5 ms·
Troy's stance makes me uneasy. I'm sure publicly shaming these companies is effective, but where does the line get drawn? In my experience the infosec communi
by eric_b 8y ago
Troy's stance makes me uneasy. I'm sure publicly shaming these companies is effective, but where does the line get drawn? In my experience the infosec community strongly believes security is the most important thing, full stop. So they feel no qualms about using every trick in the book to get their way.
But two things about this trouble me. The first is, have we decided that the ends always justify the means? It seems in other domains public shaming is unacceptable. Troy himself despises Donald Trump, but one of the things most heinous about 45 is his use of Twitter to publicly ridicule and shame companies and individuals. And now Troy is engaging in exactly the same behavior. But it's "OK" this time? What is different?
The second thing that troubles me is security "best practices" today may not be best practices tomorrow. Some of his example companies are using practices that were "best" 10 years ago. What happens in another 10 years when Troy's current advice is outdated? More pitchforks?
The security treadmill is hard for even the most modern tech companies to stay on. I think the infosec community could go a long way to helping itself by making easier to use tools, and writing canonical guides for common scenarios. Setting up HTTPS to get an "A" from SSLLabs is non-trivial. Securing SSH with perfect forward secrecy is near impossible for a mortal. There's no reason it has to be this complicated.
Edit: To the people who couldn't get past the first sentence of my last paragraph. I'm not saying that because the security treadmill is hard the companies get a pass. I'm saying the infosec community has a responsibility to make it easier to stay on it. If the barrier to securing something appropriately was so low you could trip over it, we wouldn't have this many problems.
- vorpalhex 8y agoYou're right, we should be totally OK with a company that makes profit off of us using 10 year old outdated security techniques - we wouldn't want to be rude. Imagine you went to an amusement park and saw the rides were being operated unsafely. No seatbelts, no safety protocols, no even making sure passengers were seated first. Do you stay quiet because after all, the teenager running the ride probably didn't invent the safety protocol? Sure, someone might get beheaded, but you don't want to be rude. > The security treadmill is hard for even the most modern tech companies to stay on That is nonsense. If you have the resources to track me across the web, hold vast amounts of my private information and profit off of me, you'd best damn invest in basic security practices like SSL and encryption at rest. If you don't have the in-team expertise, bring in a consultant. These aren't Mom & Pop ice cream shops, these are major international companies and banks - stop cheaping out on security to save a few pennies.
- eric_b 8y agoIt's this kind of morally righteous fury that bugs me. You compare web security to unsafe carnival rides? Please. Equifax had one of the worst breaches imaginable. So did Target. Far as I know, no one died. You know, I don't think anyone even got injured. Did some people have to call their bank and dispute charges? Maybe. Not really a life or death situation was it? I don't think Tesco or Betfair are really life or death either? Sure they should have better security, but is it worth becoming an angry mob about it?
- joepie91_ 8y agoYes, people do actually die from compromises, you just don't hear about it. For you, somebody snatching your CC might mean a hassle due to having to call the bank and dispute the charges. For somebody with little money to spend, it can mean the difference between feeding their family for 3 days and not doing so. For you, somebody leaking your private messages on a social network might mean some inconvenient messages that have to be explained to a friend. For somebody else, it can mean that suddenly their homosexuality is well-known in a country where that carries the death penalty, and gets them executed. Software is infrastructure, plain and simple. You don't maintain it, people die. You don't make it safe, people die. It doesn't matter whether you personally see it causing problems for yourself. This "morally righteous fury", as you put it, is absolutely justified. Developers (and the companies managing them) need to take some goddamn responsibility for the infrastructure they build.
- dsfyu404ed 8y ago>Software is infrastructure, plain and simple. You don't maintain it, people die. You don't make it safe, people die. It doesn't matter whether you personally see it causing problems for yourself. This "morally righteous fury", as you put it, is absolutely justified. Not all software infrastructure is critical infrastructure. It's like the difference between a company that makes bottom dollar kitchen sink sprayers and washing machine hoses that always leaking and mine railings making a town's water supply undrinkable. Both are water problems. Only one is a big enough problem that people not affected by the problem should care about the problem. You have to take both likelihood of harm and severity of harm into account. Just because someone somewhere might get hurt using a bottom dollar washing machine hose to transfer dangerous chemicals doesn't mean we should regulate all things related to water the way we regulate waste disposal near rivers and wetlands.
- tomglynch 8y ago> What happens in another 10 years when Troy's current advice is outdated? More pitchforks? YES! All companies storing data should continually stay up to date with best practice.
- zentiggr 8y ago> The second thing that troubles me is security "best practices" today may not be best practices tomorrow. Some of his example companies are using practices that were "best" 10 years ago. What happens in another 10 years when Troy's current advice is outdated? More pitchforks? Absolutely. To expand on your comment, some of his example companies were using practices that were never secure to begin with. What happens in 10 years when they still aren't being secure at all and more information is in the wild because no one held them accountable? It's best practice for every data-holder to adjust their defenses when any security situation changes, ever, not just Troy's advice. Anything less is just letting laziness rule. (Bring Trump's tweets into this is a total non-sequitur. His 'shaming' has nothing to do with the real world, only his moment to moment delusions.)
- joepie91_ 8y ago> The security treadmill is hard for even the most modern tech companies to stay on. It's not hard. It just requires you to give a damn and actually treat it as an important aspect of your process, rather than as an afterthought. And that's where most companies go wrong. > I think the infosec community could go a long way to helping itself by making easier to use tools, and writing canonical guides for common scenarios. That I can agree with, and behind the scenes, I've been arguing with infosec people about this for years now. But it's not an excuse not to get your security in order. If anything, that should be driving more investment from companies into security, to collectively produce more usable mechanisms and documentation... but that doesn't happen.
- Nasrudith 8y agoThe thing about Trump isn't the shaming - sparing the very many appropriate snarks for him. The trouble there is the position of authority and implied threat of him and his following. There is a fundamental difference between for instance "Apple stores their password data reversibly hashed in the clear in 2017!" and "Apple won't create backdoored encryption/create jobs in the heartland instead of in China!" One is promoting security by calling attention to an objectively bad security practice to store whenever not necessary (passing to the larger store of the hashed one). If people disagree with it no harm done. People will just roll their eyes if there is no technical merit like if it was that the password allowed o,O, and 0 or emojis in passwords. The other is an attempt to cudgel and bully for personal gain. Regardless of merit it is an attempt to do harm. Even if he is right in the circumstance it is an inappropriate use of the office. Since if there is actual wrongdoing involved actual action should be taken by departments. Perdue apparently has a food poisoning scandal for instance? Form a team to investigate the issue and call on justice department if it was illegal or congress if it was technically legal or should have been uncovered or enforced way earlier. Really passwords are a bad security practice to be avoided in my opinion - high grade keys are the way to go. We tried phone and email 2FA and it was inconvenience and another attack vector and the differentiation requires enough volume that a password manager is needed anyway to track everything they may as well use key reserves. We have been trying to avoid it but it is inevitable and right now it is shameful that an empty Amazon EC2 instance is more secure than my bank account.
- noxToken 8y ago> The first is, have we decided that the ends always justify the means? It seems in other domains public shaming is unacceptable. Troy himself despises Donald Trump, but one of the things most heinous about 45 is his use of Twitter to publicly ridicule and shame companies and individuals. And now Troy is engaging in exactly the same behavior. But it's "OK" this time? What is different? Intent has a lot to do with it, but to me, I see one as part of business. As another comment said, some of these companies carry enough information to ruin our lives. It makes sense to hold their feet to the fire in a public forum when they put security on the back burner. >The second thing that troubles me is security "best practices" today may not be best practices tomorrow. Some of his example companies are using practices that were "best" 10 years ago. What happens in another 10 years when Troy's current advice is outdated? More pitchforks? Security is notoriously hard, and anyone who has ever tried to get into the space understand that. But just because it's hard doesn't mean that you get a pass. It is the duty of the business in question to protect customer data. I believe that it is reasonable to expect a company that has my account and personal information to do everything that it can to protect that data. You said elsewhere that if a breach occurs, a customer only has to dispute a few charges with their bank. You're right. It is much easier for a customer to dispute fraudulent charges. But why do I need to spend my time filling out forms and cooperating with a minor investigation because a business (through negligence or otherwise) lost something that I trusted them with?
- nulbyte 8y ago> Troy's stance makes me uneasy. I'm sure publicly shaming these companies is effective, but where does the line get drawn? Troy's use of the word "shaming" makes me uneasy, because that's not what he is doing. To shame is to dishonor or make ashamed. He isn't dishonoring anyone by having a conversation with them in a public forum. The companies and their employees are dishonoring themselves when they fail to address complaints and continue to speak out of ignorance. There is a marked difference between Troy and 45: Troy is speaking directly to these companies. That the conversation occurs in a public forum is of no consequence; the companies willingly entered the forum for that very reason, and there is nothing private about the conversation to be had. On the other hand, 45 does not shame companies by engaging them directly; he shames them by denouncing them to the public. He has no interest in having a conversation, and so never speaks to them, only about them. This allows him to conveniently sidestep any attempts to refute him, since there was never a debate in the first place.
- BeetleB 8y agoAt what level do we call shaming a bad thing? When I have a bad experience at a business, I post a negative review on Yelp - sometimes with pictures to show how bad it is. What Troy is doing isn't fundamentally different. >The security treadmill is hard for even the most modern tech companies to stay on. I think the infosec community could go a long way to helping itself by making easier to use tools, and writing canonical guides for common scenarios. Many of the scenarios he points out are easy to fix and well documented (e.g. not using HTTPS, not storing passwords in plaintext). Although banks are better now, about 7-8 years ago, I often would say that a teenager creating a web site following the Django tutorial would create a more secure site than many financial institutions out there (you know, the kind that limited passwords to 8 characters, or only allowed numbers, and didn't salt their passwords). If a teenager can find and follow docs to make secure sites, then I don't think it is unreasonable to expect better from people who are paid to do it. And it is reasonable to complain publicly when they don't. Some of these institutions have people's life savings. If you walked into a bank and saw that they kept all your money behind a glass door with a single pickable lock, and that they don't request your ID when you make a withdrawal, would you complain about someone publicly shaming them?
- PKop 8y agoI think you should re-examine your premise / first principles. Why should we automatically view shaming in and of itself bad? How about instead of calling it shaming, simply label it "holding companies accountable"? Why should "a painful feeling of humiliation or distress caused by the consciousness of wrong or foolish behavior" be something people are prevented from ever feeling? Is it not sometimes merited? Bad feelings, pain, suffering... if these should be avoided at all cost, what about the people whose private information can be stolen and is then put at risk by bad practices... some which are clung to even in the face of overwhelming evidence presented? In other words, someone might have to suffer to some degree, if mistakes are acknowledged or if they are not, It's just a matter of whom... should it not be the companies and, to a much lesser extent, (causing some slight embarrassment to) those representing the company and arguing with people providing helpful advice, instead of innocent customers paying a business to secure their information, wealth, livelihoods etc? Or avoid all shaming, consequences be damned?
- Bhilai 8y ago> Edit: To the people who couldn't get past the first sentence of my last paragraph. I'm not saying that because the security treadmill is hard the companies get a pass. I'm saying the infosec community has a responsibility to make it easier to stay on it. If the barrier to securing something appropriately was so low you could trip over it, we wouldn't have this many problems. Security should be everyone's responsibility and working with InfoSec to make your treadmill easier is your responsibility too.
- user5994461 8y ago>>> The security treadmill is hard for even the most modern tech companies to stay on. I think the infosec community could go a long way to helping itself by making easier to use tools, and writing canonical guides for common scenarios. Setting up HTTPS to get an "A" from SSLLabs is non-trivial. Securing SSH with perfect forward secrecy is near impossible for a mortal. There's no reason it has to be this complicated. Agreed on this. Security is too hard to do right and too hard to check. There are no 2 guides or 2 people that agree on the same recommendation. SSL labs is a perfect example where the top rating is not realistic to obtain.
- __david__ 8y agoAre you kidding about ssllabs? Every site I host gets an "A" rating, with practically zero effort. What are you running where you can't manage that?
- Postremus 8y agoYep. I set up a few traefik instances a while ago with the integrated Lets Encrypt support. All of them have at least an A on ssllabs. All of this, without actually configuring any of the ssl /tls settings myself.
- user5994461 8y agoI might be confusing SSL labs with another verification tool that always give B and C.
- manigandham 8y agoA lot of the posted examples include basic copy/paste blocking and password rules. The barrier to better security in these reports is so low as to be non-existent. The better question is why these companies can't even do that, let alone aim higher when they are at the size they are in a world where everything is digital.