4 ms·
When you talk about IT security with people with real secrets (governments), they talk about LulzSec-types being the "lowest risk" category of attackers. The m
by willidiots 15y ago
When you talk about IT security with people with real secrets (governments), they talk about LulzSec-types being the "lowest risk" category of attackers.
The mid-risk category are the real professionals; they leave no trace, you never hear about them, you never know they were on your system, they just take your data and sell it.
The highest-risk category is true information warfare, targeted attacks by other governments and large entities. As the previous replier said, just look at Stuxnet. You don't have to be a government for this to be a real threat. Imagine if Nintendo had compromised Sony's servers, and somehow loaded corrupt firmware onto the Playstation update system...
These threats are real and constant, and anyone with sensitive data needs to be aware of them. Simply firing up iptables and disabling root SSH isn't sufficient - you need to be aware of the intricacies of your system on a day-to-day basis.
- shii 15y agoExactly, I am almost certain this was floating on carders' forums weeks if not months before.
- JonnieCache 15y agoTo be honest, if your opponent has a couple of million dollars or more to spend on hacking you, and you aren't willing to expend several multiples of that on defence, you should probably give up on the convenience of having your secret data on the internet and just have it encrypted on HDDs surrounded by handpicked armed guards who owe you a blood debt. Computers and especially networks are just fundamentally insecure for the purposes of high-value information. This is the same reason why internet voting will never be a good idea.
- jsmcgd 15y agocheck this out: http://www.ted.com/talks/david_bismark_e_voting_without_fraud.html http://www.ted.com/talks/david_bismark_e_voting_without_frau...
- JonnieCache 15y agoI'll see your 7 minutes of TED and raise you 60 minutes of Google TechTalks! http://www.youtube.com/watch?v=_GjmRwfkRXY http://www.youtube.com/watch?v=_GjmRwfkRXY Electronic and Internet Voting (The Threat of Internet Voting in Public Elections) It goes into all sorts of electoral fraud, the finer points of designing elections from a hacker perspective, the diebold hacks, and that awful rails app that those students (?) wrote in the hopes of using it in some US local elections a while back. In brief, that system isn't safe because someone can obtain your reciept and therefore your voting rights from you by coercion/incentives. Votes should never be verifiable, because then they can be bought. Vote reciepts would be pretty valuable...
- jeradj 15y ago>Votes should never be verifiable, because then they can be bought It's nearly legal to buy votes anyway, but they just call it advertising.
- anonymoushn 15y agoThey are already verifiable. You provide the seller with an absentee ballot, he or she fills it out, and then you exchange the completed ballot for the beer/cash/delicious pie.
- JonnieCache 15y agoTrue, but a crucial difference is that the cryptvoting allows verification after the fact, while absentee ballots must be verified in the window between the ballots being sent out and polling day.
- bxr 15y agoI know the high risk actors are there, my post was fueled by my continuing fascination of how low the barrier to entry to the low-risk category is, and how high the potential they have is.