https://twitter.com/BillDemirkapi/status/1506117152461496323
https://twitter.com/BillDemirkapi/status/1506117152461496323
It is a complex issue with entry of nuance I'm too tired to thumb type. I know there are lines that shouldn't be crossed. But it is so naive to think companies shouldn't have an eye on their data.
Do you think banks shouldn't have cameras in their lobbies? Or that tellers can walk in and out of the vault with black bags and no one ask what's inside?
To use your camera analogy, you better have a good lock on the security room holding the tapes.
Organizational endpoint security seems to be much more about incident response than incident prevention. That is, it's more focused on providing a nice audit trail that can be used to find and fire/arrest the perp once a breach occurs than it is at preventing breaches from happening. It probably fills a due-diligence tickbox somewhere, allowing the company to say "if a breach occurs (the probability of which is always nonzero) then we have measures in place to find out how, where, and by whom and mitigate the damage" to shareholders and important customers.
Software diversity is good. Remotely controlled mono-cultures are bad. IT management and security compliance people need to understand this.
I liken the mindset of (only we will use the remote control software to do good things) to Encryption back doors (only law enforcement will use them to catch criminals). Computer scientists call these 'Exceptional Access Systems' and it has been shown (many times) that it is impossible to ensure they will not be abused and used against you.
Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications:
What alternatives are there? I honestly don't know
If you're working from home and your device gets owned, and the attacker just sits there slowly slurping data as you go about your business... Chances are you're not going to detect it, but if you did you'd probably notice it's running when it's not supposed to and it's sending network traffic when not actively used.
If someone uses a laptop breach to go look at data you wouldn't normally look at ( or tons of records ) an audit log would give that away.
So really to do security well you have to profile the role. Why are you looking up customer record abc123? Trying to see what your girlfriends doing, or is it because they've called the customer support line?
You basically have to define what does misuse look like and protect for that.
Back on the slow slurp, hardend immutable devices that are regularly updated with limited Auth sessions would likely contain the breach.
Same deal on servers, you harder to stop it, but you monitor for when it happens.
Do people really monitor though? Some, sure, but your average org buys a tool the fails configure it with any sort of context.
Software diversity also means attack surface multiplication, so it's a delicate tradeoff.
I have talked to security engineers that have had the company procure millions of dollars worth of security tools, and yet they don't even know the basics of security.
For God's sake, I had to explain what end-to-end-encryption was to a team of "senior" security engineers the other day. They genuinely had no concept of it. As a security SWE I am so done with these sort of people. Fuck them! Why are they even in security!? Real private data is at risk because of their incompetency!
It would be interesting to know Tanium takes to backport security fixes. I mean py2.7 was sunset 2020-01-01 [1].
[0] https://www.tanium.com/ [1] https://www.python.org/doc/sunset-python-2/
When I was in college the whole student network went down. Apparently there was a hack from the student network to the campus police network, so campus IT pulled the plug on any of us having network access. Because those two weren't separated because why would they be?
So I hoofed it to the IT department and I asked to talk to someone who knows a thing or two about networking. The director of IT came out. He sat me down and started telling me about the $300,000 budget he just got approval on. I was thinking, you can't take some of that and stand up a router with packet filtering to isolate the student network from the police network in two different subnets? A FreeBSD box might do in a pinch. (It was the early 2000s and network traffic loads were... different.)
I learned a lesson that day about seniority and the Peter Principle. Climb high enough and your mindset changes, from technical solutions to issues of money and resource allocation. From there, "let's just pay $VENDOR to do it, they'll solve the problem for us" is but a small step.
Same company had a head of security who was full-time employed by two different companies at the same time (he had unlimited vacation time for both) without either knowing the other existed.
Best thing was that the company did investment/insurance services and had a banking division.
0: https://twitter.com/BillDemirkapi/status/1506123471352438784