10 ms·
If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called securit
by Simon321 7y ago
If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers. Information security can be great though if you find someone that really cares.
- raducu 7y agoI work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the production environment. I'm tempted to just credit myself 1 monetary unit in production and just show them the statement.
- winrid 7y agoSometimes it matters who finds the issue more than what it is....
- trymas 7y ago> I'm tempted to just credit myself 1 monetary unit in production and just show them the statement. I would be tempted too, though I could bet that this will be a termination of an employment, instead of the problem being fixed. I would like to be proven wrong on this speculation..
- neuronic 7y agoNot just that, I would expect criminal charges to follow.
- raducu 7y agoYes, that's what I thought as well.I'll just have to suck it up until the test environments are up again and provide a proof of concept exploit. I'm just impatient because it's a really clever and somewhat complex hack that challenges some multi-threading and transactionability assumptions some people mande and I can't really talk about it(which I'd love to share with my peers).
- deleted 7y ago[deleted]
- unnouinceput 7y agoRaducule, did you did CYA (cover your ass)? E-mail(s) to higher ups responsible in case of a fuck-up that most likely will happen in the future? Do it now if you didn't, or "wave and smile" if you did. Let them burn if you are ignored, no longer your problem.
- kstenerud 7y agoDebit yourself 1 monetary unit, and then say you could just as easily credit money.
- eithed 7y agoNot to downplay the issue in question, but you have to be realistic about prioritazation. An exploit of "if I change variable in URL I can see other people data" trumps "if I make multiple concurrent requests with specific input I can give myself monies". I guess not by much, depending on the complexity involved and the know how required to carry one vs the other. Another thing all together is who reported the issue - sometimes it's more of a PR experience, depending on the company
- beerandt 7y agoNever to yourself. Maybe to a board member. Or all of the board members. But that's a big maybe. And make sure your contract covers your ass, under production system testing / penetration, or something similar.
- raducu 7y agoI could only exploit this for my own account, and there are only money involved, if it was human lives at stake, I would not have worked at anything else until the issue was fixed. The bug that lead to me discovering the security issue was mitigated by another developer, the security issue was also deemed fixed, I am 100% it was not, but there's no way to proove it at the moment, except u production, that's why I said I was tempted to actually do it. Anyway, there's nothing much to gain by me by antagonising another coleague, the management or the bank. It's not worth the ego boost or frustration scratch, worst case scenario, I don't patch the issue in time and the bank looses money and they start taking security more seriously.
- im_with_stupid 7y agoYou'd get much less reprimand if this information was somehow leaked to someone else who then was stupid enough to do it, although to avoid any legal "abetting" you'd have to have some actual documented cya saying "don't mess with this broken feature".
- raducu 7y agoI don't have any ill feelings against the bank or the management, it's just a stupid setup where the local prophet gets ignored, we are swamped with bugs, new business features, new regulatory features, outdated devops, a lot of teams scrambling to catch the monthly release, understaffed qa, non-functional test environments and so on. I can understand every piece of the long string of factors that lead to this ridiculous situation where such a serious security issue is not being addressed; any one in particular is not ridiculous, but they all compound to the ridiculous of the end result. I've fixed another ridiculous security issue in the recent past without making big waves, where only one software architect understood the seriousness of just one option in a maven config file(a whole declarative security module was not being weaved into the bytecode because somone added another module and instead of both being applied, only the most recent one was being applied).
- im_with_stupid 7y agoThat might be true, but hacking without explicit consent is a good way to get fired with potential jail time.
- scirocco 7y agoI've heard from someone selling security products that some companies prefer to pay ransonware to a hacker, instead of investing in building up their defense and paying for security products
- varjag 7y agoThe easiest security investment is to switch your shop from Windows, cutting like 98% of threats out there cold.
- shifto 7y agoAs well as cutting 98% of your workforce as no office employee knows how to work on anything different.
- eitland 7y ago> As well as cutting 98% of your workforce as no office employee knows how to work on anything different. Techies repeating this should take a lot of the blame for why Windows still sell as well as it does. A 50 year old electrician convinced me to start using Ubuntu 13 years ago after someone at his kids elementary school or something had told him. UX wise Linux passed Windows in many areas around the time Ubuntu was introduced. The only reasons now are prefererence, hard dependencies on Windows only software, stubbornness and incomptence. Only the two first ones are good reason in my opinion.
- CathedralBorrow 7y ago> UX wise Linux passed Windows in many areas around the time Ubuntu was introduced. Is this something you decided on your own was a fact? If I disagree, would I be wrong, stubborn and/or incompetent?
- varjag 7y agoProbably under stubbornness. Whatever good things Windows has going, it's not the UI.
- Aeolun 7y agoConversely, in a lot of industries the security department is only there to prevent you from doing everything you need to do, even if the threat and attack surface are both minimal.
- davidgl 7y agoAgreed, too often security people are incentivised to make a massive fuss over tiny issues, and then often don't seem to understand that security is just one of many requirements needing to balanced
- meloentje 7y agoSo much this. In addition, these tiny issues are often purely technical in nature. I still have to meet the first security engineer who is able to identify informations security risks at the business level and view vulnerabilities in their proper context.
- umvi 7y agoSo true! Security people think the end goal of the company is a secure system. No. The end goal of the company is a product that customers want to buy. And it's hard to build said product when security hinders you at every turn.
- deleted 7y ago[deleted]
- badrabbit 7y agoBro (or Sis? :) )! They're not supposed to care about security, you are! Our job in infosec is to show others how insecurity affects what they care about so in order reduce,transfer or eliminate risk to what they care about they allow us to implement good security. The failure is on the infosec side of the equation. It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring about infosec. I mean,they care about promotions,reputation,bottom line,ROI,KPI,etc... That's what they do. You know why the marketeers and buzzword snakeoil salesmen prosper? It is because they communicate not only risk but especially [fake] solutions better! Infosec is full of user and management blaming, expecting peoppe outside of software developers and infosec practitioners to care about infosec. I am not saying I have it figured out but I am fairly certain users and decision makers need to be told solutions within the context of risk that affects them. And if it doesn't affct them they're not supposed to care. I'll give you an example, a network is filled with tls1.0,and ssl1.3, how does that affect some mid sized company's bottom line or reputation? How do they get ROI on the man hours and resources spent to upgrade everythig to TLS1.3 with proper cipher suites and key exchange? and what KPI can they use to measure efficiency of resources? How will you tell them security hygeine takes a very long time to show ROI as do many other security concepts? You don't really have to do all that if you don't want to, plenty of skill demand to where you can progress to more exciting positions.
- wayoutthere 7y agoI did work at a major cable company building customer premises hardware about 5 years back (the only reason I'm sharing this story). They were alerted to a major, easily exploited and REALLY stupid vulnerability in their system that exposed their core management network for the product to customers. They just hired the guy who reported it then fixed the problem 6 months later. The short-term mitigation was to put passwords on all their database servers (they were not there previously). Security was just not a concern until they had a major breach. The security teams had been screaming bloody murder for a while, but could not get the product teams to allocate sprint bandwidth to the massive, coordinated security hardening effort that needed to happen to prevent a potential headline in the New York Times.
- TheOtherHobbes 7y ago
- austincheney 7y agoThat sentiment reminds me of how most people think of accessibility.