Hacker News new | ask | show | jobs
by panarky 1873 days ago
The reason cyberattacks are proliferating is because many enterprises refuse to learn from the mistakes of others. They continue to connect ancient, unpatched Windows and Exchange servers to the public internet, they don't segment their networks, they don't secure TeamViewer and RDP, they don't use FIDO U2F, they don't have an IDS, they don't monitor logs, they don't execute email links and attachments in a sandbox, etc., etc., etc.
2 comments

Yes, but this is not new. Cryptocurrency is.

Also blaming the victim can only go so far

If you write the combination for your safe on a post-it note and stick it to the door of the safe, and a thief opens the safe and steals everything in it, it's still the thief's fault.

But it's not victim-blaming to observe that you shouldn't have made it so easy for the thief.

If it's just your valuables that get stolen, then that's unfortunate for you, but at least it doesn't hurt anyone else.

But when other people trust you to keep the safe secure, and are hurt because of your negligence, then it's also not victim-blaming to observe that your negligence caused harm to other people.

My guess is that there are many factors.

- More infrastructure than ever has some exposure to the internet - Outsourcing at massive scale (probably) makes consistent security screening harder - There are more programmers in the world than ever and so (probably) there are more black hats, malicious hackers, etc - As time goes on, there are more and more aging computer systems, thus (probably) there are more and more vulnerabilities in the wild - As time goes on, systems accrete complexity, thus (probably) there are more and more vulnerabilities in the wild

But yes, I do think cryptocurrency is an important change. Cash is still king when it comes to crime, but crypto does make crossing borders much easier.

The whole thing is very asymmetric:

Your own jurisdiction and law enforcement have no power on foreign territory; but foreign organizations (state sponsored or not) located there have freedom to penetrate your society and economy. Moreover, foreign governments may deliberately ignore your requests to investigate.

Thanks to technologies and to chaotic reactions to modern day problems (including covid-19 pandemic) it looks like modern forms of independent sovereign states are very archaic.

Meanwhile Microsoft and "app" developers are training normal users to avoid updates by continuing to push anti-user updates...