6 ms·
Politics aside, if there was ever a time for an Apollo-like moonshot program to build secure infrastructure and write secure code, it's now. Thanks to wide diss
by technofiend 3y ago
Politics aside, if there was ever a time for an Apollo-like moonshot program to build secure infrastructure and write secure code, it's now. Thanks to wide dissemination of techniques, Attack As A Service and even AI-assisted hacking, the bar to mount attacks just keeps getting lower. The real answer is to build resilient systems with zero backdoors rather than trying to put the hacking genie back in its proverbial bottle.
- jakobson14 3y agoApollo was a scramble to get the absolute minimum tin can to the moon as fast as possible which wouldn't kill the 2-3 men inside it. Building anything secure is a detail-oriented endeavour. It is not solvable with a moonshot. The question I have for cisco is: why are these special features for resisting cyberattack not standard on EVERY router?
- peblos 3y ago“Cisco’s response involved shipping a large order of modified equipment, specifically designed to maintain accurate time even under radio jamming conditions.” Probably not something most Cisco customers need or want
- jakobson14 3y agoRead the article in full. Timekeeping upgrades and cold-weather functionality are the flashy headlines that are easy to explain to the masses, but there's plenty in there about russian cyberattacks too. Russia has been attacking ukrane's infra over the internet for over a decade now.
- sgift 3y agoWell, as usual, the answer is a mix of cost and usability. I don't know if people outside of Germany remember it, but there was a big splash when it came out the NSA hacked Merkels phone. Our chancellor! Why doesn't she have a secure phone?! What do our security authorities even do?! Well, the thing is .. she had one. And it probably wasn't hacked. But the usability of these secure phone is so bad (one common thing is that everyone needs one, which has to be compatible with each other) that she usually just used the phone that her party gave her (she was also the head of the party), which was a normal smartphone and the NSA hacked this one. Same goes for switches etc. There are no real standards, everyone does a bit of their own thing, so you have a bunch of incompatibility. Then you need to configure them special, which takes more time and effort and so on. And, at the end of the day, there's always the matter of cost. Resisting cyber attacks means probably different chips, which are safe according to e.g. https://en.wikipedia.org/wiki/Tempest_(codename) https://en.wikipedia.org/wiki/Tempest_(codename), and the software has to be checked extra and programmed to different standards. Someone has to pay for this, simple as that. Also, if you are not the US, the US will probably want to have a say in whether Cisco can sell you such machines. Same goes for other companies and their countries.
- jakobson14 3y agoYou are vastly over-estimating the competence of both cisco and the russian hackers https://www.csoonline.com/article/656427/over-40000-cisco-devices-exploited-with-the-latest-zero-day-vulnerability.html https://www.csoonline.com/article/656427/over-40000-cisco-de...
- Veserv 3y agoNo, these systems are not secure in any configuration. There are exactly zero large scale commercial IT companies that can deploy systems that can protect against commercially-motivated criminal attackers let alone well-funded intelligence agencies. These companies do not have any super secret secure smartphones, or super secret secure routers, or super secret secure configurations. They are all just plain easily hacked, routinely get hacked, and the government agencies and companies using them get ransacked regularly. Companies such as Cisco, Microsoft, Apple, etc. are just systemically incapable of deploying or even developing secure systems. They have no knowledge or expertise in that field and for their employees to develop that knowledge would take both prioritization and years to decades of learning and experimentation.
- marcus0x62 3y agoThere aren’t any systems that are “secure” or “not secure” in the abstract anywhere in existence. Every system has strengths and weaknesses and is suitable for some purposes and not others, depending on your threat model. It is perfectly possible to use products from each of the vendors you mentioned to build a high assurance system. It depends on what you build, how you configure it, and what threats you are trying to protect against. The non-commercial/open source world isn’t exactly a bastion of impeccable security practice, either. You can counter every Solar Winds or Double Pulsar anecdote with a Heartbleed or Log4J anecdote. But, if you look behind the headlines of every major breach, for every 1 company that got popped by a zero-day, 99 got popped by either social engineering or improper configuration/outdated software. Why do they have poor configs and outdated software? They’re short-staffed and can’t make changes due to fear of outages. That’s a business culture problem, not a technology problem. > Companies such as Cisco, Microsoft, Apple, etc. are just systemically incapable of deploying or even developing secure systems. They have no knowledge or expertise in that field and for their employees to develop that knowledge would take both prioritization and years to decades of learning and experimentation. Each of these vendors employs many widely known and respected security researchers. I’ll grant their product teams can be hit or miss, but to say they have no security expertise at all is just false.
- peblos 3y agoThat's true but reading the article in full (again), nowhere does it say what other special features have been added that other companies might require Even in the referenced article from The Register there’s no mention. Lots more context of the types of threats being faced, but no additional features beyond time keeping and better reliability at low temperature.
- asynchronous 3y agoThat’s the right question about Cisco you should be asking.
- whatshisface 3y agoThe absolute minimum tin that delivered three people to the moon and return them safely to Earth could have been destroyed by a fault in almost any of its innumerable subsystems and components. It was very much a detail-oriented endeavor and set the standard for unit and integration testing for decades, maybe even up through the present.
- thedaly 3y agoIn regards to this specific case, because it is expensive and unnecessary. Cisco’s response involved shipping a large order of modified equipment, specifically designed to maintain accurate time even under radio jamming conditions. This solution employs the Cisco Industrial Ethernet switch with an internal crystal oscillator, enabling new clock recovery algorithms for accurate timekeeping when GPS is unavailable. These modified versions of the Cisco Industrial Ethernet 5000 series switches, tested and stress-tested in Cisco’s Austin, Texas lab, were sent to Ukrenergo. The project, which cost around $1 million, was supported by the Pentagon, the U.S. Department of Energy, and the Department of Commerce in terms of logistics and coordination. Cisco provided the equipment free of charge.
- jakobson14 3y agoRead the article again, or better yet do a ctrl-f for the word "cyber" https://www.csoonline.com/article/656427/over-40000-cisco-devices-exploited-with-the-latest-zero-day-vulnerability.html https://www.csoonline.com/article/656427/over-40000-cisco-de... With how shit cisco's security is and how badly they're having their ass handed to them, you'd think they could roll out any cybersecurity "hardening" in their special ukraniuan firmware to other models.
- thedaly 3y agoRead my comment again. I wasn't making any claims outside of the fact that it would be expensive and unnecessary to implement anti-gps blocking features unless you expect to experience GPS blocking.
- marcus0x62 3y agoSo you want to pay for a high accuracy local time source in every single Ethernet switch and router and wireless controller…in case the Russians disrupt GPS over one of your locations? Most Cisco customers: 1) Do not directly use a GPS time clock in their network. They use an NTP-based source that is ultimately timed by someone else’s GPS clock. 2) Do not want to pay for extra hardware they will not use 3) Do not need their network equipment certified to -34C, or want to pay for a device that would work in such conditions.
- jakobson14 3y agoRead the article again, or better yet do a ctrl-f for the word "cyber" https://www.csoonline.com/article/656427/over-40000-cisco-de https://www.csoonline.com/article/656427/over-40000-cisco-de... With how shit cisco's security is and how badly they're having their ass handed to them, you'd think they could roll out any cybersecurity "hardening" in their special ukraniuan firmware to other models.
- marcus0x62 3y agoI read it. But given your response, I think you didn't. There are two, and only two, specific mitigations mentioned in the article: high accuracy local time sources and low temperature certification. If you think you read about something else, feel free to quote it in reply, but we both know that isn't going to happen because it doesn't exist. If you think, based on the article, that Cisco shipped private security mitigations to Ukraine apart from the timekeeping algorithm, that's something you have hallucinated out of whole cloth. There is no basis for it in the linked article, and it has no precedent anywhere in their 38 year history as a company. Also, you managed to spell "Ukrainian" incorrectly and link to an article that 404s. Good job, or something.
- twelve40 3y ago> resisting cyberattack What cyberattack uses GPS jamming? This is just dumb journos trying to spice up the article. The Register's article says this is a side effect from trying to jam missile guidance systems. Probably by their own EW systems while defending from a missile or a shahed strike.
- asynchronous 3y agoI’ve yet to see “AI-assisted” attack techniques that are outside of the typical social engineering generation, can you give any examples of AI actually developing novel techniques for zero days or being used for that?
- fgoesbrrr 3y agoIt's about scale and speed, not novel attacks. Also exploitation. An AI could determine much faster what might be worth stealing reducing mitigation time.
- mensetmanusman 3y agoSoon, your entire org will be turing tested weekly over text, audio, and video, and one mistake will result in access to your network.
- sgift 3y ago"We only have to be lucky once. You have to be lucky every time." has never felt more true than now.
- nradov 3y agoThis is why zero-trust security architectures are now essential. You have to assume that some parts of your network are always going to be penetrated. https://www.nist.gov/publications/zero-trust-architecture https://www.nist.gov/publications/zero-trust-architecture
- Logans_Run 3y agoThe trouble is that it has always been a case of "Backdoors for me but not for thee" rather than backdoor free. And as for the price - I was surprised at the cost stated when even a quick search turned up various RTC modules for as low as 0.50p/$0.50 per module which I'm sure could be obtained (in bulk) for a lot less. Ah well, I guess I just don't understand big business and geo-politics.
- stephen_g 3y agoRTCs are only in the tens to hundreds of millions of parts per million accuracy per day, they’re talking crystals so we’re probably talking parts like OCXOs with three or four or more orders of magnitude better accuracy/stability (even down to less than 1ppb per day). Still these parts are only around one hundred to a couple of hundred dollars per unit, depending on specs, but the bulk of the cost was likely the NRE of hardware design (you actually need to interface these things in, which means board design etc.) and all the software development. In relatively small quantity electronics, BOM cost is a tiny fraction of the cost of anything.
- deleted 3y ago[deleted]
- andrewmutz 3y agoIf there was funding available to build secure systems, do we know how to do it? If we rebuilt everything from scratch today, what would we do differently?
- fbdab103 3y agoAt minimum, we should have open source hardware/software for network infrastructure. None of this closed source Cisco gear where they keep leaving embedded root passwords. I would love to see a proven sel4 microkernel used for more network appliances. C/C++ seem like obvious mistakes at this point given the industry's inability to write secure code. Rust/Ada or any GC language would be appropriate.
- nradov 3y agoYou're not wrong about the security issues. But competitive pressures make open-source hardware impossible in the high-end networking market. There are only a few remaining competitors, and since they consider their proprietary hardware designs to be a competitive advantage, they will never release them. Open-source hardware and software can potentially be a viable option in the low-end market, but it won't have the same efficiency or maximum performance.
- fbdab103 3y agoHigh end is going to remain state-of-the-art designs, but for 95%+ of consumers, they would be fully satisfied with a one gigabyte router/switch. I just did a search for 2013 routers (ie 10 year old designs) and gigabyte routers were already available then. While there might be more efficient implementations today, it seems like this level of hardware should be possible to create in an open way today. Today it could be consumer 1G routers. Tomorrow that could encroach on the 10G market or 50 port switches.
- deleted 3y ago[deleted]
- er4hn 3y agoThat is a goal of the government. EO 14028 makes the biden administration the first to take cybersecurity seriously. The problems are two fold: - An attacker only has to get lucky once. You have to do the right thing everytime. and - It's not clear you didn't do the right thing until it's too late. It's possible to a much better job of cybersec than we're doing today, but everything today is such a hodgepodge of "It works, it barely works, onto the next thing" that it's hard to do so. Developers can barely be expected to write documentation, getting people to routinely do static and dynamic analysis on their code is going to be a high bar to get over.
- Kalium 3y agoIt's a good idea! I like where your head is at. Apollo and other historic moonshot programs were fundamentally striving to match some set of fixed natural forces with human ingenuity. The conditions to be met and overcome were measurable and knowable. They were natural-world challenges, bristling with natural-world problems. Vacuum, radiation, lunar regolith. The sound barrier, the Polio virus, and more. Unfortunately, this is in sharp contrast to the challenges of security. Information security is an adversarial, human-centered enterprise. The forces with which we contend, armed with human ingenuity, are themselves armed with the same. It becomes a question of resources and economics. Even the cryptography on which so much relies is ultimately a question of how much breaking it is worth. If we are willing to spend enough, we can probably make it too expensive to successfully attack a system. Plus, we know that the weakest leak in any system is generally the humans involved. With all this in mind, we cannot possibly expect to build systems with zero vulnerabilities. It's not a moonshotable goal. What we can do - and what a mature security program will help you do - is plan for detecting, containing, mitigating, and recovering from attacks.
- Veserv 3y agoThose are the talking points of the people who got us into this mess who have been systemically incapable of deploying or even developing secure systems. There is no absolutely reason to listen to the liars who have repeatedly promised secure systems while being utterly incapable of doing so for literal decades. The task is not impossible, the commercial vendors like Cisco, Google, Microsoft, Amazon, Apple, etc. are just incompetent at security and are trying to poison the well by claiming that it is impossible just because they can not do it. If you want to know what actual high security development looks like you can just look to Orange Book Level A1 certified systems and Common Criteria EAL 6/7 certified systems. Systems designed for high security with formal specifications, robust documentation, exhaustive testing, thorough review, spotless penetration testing by well-funded intelligence agencies, formal proofs of correctness, and proven deployment in high criticality settings. The Common Criteria SKPP literally required the NSA to fail a multi-month penetration test while having the full source code, internal documentation, and formal specification. These commercial vendors believe protecting against state actors is literally impossible even though it has already been demonstrated in front of their faces for decades. Nothing they say about security is useful because they know nothing about what is needed to make systems that are actually secure.