Man--I like the way you think, I really do, but this is not "easy". Technical simplicity and social ease are vastly different, and it's usually the humans who are getting hacked.
Man--I like the way you think, I really do, but this is not "easy". Technical simplicity and social ease are vastly different, and it's usually the humans who are getting hacked.
http://www.cnn.com/2016/12/10/politics/smerconish-spicer-hac...
From the WaPo: "U.S. officials said the Republican National Committee’s computer systems were also probed and possibly penetrated by hackers tied to Russian intelligence services, but that it remains unclear how much material — if any — was taken from the RNC."
There were a number of significant caveats in the NYT and WaPo reporting of this that people have ignored because it confirms their existing assumptions. Probably by design; it lets the papers push their preferred narratives whilst giving them something to fall back on if it turns out not to be true.
But the point was, The russian hacker forums are orders of magnitude better than anything offered in English, and virtually every single one has made no secret (other than you need to read Russian) that they were working hard all year to get Trump "elected". From spreading rumours, distributing any dirt they could elicit, to boots on the ground playing with the voting machines. There was even talk of cash incentives from George Soros and Peter Thiel.
WaPo and NYT undoubtably have journalists that both read Russian and Frequent such forums. But it will be a while before they get the courage to go public with just how much US infrastructure is now completely pwned by the Ruskies. RNC and DNC only made headlines because some of the haul got sent to wikileaks aka FVEY.
My personal opinion is "America" deserves it for all the effort they put into making systems insecure.
That's why it's a social problem, not a technical problem, yeah?
The software should have secure default settings, if a user is not a computer engineer he should not be able to execute files from email attachments.
I suspect what needs to happen is each branch of government needs to have infosec people assigned to it that sets standards and policies around this stuff. If they don't comply there have to be consequences.
That is an impressively dismissive statement.
TLS client auth is really pretty much a dead letter: it's not easy at all. The biggest impediment for widespread TLS client auth seems to be that CA's are involved.
U2F might help.. and widespread MFA/2FA. Maybe we shouldn't be just tossing out passwords just yet, but just pushing for full MFA support for mission critical apps.