3 ms·
We can draw some interesting parallels to information security from this. Both thieves snuck in through unused passageways, just like some interesting attacks u
by phlo 10y ago
We can draw some interesting parallels to information security from this. Both thieves snuck in through unused passageways, just like some interesting attacks use legacy functionality that is still carried in software: Heartbleed exploited a flaw in DTLS heartbeat code that practically no-one was using; SMACK actually formalised the concept of using unforeseen code paths to navigate TLS state machines.
Which leads to the question: What to do with unused pathways through buildings or software? In any case, we probably have to account for them in security considerations. Beyond that, what's the best way to go about it? Documentation (publish plans with secret passageways included / open source), instrumentation (tell the cramming student to check the dumbwaiters / IDS/IPS), remediation (fill them in with concrete / clean up the code base)?