3 ms·
> The routine update, it turns out, is no longer so routine Is there the rare case that we shouldn't update because the update could contain a malicious payloa
by cyberlab 5y ago
> The routine update, it turns out, is no longer so routine
Is there the rare case that we shouldn't update because the update could contain a malicious payload? If the update gets served over plaintext HTTP I would treat it as suspicious and may even block it from connecting at all. I run the risk of having outdated software, but that can be addressed by storing the software in a machine that's not connected to The Internet in any way, so it can't really do anything/talk to a C2 server (if someone does decide to execute an 0day with the software or inject malicious code via a rogue update).
- trynton 5y ago@cyberlab: “Is there the rare case that we shouldn't update because the update could contain a malicious payload?” You don't ever update your security “computers” from some third-party outsourcer. What you do is have your own people constantly probing their own systems for potential vulnerability and patching it themselves. * jeez ..SolarWinds run their stuff on FTP and "active directory". It's got to be a joke. * “computers” .. not allowed to use the 'W' word ;]
- deleted 5y ago[deleted]
- covidthrow 5y agoPlaintext transport doesn't matter if at least one part of the payload chain is cryptographically protected/verified. If you have a machine that's air-gapped and its only IO is strictly humans (read: keyboard/screen, not USB or other electronic means) then your weak point is the human, so center your security around that. You can look at security of lottery machines to get a good idea how that's handled. But if you're updating the machine with updates, then it doesn't really fit that criteria, soooo....