I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions.
This is rampant. How is this a story?
I know of insurance companies that have help desk employees with domain admin access. And all crippling ransomware attacks take advantage lax permissions.
This is rampant. How is this a story?
Basically we work on keeping everything patched and try not to create any obvious issues. Honestly, I think the best thing we have going for us is obscurity.
1) Like a car mechanic, these people get paid to sell you solutions and they are incentivized to sell you more.
2) Plenty or honest people have biases because of what they do. If you spend all day thinking about security you might be overly concerned about things that are actually not that risky.
This isn’t to say that there aren’t great people working in the field. But it’s daunting from an outsiders perspective.
You don't want your doctor to overlook any problems just because they are rare because your health is really valuable.
Develop an empirical understanding of risk management. While we can't predict the future, through well established techniques and adequate resourcing, professionals can achieve consistent results that are far better than random guessing. Risk management principles drive not just corporate stragegy writ large, but entire industries like banking and insurance.
They have gotten away with so much for so long, they live in their own disconnected reality.
When things break some of them cash out. Others find someone to blame. They don't pay a price at all. And the cycle continue.
In China atleast people are scared of the govt. In the west its a total joke how no one is ever held responsible.
Citizens should respect Government, and Government should fear citizens?
I think we are straying away from both of these at the moment.
[1] - Of course, this isn't the complete picture: China has a penchant for arbitrarily dealing a heavy hand to law-abiding companies/persons.
Walk through the controls list, see where you compare to the controls and sub-controls and then start to establish a path forward.
I think it’s still not clear how you should build a security org, and if you should at all (should security be part of normal workstreams of your devs?)
Btw I wrote about my experience in https://securityhandbook.io/
Some time back, I got a copy of "A Practical Guide for Policy Analysis: The Eightfold Path to More Effective Problem Solving" so that I could properly quote back the use of best practices.
https://en.wikipedia.org/wiki/Best_practice
With most times people are looking at best practices, they skip to the decide step without defining the problem - that's even been done here. Is there a best practice for non-cybersecurity at private business? Well, yes - but first, what is the problem that is trying to be solved? There's no "get this book of everything to do and you're good". On the other hand a "we have customer data that includes PII data, we need to secure the data and prevent casual examination of it in house" is a problem that can be looked at and a best practice can be found.
The best practices involve a survey of looking at other organizations and seeing what they have done - what worked and what didn't.
> Part IV "Smart (Best) Practices" Research - Understanding and Making Use of Whatlook Like Good Ideas from Somewhere Else
> It is only sensible to see what kinds of solutions have been tried in other jurisdictions, agencies, or locales. You want to look for those that appear to have worked pretty well, try to understand exactly how and why they may have worked, and evaluate their applicability to your own situation. IN many circles, this is known as "best practices" research. Simple and commonsensical as this process sounds, it represents many methodological and practical pitfalls. The most important of these is relying on anecdotes and on very limited empirical observations for your ideas. To some extent, these are - one hopes - supplemented by smart theorizing. This method is never perfectly satisfactory, but in the real world the alternative is not usually more empiricism but, rather, no thoughtless theorizing.
> Develop Realistic Expectations
> Semantic Tip First, don't be mislead by the word best in so-called best practice research. Rarely will you have any confidence that some helpful-looking practice is actually the best among all those that address the same problem or opportunity. The extensive and careful research needed to document a claim of best will almost never have been done. Usually, you will be looking for what, more modestly, might be called "good practices."
---
A "here is a list of all the best practices, follow these" is the wrong way to try to use best practices but rather relabeled cargo cult security.
Also, build a risk matrix of security risks the company can face by impact vs likelihood of the risk happening. Get someone senior to sign off on it.
Use the NIST CSF and the risk registry with senior leadership support to guide the work you do.
Itll be easier if you think about security as understanding your risk posture as an org, and that risk is either fixed at your level, carefully escalated to outside your teams for a fix, or labeled and accepted risk. security teams should never be the ones to accept risk, so get a a manager to see and acknowledge in writing whenever it’s decided to just roll with a known vuln you’re Unable to fix without more time/money/tech. Try to fix as many risks as possible at your level as to not build an alarmist rep. Then, that leaves space to escalate into cross-team fixes (and you can point to the NIST CSF and the risk register with a senior leader’s sit side as a baseline reason for why they need to fix it).
Do you have runbooks for your systems? (describes how to operate the system normally.)
What about playbooks? (how to handle errors)
Have you game-day-ed various failures? How long does it take you to restore everything from backup? What order do you bring your systems up?
What level of monitoring do you have on your systems? Can you spot unusual activity? How quickly?
What sorts of firewalls? Say "system X" is compromised. How far could damage spread from there?
Obscurity won't protect you when cybercrime is a business model.
You do have a pretty good idea then. Sadly, this is exactly what it looks like at the moment: because business decisions are made by clueless dummies, there’s no way to sell a proper product; to make money you need to focus on snake oil instead.
Cynically, because it's twitter, and it's trendy amongst a certain subset of the population to bash social media in general and twitter in particular. And I think your point is fair.
(FWIW, I think social media has if not caused, then certainly exacerbated, some major problems at individual, societal, and global levels, but by no means do I think twitter is the biggest contributor. I don't think we'd see the kind of unconstructive political polarisation we're seeing in the US and UK and perhaps, to a lesser extent, within the EU, without it.)
Except like the linkedin "hack" which was just a scrape of peoples profiles, the twitter "hack" was someone running phone numbers through the "upload you contacts and find your friends account" feature.
They are both barely stories, except to remind people that posting stuff publicly is public.
>They are both barely stories, except to remind people that posting stuff publicly is public.
The reoccurring issue is that Twitter and other companies are convincing (and often forcing) you to do something unsafe like linking your phone number, while telling you that your data will be kept private and at the same time opting you in by default, or aggressively marketing, an option that compromises your security.
I'm sure you may be smart enough to know this compromises your anonymity, allows stalkers to find your phone number, etc. but the 99% of users wont.
Linking everything to a phone number is a major dark pattern that benefits the corporations while compromising the user. So rightfully, these malicious and harmful practices should be called out.
Twitter has some 200+ million daily active users and should act like it.
The reason there isnt "leak" from google is because they dont offer the functionality to look up your account by your phone number.
Bro. It's not every day that literally Mudge, who has -no doubt- seen his fair share of shit-shows, whistleblows on an employer.
https://www.ftc.gov/news-events/news/press-releases/2011/03/...
Well, it's on the front page of CNN right now for starters, so that means it's probably significant to a lot of people...
If you have a business, you most likely need to promote it on Twitter, or to at least reserve an account there so that someone else won't impersonate you. You also need to do that on almost all other major social platforms.
If you have a business or personal account on Twitter, your direct messages, the data the system generates about your preferences and interests, your geo-coordinates, and everything you post, including control of how your account works can apparently be accessed by too many people within the company.
It's a pretty big deal for anyone that uses the platform citing all that... Not something that should just be "left to it's own devices" because everyone else is doing the same. All cases of data abuse/misuse should be addressed, but addressing one this big would also be a pretty big deal.
If you don't know how that's a story I don't know how to explain it to you, I can only assure you many people will find it extremely newsworthy.
Maybe I'm a bit jaded by what I've seen, but that doesn't seem too far off from normal American business culture. Deflection and manipulation seem to be par for the course. It's why lobbyist exist. Companies want permission to do/not do the things they're not currently allowed/required to do.
The ones that get caught are normally a few bad actors that whistle blow. The companies where it's ingrained in their culture get away with it. Of course...this is all my own experience :)
Because it's being publicly revealed.
If the lax security you describe at other companies were also revealed, maybe more would be done to fix it.
That said, all these stories are important to the public.
And, oh yeah - there is no "conspiracy".
My claim is that this specific story which is most likely true but in no way surprising gets amplified right now because some specific powerful people wanted it so.
That said, given foreign influence campaigns in the news in the last 6 years, this would’ve been news then too. I’m sure it was news back in 2010 when the FTC ordered it to fix the problems.
Who are these "powerful people"? And why do they care about Twitter so much? Most powerful people aren't even ON Twitter.
Are they enamored with him - for sure, are they in his actual pocket? Doubt it.