3 ms·
I'll play game. > Right. I want the information that I can use, or get my team to use, rather than waiting for some company to distill it for us. I've worked i
by NetStrikeForce 10y ago
I'll play game.
> Right. I want the information that I can use, or get my team to use, rather than waiting for some company to distill it for us. I've worked in some of those companies so I don't have any illusions about them.
You have it now, hope you're happy. How are you using it?
> Not having a user-base of windows machines, and thus not having read about it, I couldn't say. I'd probably be able to just turn on the draconian policies that users would rebel against normally.
> But the point isn't an interview question about what I'd do, if alone at the helm, but what the entire internet could come up with. I'd wait a bit and copy that. If a security company came up with it, then good for them. But if not, good for us anyways.
Because there's nothing you can do!!! you're sold!!! there are companies with thousands of Windows seats. How can you just go and say "not having Windows users"? That shows very poor judgement and a seriously worrying detachment from reality.
It also shows me you actually don't really give a shit about security and know nothing about the challenges in the real world. This disclosure and the kind of attitude shown on this thread are the two main reasons why the InfoSec industry stinks so hard.
> Only because they got nailed so many times.
Yes. Does it matter why though? When they were getting nailed I was probably shitting my diapers. Should I be judged now for what I was doing those years?
> Security isn't their market discriminator so they'd rather ignore the issue and hope it blows over.
Are you sure? I don't think you really know that Microsoft is these days a huge and (for many big companies) reliable security vendor. Compliance, tooling, innovation, products... They've got their hands on everything. They even help shutting down botnets.
> Why can't Microsoft hurry this critical patch even if it means breaking its routine a little?
Because it was not as critical until Google disclosed it. I'm baffled you can't see this.
> I imagine Google didn't give much weight to their arguments, probably because of past experience.
I think Google was just being strict about their policies. I don't think they've got prejudices. However, it is proven by your comments that you do have those prejudices and you're basing your opinion on them.
Objectively we're not safer than before the disclosure.
> Knowing there's a landmine in my yard makes me safer even if it means I simply don't go in the lawn.
This shows poor understanding of the issue. This is not something you stumble upon while doing your daily menial tasks.
If you'd like a silly comparison, this is like Google releasing blueprints to create super cheap surface to surface missiles because they were being used by a nation against another. Now they have weaponized any script kiddie out there.
> And you can almost always figure out a mitigation strategy. At that, if there's a super-bug that's so bad no mitigation strategy can be devised, I'd rather know to turn my computers off until patch-day.
Oh really? How? What's your mitigation strategy? What a sysadmin can do to mitigate this? If your answer is don't use Windows, which could be a good long term plan, you're again out of touch with reality.
Remember, reality is not Silicon Valley.
> Ignore nothing. Acknowledged and refuted.
You're going to have to point me where you've refuted that we're not safer after weaponizing everyone.
> But the point isn't an interview question about what I'd do, if alone at the helm, but what the entire internet could come up with. I'd wait a bit and copy that. If a security company came up with it, then good for them. But if not, good for us anyways.
Holy shit. I hope I'm not using any of your products. This is not how you do security.
I thought I was discussing with someone that took security seriously and that I could learn a thing or two (I can't call myself an expert, maybe a hobbyist); it does seem though you're in this conversation just because you like to stick it to Microsoft (or to the big guys, or whatever) and can't be objective about it.
If you'd like to continue this conversation I'd like to ask you to tell me how can we be safer after the disclosure. How can I help my friends running small and medium businesses to protect themselves against the exploitation of this bug?
- EdHominem 10y ago> You have it now, hope you're happy. In general, yes very. Thanks. > How are you using it? I'm not, I don't have Windows boxes. Did you miss that? > Because there's nothing you can do!!! you're sold!!! there are companies with thousands of Windows seats. How can you just go and say "not having Windows users"? That shows very poor judgement and a seriously worrying detachment from reality. Nope, I just double-checked my entire inventory and there aren't any Windows computers. That's an example of how by knowing more about it, I can make better decisions. For now, for this bug, for me, 'nothing' is an acceptable response. > It also shows me you actually don't really give a shit about security and know nothing about the challenges in the real world. Exactly the opposite. You're sounding like you've never considered mitigations. You're parroting a corporate message that has caused more vulnerabilities over the years than null-terminated strings. > Are you sure? I don't think you really know that Microsoft is these days a huge and (for many big companies) reliable security vendor. Compliance, tooling, innovation, products... They've got their hands on everything. They even help shutting down botnets. Shutting down botnets is admirable. But it's not platform security. Microsoft is still too focused on extreme user convenience, etc, to make the hard choices. Their cloud offerings still have problems with filenames their OS accepts, and when it dies it just refuses to copy some of the files. It's not a security bug but it shows a lack of attention to details and improper sanitization. It's hard to imagine them actually properly executing on a robust and secure solution. I wouldn't trust a builder living in a crooked house... > I don't think [Google has] got prejudices. However, it is proven by your comments that you do have those prejudices and you're basing your opinion on them. Yes, I also remember their total lack of concern in the 90s which does color my view but the issue is that I still see those behaviors from them. When they release mitigations in days, not patches in months, I'll revise that opinion. > How? What's your mitigation strategy? What a sysadmin can do to mitigate this? If your answer is don't use Windows, which could be a good long term plan, you're again out of touch with reality. You seem not to read the posts you respond to. I have no idea because I haven't even read two lines about this bug. It doesn't affect me or my charges and so I'll focus my energy on things that do. In the hypothetical where it was in software my users used, I would probably just block that software for everyone. Rarely are even mission-critical apps actually so, in practice. Failing that I'd block that type of media, etc. Or restrict it to a small subset of users who I could trust, and I'd revoke a bunch of other privileges for them temporarily to avoid the attacker gaining anything of value. For instance, Disable the PDF reader, block all PDF attachments, and forward all email with an attachment to a user with a reduced-access machine to sanitize. This could be done in minutes which is why I care about finding out about things right away. I can slam the door even without fixing the problem, then analyze it at leisure. > If you'd like a silly comparison, this is like Google releasing blueprints to create super cheap surface to surface missiles because they were being used by a nation against another. Now they have weaponized any script kiddie out there. If Google found the blueprints then anyone else could. And yes, we'd want to start analyzing them for weaknesses before they were flying towards us. > Holy shit. I hope I'm not using any of your products. This is not how you do security. Haha, but you're totally wrong. Security (in any domain) is about doing what you can and understanding the limits of it, not about stupid ivory-tower perfection. My users would be safer in minutes, your users would be ignorantly vulnerable for months. > I thought I was discussing with someone that took security seriously and that I could learn a thing or two (I can't call myself an expert, maybe a hobbyist); it does seem though you're in this conversation just because you like to stick it to Microsoft (or to the big guys, or whatever) and can't be objective about it. MS isn't even on my radar and I normally say this sort of thing about other vendors. I don't care to wait on their patch cycle, or wait for them to make a tidy patch, I want as much of a mitigation as possible, as soon as possible. Some companies have bitten the bullet and pushed updates to disable whole areas of broken functionality and taken the PR hit, others would rather wait and hope nobody notices. > If you'd like to continue this conversation I'd like to ask you to tell me how can we be safer after the disclosure. Trivially, because without the disclosure nothing you do with make you safer. With the disclosure you've got a range of options. > How can I help my friends running small and medium businesses to protect themselves against the exploitation of [any] bug? Even knowing when to just unplug the network and wait is still a huge step up over being ignorantly plundered. When you've done everything you can, stop and assess. Maybe there'll be a more fine-grained mitigation (blocking a smaller subset of incoming traffic for instance), or an actual solution by then.