> About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
> About half of the company's 500,000 servers run on outdated software that does not support basic security features such as encryption for stored data or regular security updates by vendors
That 500k servers in Twitter infra are missing patches certainly is true and what was likely in the original was a statement that stored data that should have been encrypted at rest was not, and/or that acceptable standards for data at rest encryption, a relatively rapidly moving freight train, were not maintained.
One definition is "the underlying disk is encrypted". This is true, by default, of virtually all cloud environments these days. But it really only protects you against physical access to the storage media, which actually is far from the top threat.
The other, more useful/meaningful definition, is "we encrypt everything at the application layer before it is placed into the DB, and all decryption requests are logged by user". For example, using an envelope encryption scheme to encrypt data before it is stored in a DB, and upon retrieval decrypting the data with a call to something like KMS. In that environment you can literally give readonly DB access to all your developers and not have to worry about PII being exposed. If hackers somehow got access to your DB, they wouldn't be able to read sensitive data, and if they also managed to get access to your KMS credentials, any attempts to decrypt the data would be tracked and logged.
My point is that when many companies say "we encrypt your data", they are usually just talking about the first thing, but that doesn't really provide that much additional security. The second definition is really what you should be doing.
The thing is FDE essentially only protects your data when your machine is powered off. Once your machine is booted and you've logged in any block level encryption ceases to be relevant, because to get to the point of running your machine has to have loaded in the relevant key material to decrypt. From that point on user space code no longer sees a difference between encrypted and decrypted drives. In other words FDE is not relevant is you lose a powered on device (post login if relevant to the platform), and you're the kind of person people are actively targeting (I recall recently? the content of someone's phone or such being dumped by the FBI because they grabbed it while it was being used).
That's why modern OS's have different key classes, there's the lowest level which is just FDE, but you can have higher levels where requesting key material essentially just gives you a handle to that material. Then the OS, or preferably hardware with a much less complex OS, manages those handles and invalidates them according to policy rules. e.g you may want your phone to have access to your address book while your phone is locked, which does not mean you need your call history available as well.
The policies provided by OSs tend to be fairly simple because it's better to have an easy to understand API that is easy to use and hard to screw up than a more "powerful" API that is easy to screw up and hard to use (the latter resulting in people simply not encrypting things at all). e.g iOS/macOS only has the following file protections when you create files: "NSFileProtectionComplete", "NSFileProtectionCompleteUnlessOpen", "NSFileProtectionCompleteUntilFirstUserAuthentication", "NSFileProtectionNone", but they're very easy to understand.[1]
I tried to find the android equivalent but I don't know the terminology that's used and I just get linked to instructions on using AES, so if someone could link the correct doc I'd appreciate it.
[1] https://support.apple.com/guide/security/data-protection-cla... and https://support.apple.com/guide/security/keychain-data-prote...
From https://www.washingtonpost.com/technology/interactive/2022/t..., page 6:
"..more than half of Twitter's 500,000 servers are running out-of-date operating systems so out of date that many do not support basic privacy and security features and lack vendor support. More than quarter of the 10,000 employee computers have software updates disabled! More than half of Twitter employees have access to Twitter's production environment -- unheard of in a company the age and importance of Twitter, where nearly all employees have access to systems or data they should not. At Twitter engineers work on live data when building and testing software because Twitter lacks testing and stage environments; work is conducted instead in production and with live data..
"This did not happen overnight. To get where Twitter is today took.. many years.. required repeated downplaying of problems, selective reporting, and leadership ignorance around basic security expectations and practices."
If you're trying to prevent an actor who has gained a foothold on a box/network from seeing plaintext data that is actually in use by the actual production system at that very moment, you're looking for a much stronger type of control - probably some sort of client-side encryption or obfuscation/tokenization
So it is just a checkbox then.
Big tech was taken over by bean counters long ago, the fact that it’s all running on duct tape and popsicle sticks under the hood will come back to bite us when we have a digital Pearl Harbor event.
China will invade Taiwan and the first shot won’t be physical, it will be activating the 30 years of assets they grew in AWS/GCP/cloudfare/level3/AT&T/Etc
Most of their HR/engineering departments are completely retarded. They’ll hire any H1B who passes l33t code that accepts $50k under market rate then give them repo access in a few weeks. Our soulless megacorps are beyond easy to penetrate by hostile intelligence.
The CIA/NSA/FBI, you know the groups who we pay billions per year for and they take half my income to fund will of course not catch any of this.
The FBI is too busy manufacturing domestic terrorist, the NSA is too busy hacking American companies, and the CIA is too busy importing drugs to actually secure our country from foreign attack. Why? Because it’s been so long since we were actually attacked they believe it can’t happen so why not loot Rome in the mean time?
> allows too many of its staff access to the platform's central controls and most sensitive information without adequate oversight
It'd be even easier if you find an employee who's on the same political team as you.
It's one of the reasons I disliked Twitter forcing the use of mobile numbers for 2FA, they're just not sufficiently trustworthy. And I have an account under my real name! If I were a political dissident etc that just feels like an insane idea.
Wait until you hear about the large cloud provider running RHEL5... (I worked at said provider).
"This guy": https://en.wikipedia.org/wiki/Peiter_Zatko