4 ms·
I don't know... I mean, maybe the security posture is to annoy the hackers into giving up? ("This thing requires a Java applet and is slow as hell. Screw it, l
by function_seven 6y ago
I don't know... I mean, maybe the security posture is to annoy the hackers into giving up?
("This thing requires a Java applet and is slow as hell. Screw it, let's just pwn the bank across the street")
I'll call it Security by Inconvenience.
- catmanjan 6y agoThat's why your security solution should include a mix of every known technology, hackers need to know everything from COBOL to rust
- tjalfi 6y agoThat reminds me of a post[0] on alt.sysadmin.recovery. The hackers were annoyed by the compromised machine so they installed security updates and did other system administration tasks. [0] https://groups.google.com/g/alt.sysadmin.recovery/c/ITd7OlMr21g/m/e0OU5zqYvRgJ https://groups.google.com/g/alt.sysadmin.recovery/c/ITd7OlMr...
- krylon 6y agoI vaguely recall some kind of malware that upon infecting a system scanned the system for other malware and removed/disabled it. The motives were far from pure, obviously. (Although there also was a case, I think, of a piece of malware specifically created to ensure "infected" system had up to date AV software and were up to date update-wise. We sure live in strange times.)
- tinus_hn 6y agoAmusing but today there’s two kinds of hackers: people who manually run a campaign like in your story and the endless hordes of bots that automatically exploit systems to turn them into botnet slaves or cryptolocker hostages. You can’t inconvenience a bot.
- exikyut 6y agoSuch strategies are remarkably effective, and maybe arguably describes all security in a nutshell. Every time I notice an obscure feature in a Google product or service and go "hm, I wonder if that could be exploited", I then always go "...meh, it'll take too long and require too much concentration to figure it out."
- viraptor 6y agoNo, not at scale. You may be discouraged, but there's someone who will have lots of fun breaking that specific feature. See for example @jonasLyk who spent the last half a year (?) trying to abuse almost only the alternative streams and junction folders in windows.
- exikyut 6y agoWow, this guy is mad https://twitter.com/jonaslyk https://twitter.com/jonaslyk I can't help but picture him as a sysadmin walking away from a bunch of servers that are mysteriously 40% faster than ever before, but then he gets stopped at the door of the datacenter by some unimpressed looking lawyers who glare at him until he puts everything back Thanks for the reference, and fair point, yeah that's not how it works at scale.
- nix23 6y agoThe new Ilo has a "HTML5" and Java console. But 3 wrong passwords and your blocked for 10 minutes (by default).