When ignorance becomes so widespread that it is enforced by law, and wise action is actively punished, and one cannot really blame rational actors for taking the CYA approach. One can hope that some of them take a principled stand and the risk of punishment to do more; alternatively, we can expect to collapse and be replaced by a smarter, if more brutal regime. One way or another, the bleeding always stops.
Is there any evidence that this happens? I feel like there's a lot of these kind of spooky 21st century "folk-wisdom"(s) out there and if you actually trace it back its like the McDonald's hot coffee case or whatever.
This is totally unacceptable and legitimately dangerous. Dialysis machines are hooked up to this trash right now!
We require enforcement, jail, fines, and civil liability for this gross, aggravated negligence.
But yeah. Software needs to get fewer, simpler, easier to understand, verify and build. Hardware needs to be simpler and easier to understand - and possible to verify. And there needs to be awareness this isn't some hippy-dippy sentiment of strange neckbeards, but rather its the only way to get the security we all need. "Every exploit can be turned against it's owner" needs to be drilled into engineers, executives and lawmakers at every level until they hear it in their sleep, and recoil in horror when anyone even suggests knowingly shipping an exploit.
A lot of the "security best practices" just become checklists of what people thought were good ideas 20 years ago and enforced by auditors that only know how to check boxes.
aka sales & marketing.
I wonder if the background of senior leadership is predictive in these sorts of situations. E.g., Equifax had a CISO with a non-technical background at the time of their breach, and Kaseya's leadership is dominated by MBAs and accountants.
Sometimes I feel like the idea is just to kill productivity.
They kill productivity in exchange for job security.
I have argued that the raison d'etre of security policy is to ensure the existence and continuity of an environment in which work can get done. I've been told about the importance of the C.I.A triad and other things as though they were refutations of my point, often in tones of voice implying an attitude that this not-security|compliance-tech-is-incapable-of-knowing-what-he's-talking-about-and-therefore-can-be-ignored. I counter-argue that C.I.A et. al. are not refutations of my thesis, but in fact support it. If you can't ensure the confidentiality, integrity, and availability of information or systems for yourself or your customers, you do not, and/or will not, have an environment in which work can get done.
So, for the love of getting shit done, stop masturbating with broad and blind application of checklists, and take the time to sit down, really look at what you're trying to do and why, and develop actually useful risk models. And then develop security policies against those risk models. Yes checklists and various standards are useful tools that can help you cover a lot of common stuff, but are not the whole picture.
If your SSO isn't, use a good password manager.
Admin access for devs should be audited, and devs should understand that now they need some opsec. Like, separate work and personal machines; if not physically, at least use a different account, better yet, a VM.
To say nothing about adding suspicious email / IM attachments.
Remember, devs: you are a potential attack vector, a very efficient one.
Blue teams are behind from the start due to the nature of the security landscape. They are further hindered by misguided application of the "move fast and break things" method. You aren't supposed to break your C.I.A. and expose customers and everybody else to huge liabilities.
Security needs to be baked into the infrastructure and IT management practices from the start. This requires enforcement, jail, and civil suits.
Office of Personnel Management, Ashley Madison, Target and countless other retaikers, Dams and Pipelines and Water, Maersk, Linkedin, all these supply chain hacks and schools and hospitals across the country and the world.
This has been going on for decades now, with no accountability at all. It just doesn't seem to be a priority.
What in the hell are we doing? Why do MMORPGs have better security than the hospital??
Seems to me like a centralized system is fine, as long as it’s properly designed and implemented. The problem is how a business can know that an IT security system is properly designed and implemented.
The only solution I see is to couple insurance with an IT security system. If you’re certain your system protects against IT threats you should be willing to compensate your customer in case it fails to do so. Otherwise your customer has a very hard time determining whether your IT security system actually works.
Removing the "remote" from "remote administration". It's more expensive but probably still not cost-prohibitive -- driving around to client sites and installing updates is not particularly skilled labor. Plus even the worst-case scenarios are far less worse because you already have a local workforce who can do site visits to manually recover systems locked down by ransomware attacks. Data might get stolen, but at least you have continuity of business.
We have narrowed the attack surface of networks drastically, the solution is not to undo that, but to keep narrowing it. There's a lot of room for improvement especially in service accounts, admin accounts, and crucially, more intelligent behavior detection.
Despite Microsoft's best cloud security capabilities, it still doesn't seem to mind if a senior citizen's Outlook.com account is suddenly logged into in Nigeria, and even after "securing the account", it doesn't clear their devices they connected while they were in the account... That's a consumer example, but there's so much room for more intelligent behavior detection, and it to make it down to base-level products, and not expensive add-ons or upgrades. Even the big companies don't do a good job at it on their own systems, much less the systems they sell to other people.
You have to have a certain tier of premium Azure cloud-based subscriptions to get reasonably decent security controls, while if you have a Windows Server-based network, your security options are the same as you had back in 2008.
Geo-IP services are routinely inaccurate. I'm in the Southern US, the IP I used to get used to get me tagged as if I was from Quebec City. It was like that for over two years. A friend's house a few neighborhoods over showed up as some small town in Kansas. I could go from my home network-wise in allegedly Quebec City to my cell phone which showed as a town about 50 miles away from my actual location to Kansas in 10 minutes. If places banned based on these kinds of Geo-IP databases I'd be banned from most of the internet.
And there's a difference between "ban everyone reporting outside their city" and "flag unusual behavior and trigger additional protections or checks". Think how your credit card works when you suddenly make a purchase in Las Vegas.
And in my cited example, the logins were reported as malicious to Microsoft, their account panel said the account had been "secured" since then... but Microsoft apparently let an Android phone the attackers linked up in Nigeria remain connected to the account, giving them persistence past password resets.
It seems like centralized, locked-down IT combined with security that's mere security theater while allowing third-parties to willi-nilli update their stuff.
Try to get Windows 10 to have an uptime of more than two weeks without an Windows Update and reboot cycle.
Email viruses aren't really a thing like they were back then too.
The "security best practices" are a cargo cult exercise that just lulls organizations into believing they're protected against motivated actors, when instead they're just enforcing a group policy on a good day.
Well didn't their Cyberdefense playbook have anything to say about simple ACLs protecting those internet facing systems that were vulnerable to SQL injections? I mean even a very broad ACL allowing an entire country geoip block would be better than nothing.
Yea. You have money somewhere, but when you go to get it they’ll find you.
Crypto laundering has made that trivial now. So, no, I don’t believe the NSA has back doors in “everything”.
(Nor would I consider the NSA to be unequivocal “good guys” who selflessly help businesses and employees)
[1] https://en.wikipedia.org/wiki/Utah_Data_Center
[2] https://en.wikipedia.org/wiki/Room_641A
[3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
The first thing being hard is evidence that the second thing is not true, and people just like saying it because they enjoy posting the most cynical take they can.