3 ms·
Yes, putting every device in Windows AD and installing remote management tools that run at the system level is a recipe for total compromise. Software diversit
by _wldu 5y ago
Yes, putting every device in Windows AD and installing remote management tools that run at the system level is a recipe for total compromise.
Software diversity is good. Remotely controlled mono-cultures are bad. IT management and security compliance people need to understand this.
I liken the mindset of (only we will use the remote control software to do good things) to Encryption back doors (only law enforcement will use them to catch criminals). Computer scientists call these 'Exceptional Access Systems' and it has been shown (many times) that it is impossible to ensure they will not be abused and used against you.
Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications:
https://dspace.mit.edu/handle/1721.1/97690 https://dspace.mit.edu/handle/1721.1/97690
- bogantech 5y ago> Yes, putting every device in Windows AD and installing remote management tools that run at the system level is a recipe for total compromise. What alternatives are there? I honestly don't know
- ownagefool 5y agoIt's not really about alternatives, what would the spyware stop that a simple Daemon that version checks your device won't? If you're working from home and your device gets owned, and the attacker just sits there slowly slurping data as you go about your business... Chances are you're not going to detect it, but if you did you'd probably notice it's running when it's not supposed to and it's sending network traffic when not actively used. If someone uses a laptop breach to go look at data you wouldn't normally look at ( or tons of records ) an audit log would give that away. So really to do security well you have to profile the role. Why are you looking up customer record abc123? Trying to see what your girlfriends doing, or is it because they've called the customer support line? You basically have to define what does misuse look like and protect for that. Back on the slow slurp, hardend immutable devices that are regularly updated with limited Auth sessions would likely contain the breach. Same deal on servers, you harder to stop it, but you monitor for when it happens. Do people really monitor though? Some, sure, but your average org buys a tool the fails configure it with any sort of context.
- lima 5y ago> Software diversity is good Software diversity also means attack surface multiplication, so it's a delicate tradeoff.