4 ms·
The German security landscape in general is in a pretty bad shape, hence such pentesting isn't all that valuable. Patch one vector, dozens or hundreds left open
by dividedbyzero 4y ago
The German security landscape in general is in a pretty bad shape, hence such pentesting isn't all that valuable. Patch one vector, dozens or hundreds left open, and there is neither a strong security mindset nor a realistic option to implement meaningful security in infrastructure that often as not is decades old, fully analog, built without any security considerations at all, and falling apart on its own. IT security is pretty catastrophic (German law makes it hard to do it properly, it's much stricter than e.g. the corresponding US law), but physical security often as not turns out to be a sturdy closet with a hardware store combination padlock, even for things that would be considered critical and protected much better in other places.
I think this is about sending a message (we're aware of that situation + able and willing to take advantage of it) and to do it in a way that can't be kept under wraps. I guess this won't make it any easier for Chancellor Scholz to send the tanks Ukraine requested.
- formerly_proven 4y ago> IT security is pretty catastrophic (German law makes it hard to do it properly, it's much stricter than e.g. the corresponding US law) To chime in on this, if you're in Germany and report a security vulnerability to a vendor there's a very good chance you'll get a criminal investigation, house searched, computers/phones seized for a long time etc. in return. Often in combination with a cease and desist or civil charges. It's not a good idea to approach vendors directly with findings in general, but in Germany doing that can seriously screw your life up. I wouldn't do security research in Germany at all. If you have talents in the area, just go to the US.
- dividedbyzero 4y ago> If you have talents in the area, just go to the US. I believe most simply go to another EU country since that's extremely easy to do and you can still serve the German market easily.
- mk89 4y agoReally interesting topic: do you have any source you could share?
- tetha 4y ago> there is neither a strong security mindset nor a realistic option to implement meaningful security in infrastructure that often as not is decades Honestly, there is the opposite of a strong security mindset over here. Just a year ago, a security expert found an app of a major party leaking data of thousands of private persons - it was basically a web application without authorization. She tried to disclose this responsibly and naturally got sued due to unauthorized access to computer systems. Lilith Wittman is the person if you want to look further into it. That's the standard here for security topics. And if you keep digging into prosecution of cyber criminality, or at least actions of the state to increase cyber security, or at least actions to increase competency in cyber topics, it just gets worse. For example, they are looking for cyber security experts to join the police and state departments, but because they'd be working in various kinds of police jobs... they have to go through the same fitness and endurance tests as all police officers. Casual things like 12 minute runs, obstacle courses under pressure. Things IT-Nerds are good at. I might have been interested some time ago, but currently that's just a recipe for criminal charges and disappointment.
- carlmr 4y ago>Casual things like 12 minute runs, obstacle courses under pressure. Things IT-Nerds are good at. I might be able to do that, but then again the pay isn't great either. You can't ask for the right candidate with some useless extra requirements, if you don't even pay enough to get the right candidate without these extras.
- 411111111111111 4y agoSurprisingly, there was a video that aired just yesterday which talked about how deeply entrenched Russia is in Germanys IT infrastructure. (German) https://youtu.be/dtZf-A4Qd5k https://youtu.be/dtZf-A4Qd5k
- huijzer 4y ago> The German security landscape in general is in a pretty bad shape In some sense, they are doing pretty good. Much of German's companies and government organizations rely heavily on paper, telephone calls, tape recorders, physical meetings, and even fax. Many bridges (big, but also in rural areas) even have signs containing the max weight limits for various vehicle types including tanks. I sometimes wonder whether Germany's reliance on old-fashion methods are actually meant to be as reliable as possible in worst-case scenarios and to be difficult to hack. I mean, good luck hacking a tape recorder from thousands of miles away.