No. It never takes only one employ clicking a bad link. It takes that click, plus a browser/email/os system that allow for random code to executed. It take an IT department that has allowed individual non-IT employees to use computers with elevated privileges. It requires a management structure that has failed to invest in proper off-site/cold backups. It requires an organization that doesn't have a proper business continuity plan.
And at the top of the incompetency pyramid, it requires a vendor that sells an email system that allows evil email messages to somehow infect entire operating systems. Want your email to connect to your office suite? Sure. Want to install random software based on clicked links? Sure thing. Want to update your firewall, install a new browsers and simultaneously backup all your encryption keys to a random server in the far east? Why not! Anything to make your operating system experience seamless.
Locking down admin access is less about protecting the local machine and more about preventing the laptop from becoming a jumping off point into more important pieces of infrastructure. It's by no means fool proof, but it adds another security feature that has to be countered.
I don't know whether it's worth the trouble it creates, but I don't think it's totally without justification.
- A phishing email which can pwn you without user interaction is basically unheard of.
- Even malicious sites generally can't do anything bad simply by visiting them. (and yes, I'm aware browser exploitation exists, but it is exceedingly rare)
- Ultimately, it's entering your credentials in a malicious site which is what puts users at risk. A user must click a malicious link (sometimes two) and then intentionally enter their credentials into the malicious site.
Between this, and the fact that users must read emails, visit sites, and enter their credentials over and over, just to get through their workday, I believe the outcome is that user education doesn't amount to much. It would be much better if a normal user's workflow didn't usually require clicking on email links and then entering their credentials. The fact that this is required means that even a savvy users will eventually be tired / rushed / working on automatic and get owned.
If you extend from "email" to the other communication tools that companies use today (and do use for inter-company communications too), there actually have been a number of these in the past year.
Outlook [3] had one that didn't require downloading the file, exactly - the "Preview" window from just clicking the attachment once, was enough.
Microsoft Teams [0], Jabber [1] and Slack [2] were all hit by real 0-interaction RCEs.
[0] https://github.com/oskarsve/ms-teams-rce/blob/main/README.md
[1] https://nvd.nist.gov/vuln/detail/CVE-2020-3495
Good post. I don’t mean this criticism for you specifically. But, why is there an assumption among HN types that there are no bad-actors among the insiders? You can have all the safeguards you want, but if an insider deliberately installs something, you’re screwed.
In some industries — armored trucks, banks, military stuff — there is a huge emphasis on background checks, security clearances, and the like to weed out bad actors. (And, even then, it often fails.)
I sense there is nothing similar for employees handling the company’s data. Obviously, there might be background checks and the like — hell, McDonalds has background checks. But, I’m not aware of the intensive FBI-style screening you see in the aforementioned realms.
Am I wrong?
How many thousands of people, for instance, could corrupt or lock the data at, say, Amazon? Are these people scrutinized to the same level as standard Brinks Armored Truck driver? I doubt it.
- is protecting against internal sabotage actually different that protecting against external attack. I don't think it's all that different. It comes down to authenticating actions and enforcing the principle of least privilege. If you built a system that was actually secure (i.e. one that depends on reasonable inconveniences, rather than one that depends on people to be perfect all the time or is so inconvenient it inclines them to do the digital equivalent of jamming the door open) it is likely that it will be secure enough against most internal saboteurs.
- is protecting against internal sabotage going to pay off? Most people probably aren't inclined to deliberately target their own company. It's far more likely that there is a bad actor in the world who wants to target your company, than that there is in your company. And making a person's job secure less stable is probably going to make them more likely to be a saboteur, so you should carefully evaluate whether gratuitously adding stress to someone who might get behind on their mortgage is a good idea. (Which I suppose is what this kind of background check would cause.)
“Most” people are law abiding. So, I agree with the first sentence.
The second sentence, however, has little support. The universe of people who can do these types of attacks is large, but not universal. You need computer skills. Necessarily. Those with computer skills are usually already part of the industry. How many disgruntled people pass through the FAANGs each year? Now add in all the IT positions at the banks.
In short, there are probably tens of thousands of domestic ‘bad actors’ who have (or will have in their careers) access.
Probably more.
Your argumentation doesn't challenge the truth of falsity of the statement, nor does it go towards challenging my conclusion. It seems to assume I've said "there are probably no internal bad actors", when I've said "securing your system against external bad actors will deal with the cases more likely to occur, and will usually be sufficient against the less likely cases".
'X is more likely than Y and preventing X mitigates Y to a tolerable level' is not equal to saying 'Y probably doesn't happen'.
> How many disgruntled people pass through the FAANGs each year? Now add in all the IT positions at the banks.
Obviously the probability increases significantly with the number of employees, but I don't think that switches the probabilities. Still, the most important companies to consider are the companies which, unlike FAANGs, aren't really in a position to make independent judgement about their risk profile, but whose existence depends on their records/data. And even someone with as many employees as the US government probably has more people outside of their employ who want to target them than inside, although surely they always have some of both.
I'm not sure what the relevance of your reference to computer skills is. In order to ransomware a company, as far as I know, you need to buy software off the darkweb and run it from a vulnerable location. I suppose technically that requires computer skills, but it's surely not what you mean. And the companies which are vulnerable to ransomware are not all employers of significant numbers of technically skilled people.
In any case, I don't think even a gratuitous reevaluation of the probabilities significantly changes my conclusion. Even if we assumed the improbable notion that every single company in the word has a disgruntled employee and that there are no external crooks, the process of securing the system against external crooks will make it far more survivable against single internal bad actors, and the effect it has on the employees will be less likely to produce internal bad actors.
The entire issue just leaves me with a nagging feeling that something fundamental is being overlooked. There is something profoundly different in modern companies that didn’t exist a few years earlier; namely, a very tight concentration of data/ops/control. Whether it’s external or internal, it seems a single person can do catastrophic damage to the company AND the customers. Fifty years ago, for instance, in a typical auto plant, I doubt a single person could have truly devastated the company (short of a bomb or arson or something). Nowadays, we’re moving towards systems where not only could a single bad actor cripple the company but also cause all the cars already sold to stop. (I exaggerate a bit, but you get my point I hope... )
But in the corporate world, theres gotta be huge variance, but so many don't give a flying flamingo who's scoping out what, unless somebody is forcing the issue (and also auditing and reporting to the compliance department, whatever thats for).
They know the people in the NOC/SOC, the C-suite has equity, there may be physical access control, cameras and proxcards out the wazoo, but when Marge from bizdev needs those emails for the marketing newsletter or whatever, she is gonna get them immediately and hand them right over to the intern or vendor or Doug, whatever his job is.
For all the obscene value that the data and access represents, its encrypted, right? What could go wrong? Want to background check the sales people? But... look at this guy's resume! He's only asking 80% of the market rate! These dialysis machines sure won't renew their support contract by themselves.
Best case scenario is that the costs mount even higher into the stratosphere and people start demanding a second look. It's been a while, Maersk, JP Morgan, TransUnion, Colonial Pipeline, Beef, Hospitals, Schools, the OPM (for god's sake...) billions or trillions of dollars. It doesn't seem to be a priority.
It's like compartmentalization on a battleship. A single hole won't sink it, in fact, many holes won't.
It sucks locking things down for each employee, and subjecting them to bureaucracy to unlock things they need to do, but it's better than ransomware.
It's unrealistic to expect every employee to catch hacking attempts 100% of the time.