4 ms·
To be clear, given that one never knows if or when a provider has been compromised... is the plan to just not update? What if they were compromised before you
by cookiemonster9 6y ago
To be clear, given that one never knows if or when a provider has been compromised... is the plan to just not update? What if they were compromised before you initially obtained the software? There's not much that can stop attacks like this. Preventing lateral movement, escalation, exfiltration, detection, and remediation, among other things, would be the way to go.
- tedunangst 6y agoDepends how you weigh timing. If attacker doesn't know when you update, they have to hang out and risk detection at the supplier. (Who added this update?) If they can push updates, they can move quickly and compromise the target.
- sneak 6y agoThis is the key. Additionally, updates can be verified to be the same thing that everyone else got, by checking them from multiple different clients/IPs/countries. Targeted attacks are much harder, and if the compromised update is untargeted, detection risk increases drastically.
- jlgaddis 6y agoSome companies (and even some individuals) are of the opinion that, since they are "good" or "smart" or spend $x amount for "security", they aren't going to get compromised. Even worse are the ones who still concentrate their efforts on their firewalls and assume that, inside the network, all is well. They're the ones whose networks and systems are going to be completely and thoroughly "pwn3d" when someone does eventually get in. Nowadays, the general attitude amongst the "experts" is to assume that you/your company/organization WILL -- at some point -- get compromised and to, instead, plan for that eventuality and work to minimize the damage an attacker can do once they have gotten a foothold inside your network. That means doing just the things you mentioned: preventing oateral movement, privilege escalation, and exfiltration of data, concentrating on RPO/RTO (a.k.a., getting things back up and running as quickly as possible once the shit hits the fan), and so on. I've certainly not heard of anyone recommending that software and systems NOT be updated. There's only so much you can do, though. You can make sure that all of your software is only coming from "trusted sources", verify the published checksums (if any) and attached digital signatures, scan files with an up-to-date anti-virus (although, nowadays, that may not actually be worth anything), and yet STILL get hit by something like this. So, you do what you can, try to protect yourself and your organization as best you can, and prepare yourself for when the day comes that it's your name in the headlines instead of the Commerce Department and Treasury Department. (Personally, I'm of the opinion that if a nation-state wants in your network, they will -- one way or another -- get in. I'm looking forward to the day that hosts don't have a default route, are blocked at egress, and all "external" traffic has to go through firewalls and proxies before it can get out.)
- sneak 6y ago> There's not much that can stop attacks like this. Not giving people RCE on your machine will stop attacks like this.
- cookiemonster9 6y agoThat's not the case here. Updates going back as far as what, March?, with no indication that the update included this, were involved here. What I'm saying is that whether you, or an automated update process are performing the update... You still are susceptible. Unless, as I said, your idea is to block updates completely, which is... not really viable. What should these companies have done better for the update side? Sure, there were other controls that could have limited the effectiveness of this once the update was in place, but I'm not seeing anything that would block the update itself.
- tatersolid 6y agoYou gave the vendor RCE when you installed their software in the first place. Automatic updates are overall a huge net positive for security, despite this hack.