5 ms·
This, truly, is the thing to worry about: if it happened here, it likely happened at other companies. Turning a blind eye is a blank check to do it again.
by discardable_dan 5y ago
This, truly, is the thing to worry about: if it happened here, it likely happened at other companies. Turning a blind eye is a blank check to do it again.
- etothepii 5y agoThe issue here is that this isn't just "one bad apple" that if we can remove everything will be ok. Which is what motivates the idea that punishing this bad actor will make everything better. There is a systematic issue at the heart of the way we do network security. You can by a lighting / usb cable that can do all of these things and more for $120 if he'd used that he'd never have gotten caught. We treat network security like physical security at our peril.
- Ensorceled 5y ago> The issue here is that this isn't just "one bad apple" that if we can remove everything will be ok. Which is what motivates the idea that punishing this bad actor will make everything better. I think they are talking about this particular, singular, bad apple and the other companies that bad apple is also attacking right now and stopping that harm as opposed to "sending a message" to other bad apples.
- etothepii 5y agoThat feels like a choice for the victim. If after the business owner sat down with the perpetrator they decided it is just some script kiddie playing at being a spy then that's up to them. The wider issue remains that some script kiddie with $120 could have done this and got away with it for ever.
- ianai 5y agoDo you have a suggestion for a change to treating network security?
- more_corn 5y ago1) 802.1x certificate based network security (The MDM configures each approved network device with a certificate so rogue devices can't get on the network) 2) Periodic security review (look at attached network devices and determine an owner and purpose for each one). 3) Configure SIEM to alert on long-lived outbound connections.
- ianai 5y agoCan that (1) be done with windows/Mac clients?
- ianai 5y agoAnswering myself: yes, is industry standard, definitely a little odd to not have it configured on a corporate network past a handful of employees.
- jaywalk 5y agoThere's a decent amount of infrastructure involved in getting 802.1x authentication up and running in an efficient manner. While it does provide very good security, it's not widely used because of that.
- eternityforest 5y agoWithout changing things so radically that we might not even be able to continue having a "Do everything in software with one click" society, social deterrence is going to to be important. Unless people are manually verifying GPG keys in person all the time, you're gonna need to trust someone. Even with a two man rule you need some degree of trust. Trust is easier when people know they might go to jail if they break it.
- asteroidp 5y agoFile that under "not this companies problem"
- TedDoesntTalk 5y agoIt is possible the perpetrator acquired some embarrassing evidence about the company owner and was blackmailed. We’ll never know.
- asteroidp 5y agoIn the extremely unlikely chance he did, so what? He can face legal issues then Most private and embarrassing stuff rarely ever matters anyways. This isn't a movie