HP Enterprise let Russia scrutinize cyberdefense system used by Pentagon
reuters.com
reuters.com
So the Russian government has higher security standards than the US?
Tools exist to audit anything on the windows CLR. So, from a security standpoint they have everything they need and can request the source code if any red flags show up.
Sure, the source code is great if you want to maintain code. But, for a security audit it's often more deceptive than useful.
HP wants to sell their product so they do this. If the Pentagon doesn't want this they would need to purchase exclusive rights to it or the state department would need to forbid the sale of the software overseas.
"Some security experts say that studying the source code of a product would make it far easier for a reviewer to spot vulnerabilities in the code, even if they did not leave the site with a copy of the code."
I would like to meet those experts that advocate, that not looking at the code makes the product more secure.The "security-by-obscurity" point does apply when you compare "going open-source with many observers" to "being closed-source with no one looking", but this is not the case here.
Pretty much every proprietary platform vendor ever.
Although I believe SBO does work, this is simply not the case for using it.
"POSTing a script that looks like a custom FORTRAN-esque language" probably sounds a lot like "slower than expected progress" in Russian.
All cyber-security is just a way of buying time.
Depth is king. The attacker must be made to fight for every inch.
However long it takes a new hire to be able to do useful things is about how long it takes an attacker to do useful things without being bull in a China shop loud about it (this is also why key rotation is important).
Good attackers deserve credit though. They have to understand stacks that most of HN would just wrap and treat as a black box (and then pull their hair out wondering why their JS app breaks on edge cases).
I guess the Pentagon not only did the same thing, it also secured its right to patch without HPE's knowledge or approval.
If we put ourselves in the shoes of the Russians, they are about to get software the US already uses, which gives the Pentagon a head start in knowing the eventual security flaws. Like the US wouldn't use that kind of knowledge if they wanted...
Also, why do all hacking news graphs/stock images show people in hoodies?
Also most likely ArcSight used by pentagon can be totally different beast then ArcSight used by private companies.
Also most likely ArcSight doesnt cover most of US cyberwarfare arsenal.
Each installation is different - deployment site of probes, filter, tagging and correlation rules. There is not much be gained by looking at the code vs. knowing the Pentagon uses ArcSight.
The one security relevant aspect is the fact that ArcSight processes data from the internet. Programming error in that code may contain vectors allowing a RCE. On the other hand the product has been around for a while and should be safe.
ArcSight is not only used by the Pentagon but by many tier-1 companies to monitor their networks. Unless it falls under ITAR companies can sell their product in whatever manner they like.
Source code or not, some ArcSight servers were already very vulnerable. Whether or not that was done on purpose, who knows.
Surely this has completely destroyed the value of this software.
Hard to imagine any good software written by HP anyway.
Don't they employ lowest cost programmers? Heck the probably designed it using UML or something silly like that, with hundreds of business analysts and vast numbers of stakeholder meetings all working to reach consensus, before getting all those lowest cost programmers to try to write what they think the spec might mean - all truly inspired software is written this way.