• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Study Warns US Must Develop Cyber Intelligence

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
A new study by the Intelligence and National Security Alliance, a non-partisan national security organization, says the U.S. must develop strategies beyond the current "patch and pray" procedures. But...but...but....that has been working so well. :D

The report comes amid growing worries the U.S. is not prepared for a major cyberattack, even as hackers, criminals and nation states continue to probe and infiltrate government and critical business networks millions of times a day.
 
That's ridiculous. The Free market would handle security fine if the U.S. gov allowed it to. As for hackers screwing with the U.S. gov's systems, I hope they do.

However, it's going to happen as the President is a technophilic mercantilist securitarian. Some multi hundred billion dollar contract will be given to some company.
 
What the government should do is hire black hats. Get those black hats to randomly target businesses and infrastructure and try to screw it up. Companies will learn via the hard way how to get their security in order. This is exactly what a foreign power would do, only they would attack a huge number of targets simultaneously.
 
the real problems arent with zero-day attacks, which would be fixed by retroactively applying a security patch. the real problems are with incompetant IT folks who cant even follow basic, best practice, security policy.

the 6 months of "sony hacked again!" headlines came from SQL injection exploits. my 7 year old child does SQL injection. another big one is XSS. these are script kiddy attacks that take zero skill to pull off, and can be mitigated by the most basic security procedures. but for some reason, a LOT of BIG companies that handle a LOT of PII dont even give their IT departments the budget or resources necessary to protect that data.

what we need is a clear way to tell which companies are not keeping PII data correctly (before the hackers show us by dumping the info on pastebin).
 
the real problems arent with zero-day attacks, which would be fixed by retroactively applying a security patch. the real problems are with incompetant IT folks who cant even follow basic, best practice, security policy.

the 6 months of "sony hacked again!" headlines came from SQL injection exploits. my 7 year old child does SQL injection. another big one is XSS. these are script kiddy attacks that take zero skill to pull off, and can be mitigated by the most basic security procedures. but for some reason, a LOT of BIG companies that handle a LOT of PII dont even give their IT departments the budget or resources necessary to protect that data.

what we need is a clear way to tell which companies are not keeping PII data correctly (before the hackers show us by dumping the info on pastebin).

+1 and then some.
 
That's ridiculous. The Free market would handle security fine if the U.S. gov allowed it to. As for hackers screwing with the U.S. gov's systems, I hope they do.

However, it's going to happen as the President is a technophilic mercantilist securitarian. Some multi hundred billion dollar contract will be given to some company.

Wait, government can't even do security / national defense now?
 
The companies won't do this, nor the govt.

It's either (A) They just cannot afford it right now, or (B) if they can afford it, they look for the cheapest (99% of the time, non-American) company.
 
The companies won't do this, nor the govt.

It's either (A) They just cannot afford it right now, or (B) if they can afford it, they look for the cheapest (99% of the time, non-American) company.

publicly traded companies are legally obligated to look for the cheapest soloution, in order to make their shareholders the most amount of money possible.

conflict of interest, anyone?
 
Does anyone else feel that this headline should have been like 10 years ago? I mean, they are just now realizing this, really?
 
I initially interpreted the headline as: "a think tank says that the only way for the U.S. to un-fuck itself is to develop a machine super-intelligence, and let IT chart a path forward to un-fuckedness."
 
Here's a brilliant idea: Don't hook critical government and military systems to the internet. Take some of that money allocated to $700 screwdrivers and create a dedicated isolated network for that stuff. Maybe then it will take someone actually physically connecting to the network on US soil to try to break any encryption instead of just doing it from a warehouse in China somewhere.

Businesses.... yeah, you know the answer to the problem. Hire some competent IT people and listen to what they tell you for once instead of just kissing ass to the shareholders. Think long term for a change instead of just to the next quarterly earnings report.
 
The present situation is as dangerous as if the United States decided to outsource the design of bridges, electrical grids, and other physical infrastructure to the Soviet Union during the Cold War.

Ouch, lol.
 
While your title and comment are a fascinating combination I think I will decline to comment.
 
Back
Top