4 ms·
It might be underselling their capabilities by referring to them as teenagers, but you're overselling the difficulty - it is not extraordinarily difficult to de
by staticassertion 5y ago
It might be underselling their capabilities by referring to them as teenagers, but you're overselling the difficulty - it is not extraordinarily difficult to deal with these attackers.
- unclebucknasty 5y ago>you're overselling the difficulty - it is not extraordinarily difficult to deal with these attackers. Of course you'd say that, because you're vastly underselling the difficulty. You're not accounting for the number of attack surfaces, the number of attack vectors, or variables that are outside of a firm's control, such as zero days in software from third party vendors. Many firms also deploy tons of legacy code that they depend on to operate their businesses, some of which may have been developed by vendors long gone and cannot be easily replaced. Social engineering attacks are also becoming vastly more sophisticated. In general, you're not accounting for the relentlessness of these actors. Sure, it's easy to mock a company when they are sniped over some low hanging fruit, but I've been on the front lines of having to deal with these types and it's nonstop cat and mouse. They only have to be right once and most small companies don't stand a chance. But, none of that is really the point. The real point is that the blame is not with the victims, but with the criminals and the nations who sponsor them So, we should respond accordingly, instead of accepting or regurgitating their victim-blaming propaganda. I know at least four people who work at companies that were attacked over the last few years. Two of them are small businesses that sustained devastating losses and lost time. The economics hurt all of us, raise prices and can cost lives. These are attacks on society's collective security. What's so hard about holding these criminials and their sponsors accountable?
- staticassertion 5y ago> Of course you'd say that, because you're vastly underselling the difficulty. Well, I don't really think so, obviously. And where you made an affirmative assertion ie: "it is extraordinarily hard" I just made a negative assertion "it isn't". I didn't qualify how hard it is. But regardless, > You're not accounting for I am. Been in infosec my whole career and well before it. Been a CEO of an infosec company for two years now. > number of attack surfaces, the number of attack vectors The major threats are the same for virtually every organization. Phishing and malware. Both have extremely effective measures that any organization can roll out: 1. U2F (unphishable credential) 2. Default-deny execution (99% of malware is dead, and you now control more of your attack surface) > such as zero days in software from third party vendors. You can defend against this in a number of ways as well. I do feel that vendors are often the weak link. > Many firms also deploy tons of legacy code that they depend on to operate their businesses, some of which may have been developed by vendors long gone and cannot be easily replaced. That was a mistake on their part. Even still, you don't have to replace it to make it safer. You can isolate it, build around it, etc. Not to mention, very little software is truly irreplaceable. > he real point is that the blame is not with the victims, but with the criminals and the nations who sponsor them OK but that's a different point than what you originally made. You stated that it is extremely difficult to defend against these attacks, I'm saying it isn't. Whether one should have to defend against them or not really wasn't your point, even if now you say it is. > wo of them are small businesses that sustained devastating losses and lost time. It's an awful thing. They have my sympathy. > What's so hard about holding these criminials and their sponsors accountable? Right, so, here's the deal. 1. Many of the breached companies are not really 'victims'. Instead it is their users who are victims. So we hold them accountable because it is their responsibility to not let their users' data get owned. That's on them. 2. We can't hold attackers accountable for a number of reasons. Maybe in a moral sense we can, but in a practical sense we have to take precautions. I would never blame an end user, a singular person, for getting owned. It's not their job to protect themselves from the world. I'll absolutely blame companies (ones with user data) who get owned because when you sign up for a company you're taking on a number of additional obligations and responsibilities.
- unclebucknasty 5y agoI assumed you worked in infosec, so no surprise there. What is surprising is that you're essentially claiming clients primarily need only take a couple of measures that you imply to be trivial, so they are negligent if they are breached. Aside from the obvious wrongness of that mind-boggling assertion, it raises the question for even the uninformed as to why there would be a multi-billion dollar infosec industry--that includes your company--if security is as trivial as you suggest here. Of course, the answer is that it is not and that you should understand better than most the complexity inherent to infosec, else you wouldn't have a business. Perhaps that's why, of the people I know who work in infosec, not a single one is as cavalier as you appear to be here. But, here you're again underscoring my point by focusing solely on the victim's "culpability" and now even claiming that they are not actual victims. Victim-blaming is a standard propaganda technique propagated by the criminals and their sponsors. Why are you working so hard to oblige them with these odd false narratives?
- goldenkey 5y agoI've been doing infosec since I was 10. That's why I know a teenager can rip apart billion dollar companies. Just take a look at the audience of any 2600 or Defcon meetup. 90% of these people were tearing shit up since they were a kid. In fact, I was a better hacker when I was younger, because I had more time to experiment and learn new things. I know this all comes as a surprise to a bootcamp or C.S grad, but you are not representative.
- unclebucknasty 5y agoWe're being attacked by organized criminals, sponsored by hostile nation-states, not your imaginary teenagers. The point is that we should defend our companies and economies by responding vigorously against the criminals and their national sponsors with law enforcement and aggressive offensive cyber capabilities. They need a smack in the mouth every time they touch any of our citizens or the companies for which they work. These are costly direct attacks on our national security, economic prosperity, and infrastructure that are followed up with classic Russian-style propaganda, intended to minimize and redirect blame to the victims. That propaganda is then propagated by trolls and useful idiots. And, here you are with your victim-blaming and minimizing strawman claims about teenagers and boogeymen.