Upvote for the comedic use of your icon and the content of the post.
Very good.
Have a pint! ===>
411 publicly visible posts • joined 28 Oct 2020
Anyone have any idea what we can do instead of slinging fines at these offenders?
Generally the huge corporations that end up with these fines, either don't pay initial amount, or the amount is so small to the entity that it resembles no deterrent at all.
Seriously need to find another way to address this, a method or methods that will gain traction in actually getting these entities to harden their security posture, so Joe public isn't at risk.
Also, why does it appear that the fines are never used as restitution for the people actually impacted?
I've been running PiHole at home with considerable success, there are loads of great adlists you can find to add to the block list.
The PiHole has some good information, including the shocking stats of around 20-30% of network traffic being given over to advertising/shitslinging non content, but being blocked.
That metric of network traffic alters and goes up considerably when my kids get home and all the usual suspects on social media are being hammered!
Is there such an uptick in crime that Facial Recognition is being used as a tool to reduce investigative time or, is it that most PD's are underfunded and under pressure to perform?
I don't know about the USA funding for Police Departments, but in the UK you'd be hard pushed to see a Police Officer on the street anymore and I don't know if that's bureaucracy or underfunding.
Having worked in this sector before, I understand the size of the challenge.
Vendors/Suppliers can provide support remotely.
Operations Management are being sold/hoodwinked into allowing this remote connectivity/service, as they are sold on quicker resolution than having to wait hours, days or even weeks for an engineer on-site call out. (Depending on severity and criticality of the systems affected)
Ever since COVID lockdowns, this have become a prevalent stance on OT operations I have reviewed.
Some of these solutions come into play via localised purchases (Shadow IT) with 4G Router/Dongles being put onto infrastructure, by well meaning but misinformed engineers and suppliers, trying to do the right thing, without necessarily understanding the exposure risk and increase in attack surface.
These are not phrases that a lot of OT engineers are familiar with, so risk is rarely considered.
The security experts, plus the OT Wizards, know what the "Gold Standard" should be, but ageing infrastructure doesn't allow this approach at times. New build infrastructure is a different matter, but legacy installations are the challenge in today's always connected, data rich, data everywhere environment.
We need to start with education and cultural changes.
It's a security nightmare with no quick fix.
It needs teamwork and really good collaboration for a successful outcome.
@Pascal very funny! Have a beer ===>
@navarac on the point completely - Pint for you too! ===>
@A/C great commentary ===>
I always chuckle when the Russian State responses are posted.
It's like they can't believe they are also being attacked back!
Russian State Spokesman "We don't understand why we are under attack, so we are very cross and will say things about justice!" (You must say this with a Colonel Kurt von Strohm accent in your head for good effect)
I do wish the whole affair would end and the suffering with it!
Interesting point there.
I used to fly with Emirates a lot in the past, due to work and I noticed on the last few times I've flown with them, they're now operating EasyJet/RyanAir upsell on some things, such as seat selection/allocation and other minor things, just to make an extra few bucks off your already not so cheap, long haul flight.
This is, without doubt, one of the areas I'm always interested in.
One of the biggest challenges is the culture of litigation across the pond, it rather promotes this as a lucrative way to exist, the payouts are at times mind boggling in terms of size, so I can see the attraction.
I remember flagging similar nonsense when it started appearing in Europe.
My main case against some of the draft European legislation was being proposed, was to ensure we're actually protecting and rewarding innovation, not creating a model for Patent Trolls to start operating in the EU with impunity.
There are some absolutely dreadful Patents out there that USPTO has signed off.
My thoughts entirely Pascal.
All the big tech companies are at it, once you're locked into a solution watch the prices rise beyond your wildest and most uncontrollable dreams!
More like a nightmare of continual terror me thinks!
Ahh yes, the advertising... drives me to distraction too!
Give it a rest, I've installed the software, I know what I want, I find the incessant need to promote things at me infuriating.
Whilst I don't have anything significantly negative to say about Win 11 compared to previous versions, having experienced most MS iterations of Windows, I generally get used to the removal or hiding of tools and shortcuts!
I wonder what the next version of MS will bring?
One of the areas I like to discuss when with clients is the concept of having a reversionary method of operation.
In short, how do you still continue to provide your key mission items when your supporting tools have broken.
If you have a business method that is so hell bent on nothing failing, then you really should have a method of working that allows you to follow processes and procedures without those tools being available for a period of time.
MTTR and RTO are all well and good, until you have not managed to get back online.
Considering the primary role of a Hospital/ICU/ECU etc. is to provide life saving care, then surely this facility should still be able to take on patients and provide life saving care without a computer?
We're hardly in the realm of Tricorder's (Start Trek) futuristic health care. Medical support staff, Surgeons, Nurses, Specialists and Doctors can work without a computer I'm sure as that's not how they generally deliver their expertise skills is it?
Fully agree with the other posters comments about the complexity of running a facility like a hospital goes way beyond just accepting patients, however, in the absence of robust security postures that minimise the likelihood of this type of event, then turning away patients is a quite severe course of action.
Without getting into details of the actual patents and how they were, or were not being applied in this case, I just sit back and laugh at the very fact this is allowed to go on in the US.
I don't know what timeline they have for expiration of patents in the US, but some of these patents really need to expire and aren't worth the paper they're printed on, so to speak, however, as long as these patents keep generating huge sums of money on payout then you're going to have these trolls buying up patents left, right and centre.
I've posted on this before, if you've invented something significant, (not just applied existing tech in a different way), then I think you absolutely have the undisputable right to benefit from this.
No doubt weak security and/or default security settings as the A/C poster said.
This is hardly the hack of the century, think some of the comedy messages after the highways agency roadside information posts were hacked!
For shits and giggles I would love to know what happened to allow this system to be compromised, but I suspect there will be some sysadmin somewhere busily deflecting the cock up elsewhere!
I think you've made an interesting point there Arthur Daily.
Most Telco/ISP hardware is not exactly ground breaking and feature full, so it would not surprise me that there are various vulnerabilities that can be exploited and a plethora of devices to load said exploits on.
I don't know what the solution is, but I generally get all my connection config details from my ISP and replace the hardware with my devices of choice.
Totally!
They seek to recover £1.6billion over 5 years.
I bet the creation and administration of this "idea" will end up costing more and making some of the most vulnerable in society even more miserable than before as they seek to contest whatever poorly designed and flawed product is built, that automatically flags the wrong individuals, whilst letting the very miscreants who have long since worked out how to game the system, get away scot free!
FFS, this is a Macro issue, with a social care system that is in need of a major overhaul, not more IT to spy on people.
Rant over!
Agreed Pascal.
I know there's a huge difference in approach when you compare how employees are treated in the US, compared to the approach in Europe in general.
But I don't think I'll ever understand the level of arrogance that incredibly rich organisations like M$, Amazon, Google, Apple etc. show towards the very staff that help them sling whatever it is they sling for the benefit of making annual figures, so large that they are just obscene, when you look at us mere minions and our take home pay.
Some of the things these unions are asking for the employees don't exactly seem to be horrific requests that would damage these multi-billionaire led, multi-billion worth companies.
Maybe I'm missing a trick about how the US Labo(u)r market works?
The £600M is a misleading number as it's a rough order of magnitude of the value of the whole framework, not necessarily a single item to deliver.
Sure, it's still shocking the the company in question hasn't withdrawn, but continued journalistic work identifying these faux pas, certainly help keep us all informed and hold the bastards to account! (Maybe)
Often lags behind the IT thinking on security.
Some OT, by its very nature of operations, is incredibly old, lacks connectivity and may or may not pose a risk.
Then we bring in the concept of IT/OT convergence, which is 90% convenience and cost cutting of engineering staff and maybe 9% operations and 1% security related.
All of a sudden we have all these vendors with edge devices that can interconnect your old SCADA/PLC/HMI etc., then present a picture to you across the internet and we get over excited middle/senior management who are being told it will "save" so much money (read you can lay off staff) but costs millions to deploy for minimal/nugatory amounts of validated and realised improvements!
The idea that we need connectivity to critical OT and plant equipment across the public internet is the lions share of the problem.
Plant operations are generally very light on engineering staff in comparison to a similar IT estate, so deploying an engineer to identify, validate and rectify an issue can seem cumbersome and slow in comparison to a GUI and a manager sitting miles away from the issue, the same manager is being sold that it helps them do the work.....
It needs serious support from vendors to come up with secure methods of operation and the ability to react to CVEs/vulnerabilities as they are identified.
Good point @DS999, the return on investment on the exploits is lessening rapidly and the cost of developing and deploy new exploits is going to diminish the returns once again.
That said, if the approach and the ability to burn through its population is anything to go by, huge amounts of effort and cost isn't really a concern!
I'm always skeptical of the "performance" based trackers, why do you need to track my device performance? Surely a well set up and administered Web Server would provide that information?
As other posters have said, more power to the ad blocker to personalise my experience!
Funny you should say that Pascal Monett, I've done just that, after realising I just needed a push.
Straw that broke the Camel's Back? Yes, the AI Scraping turned on by default.
LinkedIn was a good idea back in the 2000's when it came out, now it's just shite.... end of.
A half decent Sales team is good at flogging anything to anyone, once they've worked out your "Pain Point" (insert sales bullshit bingo phrases to suit) and your weakest link, they'll move in for the kill.
Vendor lock in, being sold as "look how much you save by using us for everything" is to benefit the vendor, as the OP already said.
Businesses will work out for themselves, in due, course, whether cloud is the right solution in it's entirety or in part.
I've been in tech long enough to see fad computing trends come and go, whether cloud is a long term part of IT, well time will tell.
Some organisations I've worked for really would benefit from taking the time to work out the right solution, not rush to the latest tech craze to be seen to be keeping up with the Jones' in their respective industries.
I've written about this before, but some of the patents that are presented to and make it through USPTO are so blatantly BS, that they shouldn't be granted:
Shite patent submitter (SPS) " A method enabling a user to cross between superstructure supporting walls, that allows entry and exit points and can be in either an open or shut position......"
Patent Office " that sounds amazing..... Patent granted"
SPS " Mega!! Lets sue everyone that has a house, a car, an office building, a ship, an aircraft"
Yes, I know I'm being over the top, but some of the patents that have appeared in articles on El Reg, because of how ridiculous they are and yet somehow they end up as patents.
FFS, please, please, please, only submit a patent where you're bringing something groundbreaking to the planet that benefits humanity and your efforts can be and should be rewarded!
I'm surprised that ports, which must be Critical National Infrastructure to most countries, aren't already going forward with improving posture, where one port is hit by a cyber attack, I'm sure some of the huge port operators out there, (DP World anyone?), must be looking at this challenge and making moves to address cyber security challenges.
That said, better late to the party, than not coming at all.
I wonder if a baseline model for ports could be developed from this?
One would imagine there must be a lot of commonality with Port Operations globally?
There's a lot of noise about opt-in, opt-out, consent, no consent etc.
I've not seen any references to designs, Functional Requirements, Non Functional Requirements, Concepts, schemas, storyboards, data flow diagrams and add whatever else should be available for review and scrutinising.
As other poster have already alluded to, handing this over to a 3rd party to design, build, manage, is not how you start a project with this level of gravitas.
Palantir and others have not got a track record of being open with what they do with data.
Seriously couldn't have chosen a worse partner to kick this off!
The mind boggles, but we've got quango's and politicians involved, what do we expect? Apart from a level of disregard for the plebs?
Totally agree with your comment Headley_Grange, but there's no stopping the insatiable appetite from the press to stir things up when there's a void of truth, speculate and make some shit up just to keep people interested until you have something truthful to say, if you're interested in the truth of course?! YMMV
I only said something along similar lines the other day on the subject of LLMs, specifically on who is actually using this LLM "tech" beyond very nugatory requests and queries? I don't doubt that there are some super access, super priced versions of LLMs that may give you the input you need, but how exactly is the layperson going to know if it's worth it?
Screams of all the LLM vendors demanding money to provide a product to you, that you in fact have actually help populate and train, to give you information, that if you really tried a bit harder, you'd be able to answer yourself!
Not long left an organisation with a brace of the "said fuckwits" all pandering to the CTO about their amazing plan to move all on prem to the cloud, including all the shit that doesn't work properly on prem, as if the cloud will fix it during transit....
Sat back and looked at the useless fuckwits blagging their way through a multi year transfer program that's over budget and behind schedule.... why?? Because it's "Cloud"
Snake oil for some companies I think.
So it has a legal requirement to inform its regulator, and the ICO too possibly.
Be interesting to see how this is spun, the NIS Regulations require a breach of an Operator of Essential Services to produce significant reporting and within 72 Hours too.
Watch this space, there can only be more information coming on this breach......
Totally with you on this point, the whole exercise is about posturing to our "friends in the East" and, as another poster mentioned, seeing if it generates any internal noise from the various interested parties inside those "friends in the East", there's a lot to be gained from this being published, much like watching a fire power demonstration on Salisbury Plains, it merely demonstrates capability to some extent.
You're going to need far more controls in place to protect IP.
Honestly, did they really think a procedural control like the NDAA mentioned would cut it?
Seriously, it's not hard, go back to the drawing board and work out how to protect your critical or valuable environments and add the necessary controls, all of them, not just a flimsy document saying please don't do anything bad or we'll be cross with you and tell on you to a court!
It's no good relying on that contract vehicle once the damage is done, it's really not going to reverse the impact, it may get you some money, but is that what you'd really want in the big scheme of things?