4 ms·
The 'real' story is that a motivated attacker will rarely fail. You can take almost any intrusion and write it up in wildly different ways. If HBGary had not
by trotsky 16y ago
The 'real' story is that a motivated attacker will rarely fail.
You can take almost any intrusion and write it up in wildly different ways.
If HBGary had not failed in everything that you listed, odds are you would be listing some other comparable set of failures:
- something somewhere is always unpatched and out of date
- humans always deviate from best practices
- 99.99% of intrusions involve traditional threats, well known vulnerabilities, unpatched systems and human error
I could write up 100 different intrusions done in 100 different ways and almost always make the victim sound incompetent, or like a real life spy novel, or make the defenses sound like fort knox, or make the intruders sound like gods, or make it sound like my product would have prevented them, or draw the conclusion that the security environment is hopeless and out of control.
In the end it doesn't really matter how it happened or what I make it sound like.
Bottom line: Did you get owned [Y/N]
- JoachimSchipper 16y agoThen again, a motivated defender is a very though adversary. Think "web server serves plain files only and is disconnected from the internal network"[1], "secure OSes everywhere"[2], "password quality checker installed"[3], "full-disk encryption for all serious data"[4], "SSH logins only via public key"[5], etc. Yes, this takes (some!) real effort. No, getting 0wned by "please drop the firewall and send me the root password" is not acceptable if you're a security outfit. Really, you can go years without patching if you choose your software properly. (Except browsers - those just suck.) [1] e.g. https://github.com/mojombo/jekyll https://github.com/mojombo/jekyll [2] e.g. http://www.openbsd.org http://www.openbsd.org [3] e.g. http://www.openwall.com/passwdqc/ http://www.openwall.com/passwdqc/ [4] http://www.openbsd.org/faq/faq14.html#RAID http://www.openbsd.org/faq/faq14.html#RAID or the equivalent for other OSes [5] All over the internet. Or set up a Kerberos environment and get single-sign on too.
- stcredzero 16y agoBottom line: Did you get owned [Y/N] As I've mentioned elsewhere, competent security needs to take into account sociological/economic analysis. Only looking at the technical and organizational side is literally just playing with yourself. For example: if you're a major technology company, taking the step of publishing wildly popular content with DRM means you're going to be taking on a lot of highly motivated opponents. History demonstrates that this isn't a fight that you want to take on. Now consider: if you're a security company, what do you think is going to happen when you take on a subset of /b/? Here's a hint: before you're in the position where you're risking the ire of a large, technically savvy population that's had demonstrated success taking on other corporations with comparable or greater resources than yourself and a history of flaunting the law, it really behooves you to do some preparation. If you've been saving some chump change by keeping your mailserver on the same machine as your webserver, and you're about to take on /b/, now's the time to do something about it. That's like some athlete not checking if his shoes are laced up properly before the event. Did this security company ever audit its own security? Either they didn't or they did an incompetent job of that. Would you trust a security company that doesn't eat it's own cooking?
- InclinedPlane 16y agoNot necessarily. It's easy to forget that attacks typically depend on, admittedly very common, multiple layers of security failures. For example, using the same passwords on many systems, etc. Good security is defense in depth. Keeping every component as secure as possible and keeping any breach of security as restricted as possible. It may not be possible to avoid every conceivable attack, but it's certainly possible to withstand a large number of attempted attacks. The other side of the coin is that attackers don't publicize their losses. Every attacker has a limit to their skillset. If they can't compromise someone they won't announce to the world their failure, they'll just pretend like nothing happened and move on.