3 ms·
I'm not really sure about this logic. Is an APT going to use anything but old vulnerabilities against an off cloud shop that might have unique auditing to burn
by fatfingerd 3y ago
I'm not really sure about this logic. Is an APT going to use anything but old vulnerabilities against an off cloud shop that might have unique auditing to burn them? Are they going to develop a new one for such a shop when the payout couldn't be a fraction of what a success would return from even a minor cloud vendor?
On top of that you also have all the same regular vectors of desktop/mobile OSes, etc. So the cloud isn't really an adequate defense if you are a real target and is just one much more handy cookie cutter vector that will almost certainly trawl your data accidentally to an APT group when a mistake makes it practically free.
- _8j50 3y agoGoing back to moveit as an example, they used a zeroday and mass-ransomed people. The cloud isn't an adequate defense, it is just better than the defense less resourced companies and people can put together. With APTs it is all a competition of resources. If you can self-host and spend more resources than say Microsoft or Google on securing it, go for it. There is nothing more or less secure about doing cloud or self-hosting, what matters is how much money you can put into it but more importantly, how much talent you can attract. Not only do MS and Google have hefty bounties for finding vulns, skilled people flock to them for the opportunity to work there, even at lower salaries! Likewise, intel agencies and gov/mil units are coveted by skilled people. To use a real world analogy, a chinese specialops unit might invade your small town and the argument here is to buy guns and practice shooting using the locals (self-host) vs calling in the army (NSA -- i blame them!) or paying a mercenary group (because the army won't dedicate a unit to your small town only). It doesn't matter if everyone in your town is ex-military, even if you defeat the chinese specialops unit, their mission will remain,they will just keep sending more people and more firepower and better strategies until they win. And just because a mercenary group lost to a chinese specialops unit does not mean you should have been using civilians to begin with, that's a false equivalency.
- fatfingerd 3y agoDoesn't a service like moveit just blur the lines between cloud and on premises? I mean how exactly did they find these 400 orgs fast enough, was it a centralized command center? You lost me entirely on the second paragraph. Some kind of militia attitude or trusting private armies probably means you are getting well beyond normal civilian behavior. You buy locks, you compare lock manufacturers, if you aren't the easiest of targets or the most valuable you represent a waste of time.
- _8j50 3y agoThey scanned the internet, they were testing their exploit for 1-2yrs before "d-day". > you are getting well beyond normal civilian behavior That is precisely my point, the threat actors are not civilians, so you can't defend them with the resources you have as a civilian. > if you aren't the easiest of targets or the most valuable you represent a waste of time. The internet changed power dynamics so that anyone on it can try to break the lock of your front door, including nation state sponsored theives. The lock in this case was more like a vault door keeping companies' secrets. Cloud vs self-host does not change who will target you, the difference is an in-house vault vs fort knox.
- fatfingerd 3y ago> That is precisely my point, the threat actors are not civilians, so you can't defend them with the resources you have as a civilian But this is leading to a crazy generalization. Microsoft can't defend itself as a civilian with a physical presence all over the globe that hires thousands of workers. Nonetheless, the sequence from solarwinds to this breach represents a terrific amount of China's focus.. Tearing through old data to find an expired key, probably also encrypted, and combining it with an active config error for it is a bit more than scanning for a standard attack against a class of old routers. If your data is pooled without e2e encryption it is in the middle of a capture the flag game and will be owned. For Microsoft to make a cloud that doesn't have to be secure from the most sophisticated resources of China they would have to stop assembling all that data so that it would have to be assembled with the boring and endless botnet scans on hundreds of thousands of different end points. Attackers will always get better at automating distributed scans but it is always a small percentage game that isn't as great as owning 3 clouds that each have equally good copies of about a third of this data.