4 ms·
We must have a different definition of easily avoidable. The truth is that organizations that spend a much larger than average portion of their energy and resou
by trotsky 15y ago
We must have a different definition of easily avoidable. The truth is that organizations that spend a much larger than average portion of their energy and resources on computer security can and do still fall the victim to intrusions on a regular basis. Outfits that follow generally accepted best practices get successfully spearphished on a weekly or monthly basis. Startups are encouraged by the industry to throw up websites in weeks, yet the tools they're given largely do very little to prevent them from shooting themselves in the foot on a regular basis.
Lulzsec isn't even calling their shots. They're casting around for security issues widely without rhyme or reason. You're supposed to lock your front door, but if you go through a neighborhood and try everyone's front doors you'll always find one that's left open. Now imagine your neighborhood is the world. It's literally impossible that you'll ever run out of victims.
The truth is that computer security isn't shit because all the noobs out there that don't have a CSO, don't hire matasano, don't have sufficient change review policies, don't have a 24x7 ops team with live instrumentaion and don't have DDOS protection are id1ots. Sure, any one of them can be pointed and laughed at and said they're losers. But taken in aggregate, it's not all their 30,000,000 individual failures, it's a failure of the computer industry that has long pushed speed and ease over safety and continues to sweep the current security environment under the rug. And also a failure of our own security industry for selling ineffective, labor intensive solutions and pricing most of the rest beyond the reach of most potential customers.
And I dare say that Lulzsec isn't going to have much of an impact on any of that.
- mattmanser 15y agoTo be frank your point is bordering on meaningless, you've jumped from anyone can shoot someone to it's all a failure of the computer industry. I find the first assertion idiotic and the last begging the question. patio11 made a similar point about armed robbery, I mean seriously, what is wrong with you? It's fucking stupid. If someone gets shot a lot of cops will turn up within minutes. They'll devote a lot of manpower to it. In some of your states the perpetrator will be executed. There's a response. There's a massive immediate manhunt. Will people stop idiotically claiming that a serious, sickening crime is anything like hacking someone's server please? And to get back on topic, if someone gets hacked it's brushed under the carpet if possible if it's even noticed. People aren't even checking if it's happened. Where's the abnormal activity alert built into windows or linux? Or Apache or IIS?
- daeken 15y ago> Lulzsec isn't even calling their shots. They're casting around for security issues widely without rhyme or reason. You're supposed to lock your front door, but if you go through a neighborhood and try everyone's front doors you'll always find one that's left open. Now imagine your neighborhood is the world. It's literally impossible that you'll ever run out of victims. And that is why this stuff is easily avoidable. Much like a lock on your door isn't going to stop a determined thief from breaking in, simple protections won't stop a determined attacker from breaking into your site. But in an age where adding CSRF tokens is simple, SQLi protection is nearly guaranteed by using an ORM and/or parameterized queries, XSS is largely mitigated by filtering on templates, etc, it's not that hard to remove the low-hanging fruit from your site. Even with these, you will still have vulnerabilities, but a drive-by attack like those executed by Lulzsec will not work. > But taken in aggregate, it's not all their 30,000,000 individual failures, it's a failure of the computer industry that has long pushed speed and ease over safety and continues to sweep the current security environment under the rug. It's easier than ever to write secure code without even trying. If you follow, say, a basic Django tutorial, you won't be vulnerable to XSS and SQLi unless you color outside the lines. Add in CSRF middleware, and suddenly CSRF attacks (and a large amount of reflected XSS with them) are mitigated. These are not difficult things, and the software industry is getting better and better about making secure coding the rule, not the exception.