6 ms·
If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at t
by pilif 4y ago
If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely want to make sure that the only software that gets to run is the one I want running.
This (especially) includes the machine's firmware and kernel because that's where malware could effectively hide itself from countermeasures deployed on the machines directly.
If I can then also make sure that the various admin interfaces in our network can only be used by machines in a known-good state, I would sleep ever so much better knowing that the various hacks we have seen happening to 1Password, Uber, etc this year cannot happen on my network.
I would even say that this is helpful for my users because they will never risk being "the one who let the ransomware in".
This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work.
- no_time 4y ago>This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work. The fundamental issue is that you can't have one without the other, and that's bothering me. It's not like only corporate grade laptops come with TPMs now (like they did in the past). Safetynet on my phone is the same thing and it's very much "about my own private machine". Seeing the reactions and the lack thereof about these developments makes me think this will end terribly.
- pilif 4y ago> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux. The suggestions in the original post do not change anything about this.
- no_time 4y agoI am mainly worried about remote attestation encroaching on territory which was traditionally under the user's control. And once this tech reaches critical mass, sure you can disable it however that also means turning your machine into a glorified paperweight that can't access anything arbitrary websites and software.
- kevincox 4y agoYou see this on Android, my banking app requires that it is running an OS approved by a big vendor. Their website, especially the mobile version, is getting more and more tedious to use. I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.
- growse 4y agoIt sounds like you're demanding to use someone's service on your own terms. I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires. So.... vote with your feet and choose a bank that shares your values more closely?
- kevincox 4y agoYou have a point that the problem isn't the technology but the policy. However the fact is that most banks are moving in this direction so it leaves a consumer little choice.
- no_time 4y ago>I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires. They are not obliged by law in any way. However leading up to this point, whatever happens on my side of the network socket has been my discretion. Disrupting this dynamic just bothers me.
- TeMPOraL 4y ago
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- nonrandomstring 4y ago> If I was responsible for ... the only software that gets to run is the one I want running. Not wishing to pick on you personally, but the above paragraph is wonderful example of the sort of logic going around that bothers me. You trace a faultless journey from responsibility to desiring total control. That's not what responsibility is. You're describing the feeling of culpability within a brutal regime - where Vader simply force-chokes a lieutenant for "failing me once too often". Responsibility involves leadership, which involves not stripping every subordinate of their agency, dignity and humanity. It involves trusting people. Sadly, computers make a "zero trust" ecosystem far too easy now, and that's how they can destroy our society. Good computing is figuring out ways to preserve liberal democratic society while also improving it.
- api 4y agoThe problem isn’t that you can’t trust people. The problem is that people are defenseless in the face of malicious hackers with vastly more expertise and zero day vulnerabilities. It’s not that you can’t trust your employees. It’s that you can’t trust them to defend themselves from being mugged. The forcing function for all this removal of freedom is defense against malicious hackers. The removal of freedom is not the goal so much as a side effect. It works the same way in the real world. We would not need borders or armies or police if everyone were nice.
- nonrandomstring 4y agoSome good points. Lets see what we can do here: > The problem isn’t that you can’t trust people. Good. It's always best to have an optimistic view of our fellows, that's how we build good social structures. > The problem is that people are defenceless in the face of malicious hackers So. Make then not defenceless. We arm them. With education and other tools they need to defend themselves. Digital Self Defence (Or Digital Literacy 2.0 if you want a fluffier title) is the project I am committed to. Defensive tools belong in the hands of users. > with vastly more expertise We can balance the theatre twofold, by giving people more defensive capability, knowledge and rights, and by attacking the knowledge base and knowledge value of malicious actors. We must recognise that many of our own institutions play part of the problem, from vendor malware, and backdoors to security disinformation. Cyber-law needs radical reform to give end-user better security rights, and "surveillance capitalism" needs dragging to the dock. > zero day vulnerabilities. Starting maybe with an all out assault on "zero days", including the companies, agencies and re-sellers of them, using the law. > It’s that you can’t trust them to defend themselves from being mugged. Part of ones job then, is to enable them to defend themselves. You cannot follow your children around for the rest of their lives in case bullies pick on them. You need to teach them fighting skills so they won't be doormats. That's the reality of the digital workplace today. Also, don't give your kids gold Rolex Oyster watches and diamond rings to mooch around scuzzy neighbourhoods with. Limit assets, practice compartmentalisation. Half an ounce of sensible opsec is worth a ton of authoritarian technical non-solutions. > The removal of freedom is not the goal so much as a side effect. The removal of freedom is NEVER an acceptable "side effect" of any security action. Security and freedom are not diamtrics. Otherwise "the terrorists win" and one may as well join the ranks of malicious principles and directly attack our own people (which is the stance many US agencies have taken since 2001 toward baby and bath-water alike) > real world ... borders armies police But this isn't the real world. Its a digital one which is different. The old military model of perimeters and weapons isn't working and smart people in cybersecurity know that. The collateral damage of that broken model is our digital economy and liberal democracy itself (which are intimately linked in the American/Western mind if you believe one jot in things like startups and entrepreneurialism). We'll simply have to do better than handing over the responsibilities of our elected guardians to unelected companies considered by some [1] to be criminally motivated. We still have laws, schools and hopefully enough common sense to avoid that. EDIT: subtracted fulmination. [1] https://en.wikipedia.org/wiki/United_States_v._Microsoft_Corp https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor.... https://en.wikipedia.org/wiki/Microsoft_litigation https://en.wikipedia.org/wiki/Microsoft_litigation