5 ms·
> where every single person in the entire company has to make 0 mistakes, and an attacker only has to get lucky once Good post. I don’t mean this criticism for
by lurquer 5y ago
> where every single person in the entire company has to make 0 mistakes, and an attacker only has to get lucky once
Good post.
I don’t mean this criticism for you specifically.
But, why is there an assumption among HN types that there are no bad-actors among the insiders? You can have all the safeguards you want, but if an insider deliberately installs something, you’re screwed.
In some industries — armored trucks, banks, military stuff — there is a huge emphasis on background checks, security clearances, and the like to weed out bad actors. (And, even then, it often fails.)
I sense there is nothing similar for employees handling the company’s data. Obviously, there might be background checks and the like — hell, McDonalds has background checks. But, I’m not aware of the intensive FBI-style screening you see in the aforementioned realms.
Am I wrong?
How many thousands of people, for instance, could corrupt or lock the data at, say, Amazon? Are these people scrutinized to the same level as standard Brinks Armored Truck driver? I doubt it.
- squiggleblaz 5y agoI guess there's two questions: - is protecting against internal sabotage actually different that protecting against external attack. I don't think it's all that different. It comes down to authenticating actions and enforcing the principle of least privilege. If you built a system that was actually secure (i.e. one that depends on reasonable inconveniences, rather than one that depends on people to be perfect all the time or is so inconvenient it inclines them to do the digital equivalent of jamming the door open) it is likely that it will be secure enough against most internal saboteurs. - is protecting against internal sabotage going to pay off? Most people probably aren't inclined to deliberately target their own company. It's far more likely that there is a bad actor in the world who wants to target your company, than that there is in your company. And making a person's job secure less stable is probably going to make them more likely to be a saboteur, so you should carefully evaluate whether gratuitously adding stress to someone who might get behind on their mortgage is a good idea. (Which I suppose is what this kind of background check would cause.)
- ipaddr 5y agoMalware comes from the outside. Stealing company secrets and selling them is what I would be worried about from internal threats. Either way least access necessarily where possible is a good strategy.
- lurquer 5y ago> Most people probably aren't inclined to deliberately target their own company. It's far more likely that there is a bad actor in the world who wants to target your company, than that there is in your company. “Most” people are law abiding. So, I agree with the first sentence. The second sentence, however, has little support. The universe of people who can do these types of attacks is large, but not universal. You need computer skills. Necessarily. Those with computer skills are usually already part of the industry. How many disgruntled people pass through the FAANGs each year? Now add in all the IT positions at the banks. In short, there are probably tens of thousands of domestic ‘bad actors’ who have (or will have in their careers) access. Probably more.
- squiggleblaz 5y ago> The second sentence, however, has little support. Your argumentation doesn't challenge the truth of falsity of the statement, nor does it go towards challenging my conclusion. It seems to assume I've said "there are probably no internal bad actors", when I've said "securing your system against external bad actors will deal with the cases more likely to occur, and will usually be sufficient against the less likely cases". 'X is more likely than Y and preventing X mitigates Y to a tolerable level' is not equal to saying 'Y probably doesn't happen'. > How many disgruntled people pass through the FAANGs each year? Now add in all the IT positions at the banks. Obviously the probability increases significantly with the number of employees, but I don't think that switches the probabilities. Still, the most important companies to consider are the companies which, unlike FAANGs, aren't really in a position to make independent judgement about their risk profile, but whose existence depends on their records/data. And even someone with as many employees as the US government probably has more people outside of their employ who want to target them than inside, although surely they always have some of both. I'm not sure what the relevance of your reference to computer skills is. In order to ransomware a company, as far as I know, you need to buy software off the darkweb and run it from a vulnerable location. I suppose technically that requires computer skills, but it's surely not what you mean. And the companies which are vulnerable to ransomware are not all employers of significant numbers of technically skilled people. In any case, I don't think even a gratuitous reevaluation of the probabilities significantly changes my conclusion. Even if we assumed the improbable notion that every single company in the word has a disgruntled employee and that there are no external crooks, the process of securing the system against external crooks will make it far more survivable against single internal bad actors, and the effect it has on the employees will be less likely to produce internal bad actors.
- cartoonworld 5y agoYeah this is a great point, you gotta figure that armored trucks, banks, military stuff, they all have functional physical access control, clearly defined risks, established value, etc. The person wheeling the dolly full of cash and the driver of the truck... well you know those two people are going to be handling bulk cash. The MP guarding the nukes is standing at the checkpoint. Check em' because you can just move on to the next person. But in the corporate world, theres gotta be huge variance, but so many don't give a flying flamingo who's scoping out what, unless somebody is forcing the issue (and also auditing and reporting to the compliance department, whatever thats for). They know the people in the NOC/SOC, the C-suite has equity, there may be physical access control, cameras and proxcards out the wazoo, but when Marge from bizdev needs those emails for the marketing newsletter or whatever, she is gonna get them immediately and hand them right over to the intern or vendor or Doug, whatever his job is. For all the obscene value that the data and access represents, its encrypted, right? What could go wrong? Want to background check the sales people? But... look at this guy's resume! He's only asking 80% of the market rate! These dialysis machines sure won't renew their support contract by themselves. Best case scenario is that the costs mount even higher into the stratosphere and people start demanding a second look. It's been a while, Maersk, JP Morgan, TransUnion, Colonial Pipeline, Beef, Hospitals, Schools, the OPM (for god's sake...) billions or trillions of dollars. It doesn't seem to be a priority.