4 ms·
Agreed, as a random HN commenter it's way too easy to trivialize the complexity in audit logging such a complex system. Such audit logs are very much dependent
by terom 5y ago
Agreed, as a random HN commenter it's way too easy to trivialize the complexity in audit logging such a complex system.
Such audit logs are very much dependent on the integrity of the system generating them, and the vendor themselves is certainly in the best possible position to compromise that integrity.
I suppose that switching from a vendor-operated system to an independently-operated system would simplify the implementation of trusted audit logs for mitigating the remaining insider threats, though.
- g_p 5y agoAbsolutely, but to build a suitable independent logging system that understands the protocols used, and all the relevant fields, would be hugely complex. Ultimately, you'd need to log every packet in full if you don't trust the core vendor - a control packet could contain an undocumented field like 'cmd', whose value is executed by root... That's the kind of threat you'd be looking to catch. That means you'd need to terminate transport layer encryption on this "firewall/log" system, so that you can see and log the content of control messages. Ultimately, you'd need the cooperation of the vendor to actually build a system that could meaningfully understand these control/management messages, and therein lies the problem!
- jackTheMan 5y agoOr you could require it in the tender. Once they quote 25% overall cost compared to others, you can ask them to implement such a system for 25% more and come back later. it can be a minimal requirement, more so if it is such a sensitive system.