CISA directs federal agencies to disconnect Ivanti products by Friday midnight
cisa.gov
cisa.gov
> CISA has observed widespread and active exploitation of vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure solutions, hereafter referred to as “affected products.” Successful exploitation of the vulnerabilities in these affected products allows a malicious threat actor to move laterally, perform data exfiltration, and establish persistent system access, resulting in full compromise of target information systems.
This looks like a right shitshow.
Ross Anderson did a big group research "The Changing Cost of Cybercrime" [0]. I forget the number but it came out at several trillion.
After Solarwinds and the UK Horizon Post Office scandal I am wondering, how does cybercrime compare against simple incompetence and hopelessly broken software engineering? How can we measure that to see just how bad things really are?
[0] https://weis2019.econinfosec.org/wp-content/uploads/sites/6/...
There's very little cyber crime that happens by bribing someone. Most of it is just walking past an open door.
> How can we measure that to see just how bad things really are?
hence, cost of incompetence = cost of all cybercrime + n.
Defense is a costly vast landscape compared to attacking. Sure incompetence causes issues and major drives my blood pressure, but the problem doesn’t go away if incompetence goes away.
Yes. But.
There are many defensive tactics that are not free but are cheap.
Keeping system software updated is one
In the Horizon case, and no doubt in many cases to come, the crime is committed by a company against the public. They tried to pass it off as incompetence, and blame "systems" but I expect the public enquiry will lead to criminal proceedings against Fujitsu now.
Big companies may laugh at fines for treating their customers badly, but I hope to see many more ruinously brought to book for their criminal incompetence.
> hence, cost of incompetence = cost of all cybercrime + n.
Where n is at least as large as the other part. Scary!
If competence was the norm the bribes, violence, etc. become the preferred tactics
Someone on Bruce Schniere's site noted that about the Anderson study... that the increase in cyber-crime perfectly tracks the decrease in street crime. As online fraud goes up, robberies go down.
If crime remains a constant then having shitty software security is a safety valve - and fixing computer security means physical crime would rise again.
Interesting hypothesis.
Hacking computers is usually just a means to an end: fraud or theft. Competence is more than just preventing hacks.
But we can do much better
Does it? I never considered that. It seems obvious to me that they aren't the same actual people.
We have more EV cars on the road displacing ICE vehicles, but that doesn't imply that the old cars "transformed" into electric ones.
But "Why would crime become constant?" is very interesting. For that we turn to "criminology" [0,1]. Roughly, there are three "layers", biological, psychological and sociological. All of these are either fixed, or very slow and hard to change.
Indeed the biggest factors in "how much crime there is" are laws and reporting, how visible the crime is. Obviously we could make crime disappear overnight by declaring all behaviours legal. Really, the justice system can only absorb and respond to what the underlying social and economic conditions set.
Most crimes are resource motivated [2]. Violent crime makes headlines, ruins lives, changes votes and is generally undesirable. "Soft" crimes are less visible and have less impact, especially when they are against actors that are so immensely wealthy they do not even care (for example big-tech companies that see huge fines as simply the cost of doing business as usual)
When we have a fixed pool of criminal potential (set by these structural conditions), which would you choose as a new criminal entering the "market"?
And not surprisingly, Pew Research polls showed "violent and property crimes declined by 51% and 54%, respectively, between 1993 and 2018."
Therefore the hypothesis I was curious about was whether Removing the opportunity for cyber crime (via better security) would have the unintended side effect of shifting crime back into physical robbery and theft with its attendant violence.
What do you think?
[0] https://www.britannica.com/science/criminology/Major-concept...
forcing CISA to walk out of the gate with a nuclear-option mitigation is pretty insulting to the corporations/governments that spend millions on this hokum each year to achieve certification or ATO.
then again SolarWinds was effectively crucified before their customers and somehow --unaccountably-- still manages to hold a 4.5 in the gartner ratings and enjoys widespread use still to this day in government and private industry.
it feels like security certification at this level is mostly a performative art.
There's also the benefit of having one set of controls with respect to profiles and extensions.
Is there empirical data on this? I think many in the security industry believe this. I ironically use FF if we can accept personal beliefs since I believe people attack the Chrome sandbox as a badge of honor and I can use containers to isolate state to different personas. That said also anecdata bullshit take on my part.
(2) The fact that people attack Chrome as a badge of honor is a reason to use it, not to avoid it. It's why exploits for Firefox would be cheaper.
(3) I don't think my take is spicy at all? I haven't refreshed it in a few years, but when last I did, I don't think I talked to anybody on either side of browser security who felt that Firefox outclassed Chrome (I got a long, valuable Slack thread from a FF security person that I wish I'd saved that built a claim that FF was approaching parity with Chrome architecturally). I have spicy takes, to be sure, but I think I'm giving you a pretty mainstream take from software security land.
(4) Even if you believed Firefox and Chrome (or Chrome and Safari) were at parity, it makes a great deal of sense to standardize browsers, for the reasons I gave previously. The right way to think of your browser "fleet" is as multiple single points of failure; diversity isn't helping you at all. This is one of those "put all your eggs in one basket and guard it" situations.
I don't have any particular personal reason to love Chrome. I'm a Mac person, so I guess the best outcome for me would be for Safari to be perceived as the best browser. Certainly my batteries would last longer! Every couple of years I talk to people about what the landscape looks like; if I ever get different answers, I'll be sure to update my take.
Did you ever see that written down. Or was it an assumption or rumour?
I ask because I specifically advise against that thinking and debunk the "big company = trustworthy" fallacy. But what I find is that actually there is appropriate low trust of US big-tech amongst the C level, but they are compelled to use Microsoft or whatever for non-technical/non-security reasons.
I think where this goes wrong is when Bob in purchasing confuses can use this approved supplier with must use this supplier and fails to notice said supplier about to be bankrupted in court over a multi-billion security scandal, and goes ahead anyway.
Voila! We just bought a couple million IoT bricks and doorstops that will be in a landfill next week.
We once had a city IT guy block our deployment because we were vulnerable to CVE-whatever - turned out to be a minir vulnerability in the DuckDuckGo browser
The assumption is that shit will or already has hit the fan, and the question is how to reduce your own liabilities as much as possible by throwing what you can on someone else.
Certifications were and are never about practical or literal security.
A sound banker, alas, is not one who foresees danger and avoids it. But one who, when he is ruined, is ruined in a conventional and orthodox way with his fellows, so that no-one can really blame him
https://forums.ivanti.com/s/article/Recovery-Steps-Related-t...
(Linked from TFA)
To be fair, I have no love for Ivanti or Zscaler, but I do understand why companies choose them over some standalone, open source products.
You know what it led to? Us using trash like Ivanti and Solarwinds.
And this kind of Enterprise VPN with bunch of buzzwords products tend to be correlated with exactly this approach of totally ignoring what is inside the perimeter and replacing careful design of that with some other “Enterprise Endpoint Security Non-solution”.
it is where you make administrative changes/adjustments for user access. it sits on your edge and controls what users connect to on the lan. the "ivanti secure access client" is the client-side software used to create a vpn/l4 connection to the corporate network via the appliance (physical or virtual)