3 ms·
> It is expensive and difficult to protect against security breaches, No it isn't, it's super cheap and dead simple. What's expensive and difficult is fixing s
by staticassertion 5y ago
> It is expensive and difficult to protect against security breaches,
No it isn't, it's super cheap and dead simple. What's expensive and difficult is fixing security problems super late in the game. Undoing bad security is hard. Doing it right is really simple.
For example, we have 2FA everywhere at my company. It's 10 people, so that's easy, and it always will be. If we were 2,000 people I'd have to go through hoops and it'd be a whole mess to roll out 2FA everywhere. By using U2F 2FA from day one we've more or less eliminated credential theft as a threat. By disabling app execution we've eliminated malware as a threat.
Right off the bat the vast majority of attacks just don't work, and those were trivial to implement. We do way more than that, and it was all dead simple.
> One small fuckup is sufficient to have the whole thing compromised
It definitely shouldn't be.
Companies flat out do not care, in part because there aren't consequences for not caring. Otherwise they'd do something about it. Even if you're on an older network where you've got AD and garbage like that you can do a lot to improve things.
- Closi 5y ago> No it isn't, it's super cheap and dead simple. What's expensive and difficult is fixing security problems super late in the game. For example, we have 2FA everywhere at my company. It's 10 people, so that's easy, and it always will be. If we were 2,000 people I'd have to go through hoops and it'd be a whole mess to roll out 2FA everywhere. Lots of companies were founded prior to the popularisation of 2FA, and these security standards change over time. Making new applications secure by modern-day standards might be relatively simple - although you are still exposed to security risks if one of your vendors has a vulnerability (you don't often get to see the codebase of your vendors, so a zero day can hit hard). Then keeping a legacy infrastructure, older codebase or historical on-premise applications (where the vendor may not even exist anymore) secure is more difficult. And all those solutions were 'secure' by the standards of when they were implemented, just times have changed. And then on top of that, we are talking about Ransomware hackers which are buying zero-days for host operating systems - and at that point all bets are off. Let's not forget, you just needed 1 machine of the 2,000 to be 2 months out of date on patches and you were susceptible to WannaCry.
- staticassertion 5y ago> Lots of companies were founded prior to the popularisation of 2FA. Like I said, what's hard is undoing bad security. Still, I know companies that are nearly a century old that have rolled out strong 2FA policies across 10's of thousands of workers across the globe. They do it because they value security. It's much harder to fix a bad network, but it's still just a matter of effort. It's not like we don't know how to do it, it's a matter of effort.