4 ms·
And really it only takes a bad actor inside a company to circumvent most of the security on-site anyway. Until companies treat every accessor to the network as
by balabaster 5y ago
And really it only takes a bad actor inside a company to circumvent most of the security on-site anyway. Until companies treat every accessor to the network as malicious, this will continue to go round in circles. Most businesses just don't have the budget to deal with security this way.
- emteycz 5y agoPerhaps it's time for network police then. We don't expect businesses to deal with other crimes...
- balabaster 5y agoThere needs to be something. I'm curious what we will come up with. Some kind of sentinel that sits on the network and does behavioural and threat analysis of all network traffic and prevents damage before it can happen perhaps?
- aaronax 5y agoWhen I hear something like "network police", I start drawing parallels to the real world. In the physical world, you generally don't have anonymous people running around (or at least most cases you have a way of linking any actions/crimes committed to a real, permanent identity), disguises aren't allowed, and trespassing is not permitted. So the Internet could be like this if it was more regulated. Anonymous traffic could be prohibited...no more TOR nodes, no hands-off proxying of traffic, no "it's an open access point, I totally don't know who was creating that torrent traffic". Would these sorts of laws be accepted, or would they simply result in more attempts to anonymize traffic? I imagine that this is sort of what things are like in more authoritarian places like China. Is it effective there?
- nradov 5y agoSuch sentinel devices have been available for years. The trouble is they can't reliably identify attempts to exploit zero-days because the patterns are unknown.
- elliekelly 5y agoSure we do. Anti-money laundering regulation is basically just the government outsourcing the front-line policing of financial transactions to banks and businesses.
- emteycz 5y agoAnti-money laundering regulation requires you to obtain and log information about the customer, not to recognize money laundering and definitely not to solve it (except in very special cases applicable to mega-corporations).
- elliekelly 5y agoI’ve been the AML Officer for several large financial institutions and I can assure you they absolutely do need to recognize money laundering. They’re required to have systems, policies, and procedures in place to identify, prevent, and detect money laundering.
- emteycz 5y agoKeyword "large". Yes, we require large companies to do much more than small ones. But we require even the small ones to deal with network breaches perfectly.
- buitreVirtual 5y agoWith proper backups outside the reach of most personnel, and requiring multiple signatories to delete them, a bad actor is not enough to bring the business down.