5 ms·
Whitelisting allowed outgoing targets isn't absurd at all. It should be standard practice for anyone running a system remotely like Equifax's. It's not the only
by passive 8y ago
Whitelisting allowed outgoing targets isn't absurd at all. It should be standard practice for anyone running a system remotely like Equifax's. It's not the only type of protection, but if your business is basically a lump of data, you want to know exactly who you're communicating with.
- staticassertion 8y agoWhich just means you need to proxy your exfil with a host that has external traffic, such as anyone's laptop, or an edge server. Of course, now this means you just need to detect that sort of proxying, which may be easier. Detecting exfil sucks and is hard.
- passive 8y agoSure, but that's at least an additional piece of security, requiring additional work to bypass. I totally agree that 100% exfil detection is near impossible. But if you were going to try to get close to it, this is one of the world's databases where you really would want to. Their entire model is about collecting a shit ton of information and providing very heavily controlled access to it. Very well paid people should have spent a lot of time examining how to balance the need to pull in data from many sources, while providing only monetized ways to actually retrieve said data. They're like an old-timey pirate captain, who spends most of her time roaming all over the place in the hopes of being able to plunder someone else's treasure, then hiding said treasure in a safe place. Except they really didn't take the hiding the treasure part very seriously. ;)
- staticassertion 8y ago> Sure, but that's at least an additional piece of security, requiring additional work to bypass. I would not consider the ability to proxy traffic much of a new capability for attackers. You can do it trivially with a single SSH command. Even a script kiddy with automated tooling should be able to handle this. Agree that detecting exfil when you have sensitive data is very important though. Just that it takes a lot of work to protect against, and a ton of work to detect.
- ams6110 8y agoSo you're going to whitelist every mortgage broker, car dealer, apartment manager, etc who might need to pull a credit report? Doesn't sound practical.
- passive 8y agoNo, not like that. You have a delivery service for your credit reports, which can make outgoing connections as it pleases, that ensures every credit report it delivers is paid for. You invoke it from inside your network, sending it the credit report along with the transaction number. It looks up that transaction to figure out where it needs to deliver the credit report. It doesn't have access to read any of the raw data. Won't be perfectly secure, but it diminishes a major area of risk. (There are other architectures that will accomplish the same thing, the key is that if a machine can access the user databases, you should be drastically limiting what kind of outgoing connections it can make.)