3 ms·
No network of any reasonable size/complexity can keep out a focused attacker. If you think yours can, you are wrong. Today's threat models are dominated by t
by jjguy 15y ago
No network of any reasonable size/complexity can keep out a focused attacker. If you think yours can, you are wrong.
Today's threat models are dominated by the criminal, opportunistic attackers looking for user information or computing power. Real discussion and countermeasures for focused attacks are severely lacking.
Governments know this. CISOs know this. They speak of it privately to each other, but rarely in public because the issues are so sensitive. Messaging from industry is dominated by the vendors who both have significant equities in the "we're secure!" message and speak very narrowly about the security of their applications, but rarely/never about the collection of those applications into these beasts we call networks.
Posts like this are becoming more commonplace, but neither industry nor academia are making tangible strides to solutions. If you want a startup idea, focus on security and go disrupt.
- tptacek 15y agoGood luck with that. Security is lousy with product startups. The opportunities for technical disruption are clearly there. But no sector outside Business Process Software like SAS and Oracle has so much built-up institutional knowledge of how to run direct sales and marketing to enterprise customers as security. The crappiest me-too products are weaponized for enterprise sales 6 months before they're launched. It's hard to break through the noise.
- jjguy 15y agoThe noise is incredibly annoying. There's no industry-accepted way to distinguish between a security expert and the guy with the A+ cert. We really need to raise the bar and instuitionalize better standards. Your points re: difficulty of enterprise sales are hard-learned, I assume. My intuition says there's an opportunity to exploit there, given the disconnect between users and industry. Of course, the same is true of cell providers, but no one has managed that one yet either.
- tptacek 15y agoThe one disruptive approach I've seen work over the last 10 years is open source. There are early adopters and there are influencers. But in enterprise sales, they're rarely the same people. Among 2000 billion dollar enterprises, there are perhaps 20-30 with strong security teams with the bandwidth to truly engage with new technology (as opposed to simply running a bakeoff and deploying a product in a category that a trade press magazine says is important). Those are influencer early adopters. Open source allows you to release something early and maybe catch the attention of those influencer early adopters. A scrappy sales team that can take a meeting with a new customer and put a couple F-500 deployments on the logo slide because they've got Github followers has a shot at getting pilot deployments. Open source is also "free", in the sense that enterprises can't not spend money on software; deployment decisions follow purchasing decisions, not the other way around, so the drumbeat of technology at an enterprise is purchase orders. Try hard to give your software away at an enterprise; nothing will happen until you give them a way to pay you money.
- pilom 15y agoOne idea for startups: http://simplecybersecurity.com http://simplecybersecurity.com I'll be publishing exactly what steps have been done to each AMI and blogging about improving security of individual products. Still half stealth as the landing page isn't exactly optimized.