Wide-ranging SolarWinds probe sparks fear in Corporate America
reuters.com
reuters.com
Money-handling, for example (banks, payment systems). If ever there was a Fraud Magnet, that's it. I've heard PayPal described as "a giant fraud-detection system, wrapped around a tiny money-transferring system."
And yet, they don't seem to be in the news all the time like "data theft" stories are. Could it be that the legal and regulatory and insurance systems have made it a manageable problem? Someone steals your credit card, your losses are capped. Someone steals your Personally Identifying Information, sorry, pal; change your passwords.
So maybe treating PII as the same thing, in every way, as money is the answer.
That's the way how most of the world has mostly solved identity theft, however, it's not that easy to implement in USA because there's no system of universal secure IDs in USA (by design) - there's a multitude of ID forms, some of them are not really secure (easy to forge, no verification if it was really issued by the institution who did so, no easy process to quickly verify online if the provided credential has been lost/stolen/revoked, etc), and there's a sufficiently large minority of potential customers who don't have a valid ID.
It would be helpful to have laws that clearly assign the credit fraud risk fully onto the defrauded companies instead of the people whose identities were used, as experience shows that this would rapidly result in improvements to fraud elimination (there's all kinds of measures that simply are not taken since they add friction), however, a proper solution does require a decent state-run identity system as the foundation of trust, and USA has made a political decision to not have one.
The root of the problem is sharing the private information. Why your credit reports are shared among completely different entities? Nobody want to gives them a consent to share your private information.
> system of universal secure IDs
Actually, it's the opposite. US has universal ID(not secure though). That's the problem. If there exist one idiot who doesn't verify your identity, everything fails in chain reaction, because everybody else believe the idiot.
Do we? Our SSN is not a unique number, and not just because the keyspace is too small for our population. (It's worse: some of the prefixes are geographically related.)
https://www.ssa.gov/employer/randomization.html https://www.ssa.gov/employer/randomizationfaqs.html
Even if what you say were true, handwaving this as unimportant because it only affects people over the age of ten seems a bit silly.
The post that I replied to is almost entirely incorrect as it relates to available SSN “keyspace” (misnomer), uniqueness, etc.—-for which geographic prefixes and group numbers are relevant.
I supplied direct sources, so no idea what your “even if what you say were true” skepticism is rooted in.
Freeze your credit. Burden shouldn’t fall on the consumer, but it’s easy and easy to lift when needed.
Identity Theft is actually just fraud. And the companies that allowed the fraud should be required to shoulder the burden of addressing that matter with the actual people who committed the fraud. No part of that burden should ever be placed on you, just because someone pretended to be you and commit a fraud.
But I think this is mitigated as long as it’s optional for a company. The company is held liable for any fraud that they allow. The company has the option to use the government ID to prevent fraud, but they can also assume more risk and take on a customer without the “official” gov ID, if they want to.
I can see this resulting in something like creditors saying: “either you can use a govID to sign up for this credit card, like normal. OR you can send us a $10k deposit and forego the govID entirely, if you like.”
This solution makes it so that companies are held more responsible, but decreases the risk of having more government power by making it a decision for the company’s “risk management team” to decide.
How does that not already happen, just inefficiently? It's hard to function in the U.S. if you don't have a Social Security Number — that's why people bother using someone else's — and we already have a de facto ID system for most people but it's a patchwork at the state level which was somewhat federalized with RealID.
It's hard to imagine an environment where people would unjustly be “cut off” where the state level system would prevent abuse which would otherwise happen — it's not like, for example, California stopped politically-motivated DHS activity during the Trump era.
My hope is their anti-vax research eventually leads them to learning about DNA.
So, in practice, anything that pattern-matches to "people will need to carry some sort of token given by a big organization (private or public) to pay or be paid for goods and services" will be viewed by some as the Mark, or a slippery slope towards the Mark.
Anyway, the Mark as described in Revelations is pretty... bodily, for lack of better term. It evokes the image of getting a barcode stamped on your arm or your forehead, in exchange for swearing fealty. The Mark feels like a concrete, physical thing. That's why things like "government ID" or "payment chip in your arm" pattern-match to this prophesy for so many people, while things like "mobile phone number" or "e-mail address" don't.
(There's also a factor of scale/graduality. For people alive this century, countries and governments were always a thing. A big thing. Banks too. The governments, the UN, the international financial system - they look big, evil, and pattern-match to the Beast. In contrast, for most people alive today, mobile phones and e-mail addresses were something they've seen introduced gradually, from great many independent vendors. They don't have this obvious Beast-like quality.)
Source: grew up as Jehovah's Witness. While I obviously can't speak for all fundamentalist Christians, and while JW teachings don't consider government IDs to be the Mark[0], I got pretty familiar with the patterns of thinking people show around this topic.
--
[0] - They do, however, believe that the Beast described in the Revelations is currently embodied by the United Nations. So if the UN ever proposes a common ID scheme or an electronic payment system, I'm pretty sure plenty of Witnesses will throw a fit.
It'll be really hard to convince people to give up the convenience and higher returns of online-only banks.
A better option would be using cryptographic digital signatures by an HSM (smart card) to verify ID for financial services.
Framing the action of defrauding a person as a downstream effect of being a victim of theft, is nothing short of institutionalised victim blaming. No, just no. The person was defrauded because of stolen identity and/or payment info documents. They were not a "victim of theft": they were a target of fraud.
Calling it theft is a sleight of hand to absolve banks, payment providers and businesses from their responsibilities.
Using a secret number to verify identity is absurd and hilarious.
How? Money is fungible, PII is very much not. It's not like they can give you a new identity if your identity is stolen.
Credit cards generally have one use: payments. Usage is not difficult to quantify. The card is generally worth the same to whomever is in possession of it.
PII has a multitude of uses. The prices offered on the black market for PII do not reflect its value to those that it identifies or those from whom it was stolen.
Banking industry isn’t better because they have solved the problem, they are just hiding behind the fact that victim can be compensated and hence an insurance can cover all risks
The premise of the talk, as I understood it, was that too many small operations or "mom and pop" shops think that they do not need "Department of Defense" level security, because they're a small general store, not Fort Knox. That's a misconception. "DoD Level Security" doesn't mean that you protect your place like the NOC list in Mission Impossible; it means that you are proactive in thinking about your thread model and assessing the value of your assets. If, after proactively thinking it through, you're still comfortable with just a cheap pad lock and no alarm system, then you've applied "DoD Level Security" (or something like it).
The answer, as it often is, is for regulatory pressure and robust enforcement to connect the externality's consequences back to the agent. The easiest step is by requiring disclosure of breaches. As such, the news in this article seems like it should be unequivocally celebrated.
Oh, but the problem appears when you'll holding other people's information. "Your SSN ain't worth much to me, sorry, keeping that pipeline open only matter X much to our bottom line," etc. .
"Good Security
Yet somehow, keeping their PII imposes almost no obligations on you at all.
About god damn fucking time.
If we can make security lapse expenses higher and higher we can all pay more and more until all products are completely secure but no products remain....
So you might save $5 on the price of the "smart doorbell" and then loose $50,000. Obviously there is some kind of balance that needs to be struck, but the amount of data leaks and fraud is plain out of control at the moment,
If a business cannot manage, it closes, as simple as that.
IMHO the Kaseya hack was far worse, maybe worse than WannaCry but with better outcomes. This was a criminal operation, provided by criminal software suppliers that really was only resolved when the keys were leaked on a forum.
The rumor is that local intelligence forced the disclosure of the keys (eg: guns to heads), because this is pretty much the destroy the world scenario that is unstoppable. It is easy easy for attackers to cause billions of dollars of damage in a day.
Its not getting better. It can't. Our systems are designed for large scope of trust with massive surface areas. Security is a game where the defenders cannot mess up once. Its hopelessly asymmetric and can never be better.
Coincidence theorists are the real crazies.
If you look at how this sort of thing is regulated, there’s two general approaches. The first is creating a category of data that requires special protections, and defining a standard for protecting it. Either through legislation (like HIPAA), or self-regulation (like PCI). The other is to specify a requirement to protect all PII, but not define any specific standard for protecting it, only prescribing penalties for failing to do so (when seems to be what the EUs regulatory approach is).
Both of these approaches are problematic.
Is it self-evident that any breached data was not sufficiently protected? I don’t think any experienced professional would agree. It is impossible to build a system that is completely protected from being potentially compromised, and it’s possible for a largely unprotected system to last its entire lifespan without being compromised. So the simple fact that a system has been compromised doesn’t necessarily reveal any information about how adequately protected it was.
On the other hand, is there a single security standard that’s widely regarded as being good? I don’t think there is. The ones that are generally regarded as the best I would personally consider to be not bad, but not great. One size fits all solutions tend to find a lot of not fit for purpose use cases as well.
It’s also not apparent to me at all that spending more money on security achieves better security outcomes. I’ve worked in numerous large enterprises that spend enormous sums of money on security budgets, and manage to achieve very little with it. So I don’t think you’re going to get much consensus on that being a suitable metric for how adequate a company’s security systems are either.
You could easily devise a system that punishes companies for falling victims to these attacks. But that’s the only outcome it’s going to achieve. A punishment for being the victim of a crime.
9 July 2021 - phone call between Joe Biden and Vladimir Putin. ... Biden later added that the United States would take the group's servers down if Putin did not
13 July 2021 - REvil websites and other infrastructure vanished from the internet
23 July, Kaseya announced it had received a universal decryptor tool
I'd love to read the real story behind that. Perhaps "guns to heads" did happen.
[1] https://en.wikipedia.org/wiki/Kaseya_VSA_ransomware_attack
s/likely/definitely/
Yes, tens of thousands of companies were hit by the trojaned update. IIRC, only 30 or so companies were then exposed to the second- and third-stage malware. The attackers were very careful: for grand majority of affected companies the functionality was disabled shortly after infection.
I have heard two plausible theories why this might have been the case. One is that the attackers wanted to avoid detection as long as possible, and the ongoing additional egress traffic would have been easy to detect. Another is that they wanted to protect their infrastructure from being flooded and their collection systems from getting overwhelmed. Personally, I think it's a bit of both. If you're after intel and want to find needles in a haystack, the last thing you want is truckloads of more hay.
Its annoying that there's law for people, then there's laws that apply to some corporations, but not always and not all of them.
"Maintaining an attractive nuisance" is what they tell people with unfenced junkyards, right? Why couldn't that apply to some of these folks aggregating data about our kinks "unwittingly" displaying the results to the world.
As with all aspects of modern business operations “how to do it right” has been crowed about for decades by experts who care. It’s just that nothing matters until it matters, such as waste disposal, workers rights, product safety, etc…
If you show me the incentives I’ll show you the behavior. The only way we will ever get data security to matter more than theater and “check the box” is for the obvious to happen (bad consequences).
We don’t have a Ralph Nader.
This is why I’m against responsible disclosure, accepting below market payouts on bug bounties, and generally treating companies with any modicum of trust. Until it hurts so bad that people are on the steps of the capitol building beying for the blood of CIOs will we see meaningful change.
When you have a network security department unable to articulate its policies, which relies on vendors for everything including expertise, you damn well should worry.
If it's a public company, it's securities fraud. IMHO, securities law is the most effective tool at the moment in encouraging improved security engineering, best practices, and posture.
https://www.sec.gov/news/press-release/2021-154
""As the order finds, Pearson opted not to disclose this breach to investors until it was contacted by the media, and even then Pearson understated the nature and scope of the incident, and overstated the company's data protections," said Kristina Littman, Chief of the SEC Enforcement Division's Cyber Unit. "As public companies face the growing threat of cyber intrusions, they must provide accurate information to investors about material cyber incidents."
The SEC's order found that Pearson violated Sections 17(a)(2) and 17(a)(3) of the Securities Act of 1933 and Section 13(a) of the Exchange Act of 1934 and Rules 12b-20, 13a-15(a), and 13a-16 thereunder. Without admitting or denying the SEC's findings, Pearson agreed to cease and desist from committing violations of these provisions and to pay a $1 million civil penalty."
That's just a fucking sad state of affairs. Apparently they owe nothing to their customers.
I can understand companies being worried that a compromise of a test system with no access to sensitive data -- which they normally wouldn't be required to disclose -- could make them look bad. But at the same time they're all being required to disclose this info so at least there's safety in numbers.
https://www.reuters.com/technology/hackers-demand-70-million... (July 2021: Up to 1,500 businesses affected by ransomware attack, U.S. firm's CEO says)
(disclosure: infosec practitioner)
So even if a system with absolutely no information was breached if your other system(s) use(s) the same or similar security then it doesn’t really matter that nothing was taken. The breach could still material (and require disclosure) because it’s exposed a material security vulnerability.
A public corporation has a legal and fiduciary duty to its owners other than hiding what happened.
I’m skeptical that a probe will have any more teeth than the censorship testimony fist shaking we’ve seen at Zuckerberg and Dorsey.
Even if there is, the solution needs to be punitive. That if you ship shitty software and didn’t follow good practices that you’ll be investigated and fined. New frameworks for what constitutes software negligence.
The last thing I would want to see is software regulation, oversight of development, Government access. For about a dozen reasons each.
But of course with the extreme shortages companies will basically hire anyone fresh from college and the level of responsibility from people in the industry is low.
Compared to engineering where you often see the same things from job to job.
However, because the majority of software does not affect the safety of human lives (the exceptions being software that operates critical medical equipment, avionics on aircraft and rockets, etc.), the target level of reliability is not nearly as high as in the engineering of objects that do affect the safety of human lives (like buildings and bridges). Humanity also has centuries (indeed, millennia) more experience with the construction of physical objects, although rigorous scientific design of them only began in the last few; and even modern era engineering fails to account for all factors (e.g. the Tacoma Narrows bridge that collapsed due to oscillation induced by wind: https://en.wikipedia.org/wiki/Tacoma_Narrows_Bridge_(1940) ). Modern engineers operating today still make mistakes that cause death, such as the collapse of the construction crane in Seattle in 2019: https://en.wikipedia.org/wiki/Seattle_crane_collapse (due to wind and unsafe operation IIRC).
If you're building a website or app where people can order food from restaurants and creating a market for couriers and consumers to connect, then no aspect of your software has any affect on human life. (The software might tell the courier where to drive, but they are responsible for driving safely to those locations.)
When we consider software that is responsible for the operation of autonomous vehicles, or the avionics on aircraft or rockets, then the level of engineering reliability is targeted to match or exceed the reliability of the physical systems. A great article on the software engineers who worked for NASA on the Space Shuttle's software: https://www.fastcompany.com/28121/they-write-right-stuff
A software engineer is a person who can build software to a target level of reliability. That the targets are not always as high as "responsible for safety of human life" does not mean it's not engineering. I would give AWS's automated theorem-proving about the correctness of their TLS implementation as an example of a feat of software engineering that targets a high level of reliability: https://aws.amazon.com/blogs/security/automated-reasoning-an...
We might loose any respect for people in charge whatsoever.
And I think the discussion is about private businesses not some forced open source ideal you seem to have conjured up.
One good friend got audited five years in a row; maybe the local bureau chief was just sure he was up to something. The last time they were writing a check to him, it was going to be for less than $2, and the agent asked if they really wanted it — "Of course I damn well want you to write that check!".
I've had a career mostly in small businesses, and always had a CPA do it with never an audit. I strongly suspect that it not only likely gets me more proper deductions that I'd miss, but also gets a lot of points in avoiding an audit, since the CPA is also putting their license on the line by signing it. I'd recommend the practice, just find a good one who charges flat rate (they do exist, just takes some looking).
Don't talk to the police or the IRS. They are never aligned with your interests, and whether you get a reasonable person or someone who just loves to ruin your day is random.
If our local IRS equivalent contacted me "to clear something up", I'd defer them to my tax consultant in all cases. Assuming good faith with state employees is often a costly mistake.
Basically, give them only what they ask for and exactly what they ask for.
If no one sees something, it doesn't exist, right?
First, there is no unbreakable software. Second, software is written by average people vs above-the-average people who are hacking it. Mission impossible.
(1) How do you improve the state of the art, so that, if a company is serious about security, they can succeed?
(2) How do you fix the way companies are run so that they actually even try to take security seriously?
Both are big contributors to the overall problem.
I do think there is room for improvement in #1, so it's something we should be looking at. But we could get a lot of mileage out of #2 even if there were no way to move the needle on #1.
With regards to skill sets, I have repeatedly found that people who engage in hacking range from skill sets of "knowing how to use a hacking kit" to "uber developer with security knowledge". There is a wide range of skills and knowledge.
However, it is practically an entry requirement for someone in the security space to view software differently than most programmers. That is defined as non-average.
In turn, I guess a security professional is more scarce than an average developer. The question is if all security professionals are hired to strenghten systems, or some of them to break it.
More to the point, hackers can be very motivated to break things in a way that the average developer is not motivated to secure them.
The real issue is that software has many bugs as the sum of all contributes to it, and all it takes is finding one.
What I mean is that it takes just one sloppy developer to introduce a bug, and that's all you need.
Making unbreakable software is a much harder task than breaking it.
It's not about who's smarter, it's about what's easier.
I wrote code with no pressure, tested it used it for months, and with some input that I didn't think about it broke spectacularly... I might be below average programmer (although I would say no, from what I have seen so far), but as I said, the chain is just as strong as its weakest link.
Like, what? “Thank god, I only hire developers with a skill level of 78 so it will take a developer of skill level 79 or above to even have a chance at finding a bug here, and we all know skill level 79 developers are rare so I’m secure!”
This isn’t an RPG, life is full of unquantifiable things and differing conflicting incentives. If anything, the domains in which exceptionally skilled developers often work and the tools they use make bugs more common.
It doesn’t take a Linus Trovalds to find bugs in Linus Trovalds’s code.
By the way the worst clusterfuck I ever saw was caused by a very talented programmer that implemented a very complex object store on disk... the thing was brittle at best, and it failed in very spectacular ways.
Very entertaining to debug
dedicated above-average internal* cybersec staff < (SEC fines + outcry when breach goes public)
* external seems like a different can of worms. perhaps someone in cybersec can refute/expand
- require full disclosure to national data registrars following breaches from now on.
- Make source of income as big a deal as KYC
- make KYC a "walk in the branch with some photo id". How many of us really need to borrow thousands without going into a store or bank.
fundamentally, we have as much crime as we are willing to let the banks allow.
Either way, I’m glad government agents are going door to door to check on privately owned servers. Maybe they should check everyone’s vaccination status while they’re at it.
"In addition to the Securities Exchange Act of 1934, which created it, the SEC enforces the Securities Act of 1933, the Trust Indenture Act of 1939, the Investment Company Act of 1940, the Investment Advisers Act of 1940, the Sarbanes–Oxley Act of 2002, and other statutes. The SEC was created by Section 4 of the Securities Exchange Act of 1934 (now codified as 15 U.S.C. § 78d and commonly referred to as the Exchange Act or the 1934 Act)." [1]
[1] https://en.wikipedia.org/wiki/U.S._Securities_and_Exchange_C...
In essence, if you want to keep your dirty laundry private, then you're not allowed to take money from the public stock market, as investors (i.e. everyone if you want to be publicly traded) deserve to know about any major issues with your private servers. SEC doesn't care about how poor your security is as long as the company is open about it, but it absolutely cares if company lies about their (lack of) exposure to its owners.
These people need to be exposed.
Years ago, a guy I know was asked by management to spec out an email system that had no limits on the size of file attachments. He asked why and was told that 'leadership will have no limits on their authority... none whatsoever'.
When he produced the quote, leadership was in shock. The price was enormous. They told him they could not afford to spend that much money on a mail system, and he said, "Well, I guess there will have to be limits then."
For some reason I envy whoever got to hear that sentence in real life. It makes it perfectly clear that you're dealing with assclowns.
It will be unfortunate for them to hear that disk space places limits on their "authority."