Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> At some point, it becomes more efficient to go after the hackers, rather than trying to defend every single Hospital.

I'm sorry, but this is completely backwards. It implies some global authority over communications, which is complete opposite of the Internet environment of communication in spite of hostile noise. Yeah sure it seems mighty cool that the US can pressure Russia to go after a notable group and shut them down. But thinking that can scale up to eliminating "Internet crime" is hopelessly naive. Unless we want to end up with a globally surveilled permission-required network where every node needs some associated identity, as well as making people even more liable for security failings (when their identity gets used as a proxy to attack others), it's a non-starter.

What needs to happy is that hospitals, every business, and really every individual needs to develop a small sense of network security. This is akin to how everybody has developed a basic intuition about electricity - ie don't touch it unless you know what you're doing or you will get shocked, start a fire, and/or die. The Internet is a multi-actor environment and connecting your stuff to a multi-actor environment is not free. If you want to avoid increasing the cost, knowing what you're doing can be simply consist of avoiding networked devices, getting explicitly security support and indemnification from the manufacturer, etc. The current culture of just plugging whatever in, proclaiming "works for me!", and then promptly forgetting there could be other implications is what's not sustainable.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: