3 ms·
While I generally agree that solar winds was lacking a lot on their internal DnR team (iv cut investments in cybersecurity) a lot of the identified issues are t
by InitialBP 5y ago
While I generally agree that solar winds was lacking a lot on their internal DnR team (iv cut investments in cybersecurity) a lot of the identified issues are things that are seen in businesses EVERYWHERE.
Until recently I was a pen tester and (just a guestimate) 9/10 clients that I do testing for don't properly segment IT networks, use weak passwords for things they shouldn't, and list sensitive and high-value clients on their webpage (they are trying to draw other customers in).
I'd like to clarify two points:
1. It doesn't matter how much money you spend on security - there will ALWAYS be a way for attackers to get in. E.g. Log4J issues recently. There is always gonna be another zero-day or a new email phishing payload or a new NSA hacking tool leak and at most a big company can pay a lot of money and hire a lot of engineers to Reduce the chance of something bad happening.
2. None of these practices are really that unusual (I've seen plenty of software that recommends to tell your AV to ignore it.) and actually managing and knowing about every single credential/password etc in a corp network is almost impossible. Usually things like the FTP server with a weak password get set up long before the company hires their first security engineer, and then refuses to make changes to existing stuff that would take a lot of time and effort.
I do feel that SolarWinds is on the hook for this, especially egregious is (iv cut investments) because of their exceptionally high value clients and the level of access they get into client environments.
However, I don't think it would have mattered much how much money they put into their security team, the team that ran the operation was likely a state-sponsored team and they probably had the funds/people/time to crack such a juicy target regardless of how difficult it was going to be.
- still_grokking 5y ago> a lot of the identified issues are things that are seen in businesses EVERYWHERE Exactly this is the problem. And exactly this shit needs to stop asap! What you're basically saying is: "Software can't be secure at all. So what's the point?" This line of thinking is completely flawed. Software is in the end a mathematical construct and can be even proven secure (according to some arbitrary formal definition of "secure"). That's only a matter of the amount of money you're willing to throw onto this problem in the long run! Starting to jail the people actually responsible for all the daily IT security nightmares (those people are not the developers!) is the only way to get to an end with all the madness modern software development is. As long as the "bugs are an ordinary part of software" attitude prevails nothing will change. But this attitude can only change if the responsible people start to feel consequences for creating one tire-fire after an other—and getting away with it every time.