistake.
- Mary-Jane 6y agoGood God no! I get where you're coming from but you've clearly not worked in this field. Heath Care IT is a disaster that was CREATED by regulation written in a different era of computing. The whole industry is terrified of making changes because of the multi-year hoops they're forced to jump through to release them; you don't flog a horse for stopping when you pull on the reins. The correct solution is to change the flawed thinking in our regulations that treats all changes as equally hazardous to patent safety. The government should be encouraging (the right) changes to be released more quickly -- punishing companies for following the rules won't fix anything.
- nodelessness 6y agoThat doesn't justify someone abusing flawed systems to threaten people's lives. "Oh we brought it upon ourselves by making it easy to break in so we should fix that instead of going after the thieves?"
- FractalParadigm 6y agoIf the bad actors are halfway around the globe where they have zero jurisdiction, what can you reasonably expect US law enforcement to do? It's a bit like getting mad at police for not investigating your car getting broken into, because you left the windows cracked open.
- EQYV 6y agoI didn’t say law enforcement. Maybe the intelligence agencies can do something useful.
- nodelessness 6y ago9/11 also happened spectacularly in the middle of new york. Does that mean law enforcement tried to do something about Afghanistan? Was it the fault of airports to not do a thorough cavity search of each and every passenger? Our life is to this day in many small ways runs on a contract that others are not trying to kill us. Security check or not.
- 6y ago
- nomercy400 6y agoMaybe the US should also invest some of their military money to solve the situation of insecure hospital IT. You need defense, you won't win it with offense. There'll always be another bad actor out there.
- deleted 6y ago[deleted]
- EQYV 6y agoAbsolutely true as well.
- Dahoon 6y agoSo should Russia do the same? After all the US did officially declare a cyberwar against Russia. If this ends up being attributed to Russia they have a very real defence in pointing the finger at the US and saying "You started it!"
- EQYV 6y agoIf the United States pre-emptively attacks a foreign country with a cyber attack resulting in the loss of human life, then yes, Russia or any state would be justified in retaliating. This is equally true for any such use of any weapon of mass destruction.
- benlumen 6y agoAnd if it’s from China? This is going to be a controversial suggestion, but I have a feeling that we might already be in an asymmetric world war and our leaders might quietly know it. This year has felt like checkmate.
- slimed 6y agoThat is exactly how it feels.
- EQYV 6y agoThen we should not be so meek as to do nothing. During the Cold War, nations did not sit idly by as their adversaries developed nuclear capabilities which, make no mistake about it, targeted civilians and civilian infrastructure. Of course, we developed our own defensive capabilities but then, as now, we faced a type of threat which hugely favored the attacker. So we kept pace with the offensive capabilities of our adversaries. If China or Russia (the states themselves) is identified beyond doubt as the source of this attack, then our policy must be to retaliate in kind. Mutually assured destruction for the cyber-age. If it's organized criminal hackers we're dealing with, then we should treat them how we would treat any legitimate terroristic threat. I would want our intelligence agencies to reach out and touch them. This may not be a popular point of view on Hacker News. I unfortunately cannot fathom an alternative solution.