2 ms·
And all this while everyone is paying billions for complex info-sec software that does a lot less then it says on the tin. It's similar to the epidemic problem
by Stranger43 9y ago
And all this while everyone is paying billions for complex info-sec software that does a lot less then it says on the tin. It's similar to the epidemic problem with non-verified/signed SSH keys where everyone just clicks Ok to any host-key presented. Though a bit more subtle, and something that should have been avoidable with a proper designed protocol.
It's the kind of trivial little thing that gets ignored(along with boring old maintenance tasks like patching infrastructure servers ect.) not despite of but because of all the attention given and budget spend on attending conferences on cyber-warfare and never to be correctly installed(let alone monitored) infosec appliances.
Almost every major hack ever blamed on super advanced state sponsored groups turns out to be someone fumbling a routine update (like what happened with equifax and wannacry) or setting a bad password(guccifer 1+2 etc.) And yet the lesson that gets drawn is never, "lets start following proper procedures for maintenance and training" but "lets reduce the maintenance budget some more by spending on infosec conferences and toys."