3 ms·
An attacker would first have to find my system, specifically, and then breach it. In terms of the most common method of breaching systems, social engineering, i
by usrbinbash 3y ago
An attacker would first have to find my system, specifically, and then breach it. In terms of the most common method of breaching systems, social engineering, it is me, a single software engineer with a very solid background as a sysadmin, compared to a staff of many hundreds or thousands of employees at a large, visible company.
So simply in terms of attack surface, exposure and discoverability, doing that is a REALLY tall order. Many animals on this world survive not because they are huge and strong, but because they are tiny, fast and next to invisible.
Economics play a huge role in attacking systems. Targeted attacks are time consuming, costly, and if the end result is one guys passwords, usually not worth it. People carrying out such attacks want to use a dragnet, not a fishing rope.
> If you use open-source and a critical bug is found
...then many many many large organisations have the same problems as I do, only while being a lot more exposed and visible than me. Because the software I use relies on the same standardized, battle tested, vetted and re-vetted for years technologies as many commercial products.