Nvidia Corporate Network Breached
forbes.com
forbes.com
I think that endpoint security is what needs to be enhanced. Looking at what's been disclosed about malware recently (APTs: https://en.wikipedia.org/wiki/Advanced_persistent_threat), we need to focus on a few things:
1) Isolating components: Components, and processes themselves should be isolated from one another, and the operating system. A web server should be able to run malicious code without fear of it easily getting root access. We have tools to make this possible today, like Apparmor, and SELinux. The fact that distributing Apparmor, or SELinux profiles with applications today isn't normal, makes me sad.
2) Modularization: We should do our best to split the components of a system up into small, well-understood pieces. Rather than trying to combine multiple components into one monolithic process, breaking up components into their individual components. I think Cloudflare's work around Keyless SSL was great, but we've had HSMs for years -- that could have easily avoided such disasters as Heartbleed.
3) Decent abstractions: With the advent of further distributed systems, and modularization, we're going to see more and more interfaces between systems crop up. Largely, CISOs are limited to what the systems, and networking team can do. These limits typically manifested themselves at layer 4 on the network side of the house, and limited layer 7 capabilities like URL filtering, and file system ACLs. I think we need better stories around resource access and authorization. For years, we've had systems like Kerberos which would have been a great building block, but yet goes unused. I hope we see X509, and GPG become more ubiquitous for access management, and encryption.
Why does this only apply in the user space? The first thing I thought if when I read this sentence was systemd...
OpenBSD (and even FreeBSD), on the other hand...
Is there anything we can do? Or just keep plugging holes as they come up?
For example I no longer expect my email address not to leak - it doesn't matter who you send it to (which company or person) eventually it will leak. There are only a few rare exceptions, which is the opposite of the kind of world you want, but it's the reality.
For email, instead of concealing the address we focus on filtering the spam.
Is there something that can be done for passwords? Personal information? Other things?
Also, after these hacks I would hope most companies will be considering adopting end-to-end email and chat encryption policies ASAP, to protect sensitive information (such as the dealings between Sony and MPAA) from getting out in such a leak - even if that means the top execs not having access to everyone's emails and chats anymore. Right now most companies prefer to spy on their employees, which makes them highly vulnerable to this type of leak in case of a hack. It also proves the point that surveillance is a bad "cybersecurity" policy (NSA and most other "security" agencies believe it's the solution to hacking, somehow). They might want to reconsider that and encrypt everything end-to-end.
They also need to compartmentalize a lot more. You can't have a "network of 50,000 computers" in a company, like I think Sony had.
I also believe it's already quite common for large corporations to have employees access the Internet only through a VM along with solid whitelisting policies (although I'm pretty sure Sony didn't do that and there are probably many more like them).
So yeah, I think the main point would be to keep security as close to an individual employee as possible, as opposed to having everything accessed company-wide, with virtually no protections within the network itself, just outside of it.
I think we're now finding that doesn't scale very well as it only takes one hole and it's broken. It's better to treat the network as some level of 'untrusted' and protect your servers/computers better as individual units accordingly.
I think its definatly time we started treating our internal networks as unsafe. Not as easier for the end user, but if done correctly a lot safer for everyone.
A little depressing, but its what would have had to happen eventually.
There are situations where the former can make sense, such as a siege, where e.g. a penetration is quickly obvious and you can use your interior lines of communications to rush reserves to the action.
The key, of course, is the "quickly obvious". Prior to the stats of the art allowing that (which sounds difficult and painful in principle), defense in depth is obviously the way to go. But you've got to achive it in some why where e.g. compromise of "bob@nvidia.com" + password doesn't quickly get you past any defense, or any that's relevant to bob.
2-factor
Network compartmentalization. For example, in the Sony Pictures hack, why does HR's network need to be accessible from the same internal network that everyone else is on?
why does HR's network need to be accessible from the same internal network that everyone else is on?
Convenience I guess. Every book I've ever seen on network design and system administration talks about "departmental" servers and segmenting corporate networks at functional borders, but in practice I've never seen it. It's hard enough to get people to use different network shares for different data (e.g. personal, departmental, project related) instead of one global, world-writable share. This occurs at every level, from small businesses to the largest corporate and government networks.On top of that, even if you compartmentalize, there really isn't any technical method to prevent Sally in HR from emailing a list of personal email addresses, phone numbers and addresses to Sam in the Communications department so he can send out Christmas cards to everyone. And, Sally being a non-technical user will probably just "hide" the social security and salary columns in that spreadsheet instead of deleting them and then will blame Bob in IT when that list of salaries ends up on the global network share and eventually printed out and taped to the wall in the hallway.
Specialization is also starting to play more of a role. Various hosting and cloud companies have pitched themselves as experts in security, and large ones like Amazon have never been hacked directly. Companies that specialize in something other than IT (like Sony) can rely on cloud firms' expertise rather than trying to figure it out themselves (and repeating past mistakes in the process).
Software companies also put a higher priority on security than ever before. New software like Google Chrome is setting a high standard for security, and insecure stuff like Adobe Flash is shunned.
It's increasingly obvious that even the best programmers in the world can't always write secure C software, but new memory-managed languages are playing a greater role. Google's Go is quickly being adopted to write software that runs anywhere, nearly as fast as C, but with proper memory management.
I could provide more examples, but my point is that we're doing more than playing whack-a-mole with the exploit of the day. We've invented (and widely deployed) new ideas that make things permanently better, and there are more such ideas in the pipeline.
Call me an optimist, but I think we will see massive improvements over the next few decades.
Scary.
It's pretty easy to keep your password manager secure against the threats that most people actually face, and this removes the worst elements: password reuse and low-entropy passwords.
1Password is probably my favorite app/suite of apps ever. And I willingly shelled out for them. But most people balk at paying $.99 to remove advertising in mobile games, so I don't see this catching on.
(Plus sync, plus backups, plus...)
It can be, but it doesn't have to be. There's perfectly good password managers[0] which are free and open source. The problem in this case is getting people who aren't technically literate to use them.
Password Managers are not the solution to the problem, they are a bandaid.
Have your master pw compromised: have all passwords compromised
You're taking multiple failure points (which certainly has a higher chance of a failure than a single failure point) and replacing it with a single point, with lower chance of failure BUT with bigger consequences
The following is a password manager developed by Bruce Schneier:
Then don't.
I rely on similar passwords for non-important services, but important ones have an unique password/2FA
You're still vulnerable some attacks like keyloggers but I think your description downplays many of the benefits (mitm or a poorly secured remote database wouldn't expose your master password). There are other great features password managers are starting to add; letting you know how long ago you changed your password, informing you if you haven't changed a password after a site had been compromised, changing your password for you (each site is different and updating passwords is very time consuming).
Better to have 5 passwords on a post-it on your monitor, safely within the guarded walls of your HQ office, than 1 password shared between your Playstation game account and your gmail.
Nvidia, and in fact all of us, should be teaching folks to not reuses passwords and also to store them securely. It's almost 2015, and password managers are available for pretty much any platform, they're secure against the threats commonly faced by most people, and they're easy to use.
Secondly, you are basically ignoring physical security when you discuss post-it's as a means to secure a password. What happens when the "delivery man" or "pizza girl" shows up to do deliver their package and steal all your passwords?
While most work places get physical security dead wrong, these are simple first steps.
It is important to have a security policy that fits your threat level, and the engagement of your employees. You can expect from an upper management person that he has a fast lock screen and an encrypted disk and a tight firewall on his laptop. In those conditions it makes absolute sense to recommend a password manager, preferably with a hardware security key. That's a fully decked-out APT resistant upper management guy or sysadmin. This is also the sort of target that would be the subject of a 'pizza girl' covert operative, so yes having passwords on post-its would be horrible.
But that's not the type most likely got Nvidia. The other 50.000 employees is what is getting our big corporations in trouble. A poorly secured Windows laptop with out of date software, and no control on third party applications, that's a terrible place for a password manager. How easy is it to write a tool that extracts passwords from the manager if your tool got sysadmin rights by posing as a Java plugin installer, or a cracked video game?
The sort of hacker that targets those employees is not necessarily an APT, more likely as mentioned before the passwords of these employees were gotten from big fly-by password leaks like the PSN hack. This sort of hacker wouldn't even look at your physical security, they don't care about your physical security, they're likely across an ocean from you, and likely wouldn't even drive by your office if it was in the same town as they are.
The game is seggregating your security levels, and minimizing attack surface where possible. Standardizing a password manager across 50.000 low-tech employees sounds like a bad idea to me.