3 ms·
> you could bypass this if you had admin rights but it would leave a trail A move I've seen being put in place at several locations, is removing local admin ri
by mseebach 8y ago
> you could bypass this if you had admin rights but it would leave a trail
A move I've seen being put in place at several locations, is removing local admin rights from all users. Those with advanced needs, like developers, gets a VM which is limited to a specific VLAN, with no access to the production environments.
The principle is sound, implementation is ... difficult, to say the least.
- jacquesm 8y agoAnd if you're willing to run a lot of screencaps or re-type the stuff you see on another computer you can still get the data out. Before modems were common in the hands of unwashed masses my friend and I would transfer files on the phone by spelling out blocks in hex. Slow but with a checksum every 16 bytes it was good enough to get some work done. If the data is high value enough it would probably be worth it.
- mseebach 8y agoAirgapped exfil is a whole research field. Priority one is making accidental leaks or infections all but impossible. Priority two is making large scale intentional leaks as slow and difficult as possible. As long as there are human eyes on the data, some level of leaking is possible.
- dogma1138 8y agoAny host based DLP will monitor and block screen caps you also need to get them out some how. Printing will also be heavily restricted and monitored. Sure no DLP solution would beat pen and paper but that’s not a good way to exfiltrate data these days and a security guard checking people leaving a restricted area would be a good enough way to plug any leaks.
- ekovarski 8y agoAll of these technologies are great to prevent employees from casually stealing data but as history has proven, usually while the front is well guarded, the back end many times has quite a few holes for hackers to exploit. It's like they say, the most secure computer is the one not connected to the network.
- dogma1138 8y agoPeople like to dramatize things way too much, most "breaches" are accidental there are 1000's of companies that manage to keep their data secure on a daily basis despite targeted attacks. With a few exceptions it's much easier to either poach your competitors or simply buy them outright which is why "corporate espionage" is mainly employed by nation states these days that need to catch up. It's also important to note that stealing a design isn't that useful these days since you are too far gone what would be more important especially in the semi industry is to know the characteristics of a specific design or process in order to be able to preemptively position your offerings to compete without giving up any unnecessary ground.
- MrMorden 8y agoA malicious insider can always memorize the information to be exfiltrated. (See e.g. Ana Montes.)
- jon-wood 8y agoI’ve not seen this approach, but it’s definitely an interesting one. What do you do about the people who actually need production access?
- dogma1138 8y agoOrganizations that take security seriously use PAWs for production access. https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/privileged-access-workstations https://docs.microsoft.com/en-us/windows-server/identity/sec... Example of an actual implementation in the wild: https://uit.stanford.edu/service/paw https://uit.stanford.edu/service/paw
- mseebach 8y agoWell, bias towards "infrastructure as code" and minimise the need to actually access the servers. Read logs through Splunk, configure through version controlled Puppet (or similar tools). The only machines that can actually SSH into prod at least have screen-session-recording software, perhaps are kept in a separate room, with a policy of two staff present at all times. The general idea is that the closer you actually get to being able to bypass the checks and controls, the more attention you bring to yourself and your errand. Yes, it can't be Git and Puppet all the way down, at some point someone will necessarily have access to do something as root on the server that hosts the Git repo that Puppet runs from. But instead of that being every dev on every laptop anywhere in the world, you can make sure it's a very small group of people, from a small number of workstations. This is difficult and requires a substantial and very competent team to implement correctly.
- dogma1138 8y agoOh yeah you don’t have admin rights or they are restricted via UAC and an agent that allows you to promote only certain apps and then restricts inheritance of permissions from these apps. In a restricted environment you will have several monitoring agents that track and enforce system integrity.