NSA publishes ten most common misconfigurations in networks
cisa.gov
cisa.gov
Jump/Bastion servers everywhere, with the ability to "get work done" (via scp, and restricted SSH options) severely limited. That with VLANs lets' the PHB and 'Cyber insurance' people checkbox that "yes we are secure".
Everybody can `sudo su` with no restrictions and no additional password/2FA. Boxes on internal network can't access the internet (outgoing comms blocked). While this is handy during general usage, during setup for a 'TESTING' environment that might require 100 ruby/gems and 3rd party files to be installed, it's a royal pain in the ass.
I could easily breakout with SSH tunnels, but I'm trying to respect the client wishes. It makes the job 1000x unnecessarily difficult.
Penny wise and pound foolish.
So they give lip service.
OH, and all passwords are a variation on 123_$CORPNAME, $CORPNAME123, and abc$CORPNAME123.
More patience than me haha, I remember the last project like that I was on with a small group of contractors - we spent the half of the first few weeks working around all these theatrical limits. We had an HTTP Proxy that could run over RDP. Fortunately nobody was really looking (or caring).
The fact it’s 2023 and software still doesn’t ship with secure defaults blows my mind.
OpenBSD has been pushing secure defaults for a long, long time.
"Properly trained, staffed, and funded network security teams can implement the known mitigations for these weaknesses."
You need someone who actually understands networking tech at a deep level to accomplish anything beyond what expensive tooling/devices will offer you. Otherwise, you're always going to be limited by whatever vendor you're using and the capabilities they build in, assuming you're using the solutions to their full capability.
A lot of companies struggle to have property trained, staff and funded IT, let alone their security team.
The more home servers and services I have, the harder it is to keep everything up to date…
I wonder if ubiquity does this better.
This burned me so bad that I have to second guess updating software now, which creates a moral hazard. We need to figure out how to price and actually extract the externality cost that these errors create. Otherwise, we are in a perpetual gradual slide.
> We need to figure out how to price
What is MSRP on extra set of hardware that is physically disconnected, as failback.
> and actually extract the externality cost
Roll it into overhead.
Of course, now you have to be really careful to guard access to your Ansible setup...
Access - don't share your private keys!
Every one of the mitigations relies on failable-by-design human beings to do a perfect job at closing every potential security hole. Often using obscure wizard level knowledge about the system they're working with.
Does anybody trust that ACLs will always be perfectly maintained? That credentials will always be kept up to date? that patch management will always be timely and comperhensive? You can try as hard as you want - or how much of a budget you have - but in real life you'll never patch all the potential holes. At any given time we - the royal organizational we - don't even know all the potential holes.
I think we need to treat network security like nuclear weapons. Networks need to be fail-safe. The reason nuclear weapons have many fail-safe features are because their history is rife with failures tracable to human error.
What does fail-safe even mean in network security? I have no idea but I think the question is worth asking. How do we remove humans out of the security loop? How do we make networks smarter and self securing and fail-safe?
In my (slightly dystopian) imagination the network needs to be some AI overlord model which controls it all and asks users in plain language what they want to do and decides what to allow based on the user's moral character. Then it uses its omniscient eye to surveil everything and shut down any transgressive actions.
Because clearly human beings are not up to this task.
But seriously is there any research on autonomous and self securing networks out there?
Found this a bit odd though:
> The presence of easily crackable passwords on a network generally stems from a lack of password length (i.e., shorter than 15 characters) and randomness (i.e., is not unique or can be guessed).
Randomness I get, but:
log2(72^15)~92
(alphanumeric including some symbols) and even only all lowercase:
log2(26^15)~70
I still think searching a 2^70 space is pretty hard? (Making big assumptions: no rainbow tables (proper salt), no daft ntlm 15=8+7, actually random characters).
They'll never guess it!
If you're literally choosing "correct-horse-battery-staple", yeah, it's just a slightly harder dictionary attack, but that's not the suggestion being made, and that's not different than choosing hunter2 as a password.
I guarantee 5 words will be easier to remember than the 14 random characters required to get equal entropy from a random password from a dictionary of 58 characters. https://www.wolframalpha.com/input?i=solve+for+x+log2%28%285...
The problem with really large lists, is you get some very rare and really long words.
The list was good but this last one reads more like end-point security.