It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring about infosec. I mean,they care about promotions,reputation,bottom line,ROI,KPI,etc... That's what they do. You know why the marketeers and buzzword snakeoil salesmen prosper? It is because they communicate not only risk but especially [fake] solutions better! Infosec is full of user and management blaming, expecting peoppe outside of software developers and infosec practitioners to care about infosec. I am not saying I have it figured out but I am fairly certain users and decision makers need to be told solutions within the context of risk that affects them. And if it doesn't affct them they're not supposed to care.
I'll give you an example, a network is filled with tls1.0,and ssl1.3, how does that affect some mid sized company's bottom line or reputation? How do they get ROI on the man hours and resources spent to upgrade everythig to TLS1.3 with proper cipher suites and key exchange? and what KPI can they use to measure efficiency of resources? How will you tell them security hygeine takes a very long time to show ROI as do many other security concepts?
You don't really have to do all that if you don't want to, plenty of skill demand to where you can progress to more exciting positions.
https://www.csoonline.com/article/3410278/the-biggest-data-b...
You think a million a year is expensive? It's not - not if it's saving you a $200m fine, and possible class action damages.
All of this sort of thing leads me to think that there is currently a huge mismatch between the security products industry, and how companies implement all the conflicting white paper snake oil, and what the ACTUAL vulnerabilities are. And I know how stupid this mismatch winds up making the average Fortune 500 worker bee's daily life. But that's a topic for another post.
I think it's difficult but there's almost no doubt that Yahoo would have people who understand the problem with security. The problem is, were they, and did they have the power to reign this in at scale?
All too often, you get risk people buying products then asking for all your logs, promising the easy silver bullet. Being a pessimistic engineer, you're unlikely to ever be near a leadership position with people who want easy answers.
I mean, who else is buying a SEIM, asking for all logs, and then hoping it'll take care of everything? That's the CISO, Director, VP, Head Of, etc.
Security was just not a concern until they had a major breach. The security teams had been screaming bloody murder for a while, but could not get the product teams to allocate sprint bandwidth to the massive, coordinated security hardening effort that needed to happen to prevent a potential headline in the New York Times.
Why does legal succeed then? Partially, there are pretty firm laws covering risk, that haven't quite caught up to sec breaches and such (but this is clearly beginning).
However, the big reason: Legal can explain the 'so what' because of that shared common language. Sec folks seem to largely not bother learning how to translate tech jargon to 120 seconds and a power point slide or two that business can understand.
Legal constantly fights the same fights. They get those systems put in place because they acknowledge that fighting these fights is a critical aspect of their job and they make sure those control points are in place. Before I became an InfoSec PM I consulted for legal departments to fight those internal fights for them. They’ve had decades to refine and develop best practices around how to do these things.
Also places where everything is blocked by default by legal are generally badly run legal departments and have plenty of handshake agreements and covert business activity going on the same way places with intransigent and uncooperative InfoSec or enterprise architecture ends up with tons of shadow IT. They’ve been moving towards automated review and self-service tools to speed things up for a while now.
Mgmt/non-sec care about pretty clear, often profit-oriented metrics (ROI, etc.). There is such a clear precedent for successfully internally selling, implementing, and creating buy-in for cost-producing (i.e. infosec) but business-saving practices. Insurance, financial risk departments, legal departments etc. etc. etc. Sec can fall under that too. Sec people don't bother to learn the language 90% of the time. Sec people then burn out because they feel they're paddling nowhere.
Failure to learn that ^ language as a sec eng, means you fail to learn how to successfully implement sec in a way that has lasting buy-in. It's doable. It takes a bit of leadership, a bit of buzzword-learning.
If you want to play ball with mgmt and not be a mindless keyboard monkey sec eng who has no care if people care about sec or not, you must be able to take all those sec thoughts, distill it into 3 power point slides and 120 seconds of 'so what,' and be ok doing it over and over.
A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the production environment. I'm tempted to just credit myself 1 monetary unit in production and just show them the statement.
I would be tempted too, though I could bet that this will be a termination of an employment, instead of the problem being fixed.
I would like to be proven wrong on this speculation..
I'm just impatient because it's a really clever and somewhat complex hack that challenges some multi-threading and transactionability assumptions some people mande and I can't really talk about it(which I'd love to share with my peers).
And make sure your contract covers your ass, under production system testing / penetration, or something similar.
The bug that lead to me discovering the security issue was mitigated by another developer, the security issue was also deemed fixed, I am 100% it was not, but there's no way to proove it at the moment, except u production, that's why I said I was tempted to actually do it.
Anyway, there's nothing much to gain by me by antagonising another coleague, the management or the bank. It's not worth the ego boost or frustration scratch, worst case scenario, I don't patch the issue in time and the bank looses money and they start taking security more seriously.
I can understand every piece of the long string of factors that lead to this ridiculous situation where such a serious security issue is not being addressed; any one in particular is not ridiculous, but they all compound to the ridiculous of the end result.
I've fixed another ridiculous security issue in the recent past without making big waves, where only one software architect understood the seriousness of just one option in a maven config file(a whole declarative security module was not being weaved into the bytecode because somone added another module and instead of both being applied, only the most recent one was being applied).
Techies repeating this should take a lot of the blame for why Windows still sell as well as it does.
A 50 year old electrician convinced me to start using Ubuntu 13 years ago after someone at his kids elementary school or something had told him.
UX wise Linux passed Windows in many areas around the time Ubuntu was introduced.
The only reasons now are prefererence, hard dependencies on Windows only software, stubbornness and incomptence.
Only the two first ones are good reason in my opinion.
Is this something you decided on your own was a fact? If I disagree, would I be wrong, stubborn and/or incompetent?
Also, I wouldn't conflate UI and UX.
I'm certainly not going to object to you having that view, but if that's how you see it then it's not a very interesting discussion is it? Would be like discussing whether the Beatles were better than the Rolling Stones "in many ways".
For what it's worth, I believe you are very wrong. But I understand and kind of appreciate this view, largely because it keeps me employed.
Things Linux did better at that time:
- installation experience, os: installation of a "pre-installed" Windows laptop could take up to 4 hours before you had finished completely.
- installation experience, additional software: I was good at removing Windows spyware and adware back when that was a local problem. Never had any Linux user with that it problem.
- driver issues: 50/50, since around that time hardware would mostly "just work" unlike Windows were one would typically, again at that time, have to hunt around the Internet or dive for the cd. Reason why Linux don't win hands down was because if something wasn't supported it would often be a dead end until next distro release, sometimes longer.
- end user support, other ux issues: the same, which means Linux probably win with a comfortable margin since Windows had the benefit of everyone "knowing it" and still didn't come out way ahead.
- in addition Linux typically is faster, even to this day, which is a huge issue with some users.
You might have noted I wrote in many areas, not all.
For users who earn their livelihood with Autocad and Photoshop I'll have a hard time recommending Linux. Same goes for people who have tried Linux for a few weeks and still don't like it. It might be preference or it might be stubbornness, I don't care.
But blanket statements like the one I replied to:
> As well as cutting 98% of your workforce as no office employee knows how to work on anything different.
is just plain wrong. The fails here are mostly related to other issues, not dumb users. (I really don't like that idea that all users are so stupid they cannot change adapt.)
If anyone needs Excel they get it.
So far I've spotted I one person that probably uses Excel. No complaints that I've heard or seen.
Most of my work with a wildly spread organisations and we can have excel go through US to Russia to Uk Back to Ukraine and then back to me in the UK
The actual friction will come from Windows sysadmins with no other practical skills.
This is why I think one of the key things is in stack standardization (choose best in class foss tools that match requirements, for example, I personally have a gpl or gpl compat requirement), and stack size reduction (which means you don't need every fancy sounding tool that you hear about, make sure the use case is justified first).
People have such a stockholm syndrome relationship with MS (and proprietary sw in general) it's absolutely sickening. For example, I think educational institutions should be teaching and using FOSS first.
Some will whine about no one using linux or not knowing how, and one response I use is "you had to learn how to use windows too, and even it changes things up, just look at 7 to 8/10, so why not learn to use gnu/linux and free yourself from MS?"
But from a company's perspective, if they have to pay 1M for an infosec team over five years, or 1M for a breach once every 5 years, what's the difference? You're still paying the same amount of money.
When does infosec start to realize that it's not just about company costs/risks, but the lives of all those users who are going to get screwed when your 'low risk = cheap fix' mentality pays off?
I'm in the Equifax breach (like sooooo many more)... part of my 'general concerns about the world' is whether/when I get my life hacked and have to rebuild.
Let me know where you get hired next, so I can take my business elsewhere.
> lives of all those users
Equifax cares about one thing: earning profits for its shareholders. They got caught with their pants down. Now other companies can look and try to estimate their expected cost of being breached (probability of being breached multiplied by the dollar cost) vs the dollar cost to upgrade their IT systems, infrastructure, management, company policies, etc etc etc. Realistically, Equifax is probably incapable of doing the necessary changes upfront without a complete overhaul of it's people and leadership structure.
The vast majority of companies will spend the least amount of money possible to pretend that they fixed the problem.
You want companies to care? Then create regulation that protects
> lives of all those users