7 ms·
CISA directs federal agencies to disconnect Ivanti products by Friday midnight
- t3rabytes 3y agoMore info in a directive from 1/14/24, https://www.cisa.gov/news-events/directives/ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure-vulnerabilities https://www.cisa.gov/news-events/directives/ed-24-01-mitigat...: > CISA has observed widespread and active exploitation of vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure solutions, hereafter referred to as “affected products.” Successful exploitation of the vulnerabilities in these affected products allows a malicious threat actor to move laterally, perform data exfiltration, and establish persistent system access, resulting in full compromise of target information systems.
- nonrandomstring 3y ago> Agencies running the affected products must assume domain accounts associated with the affected products have been compromised. This looks like a right shitshow. Ross Anderson did a big group research "The Changing Cost of Cybercrime" [0]. I forget the number but it came out at several trillion. After Solarwinds and the UK Horizon Post Office scandal I am wondering, how does cybercrime compare against simple incompetence and hopelessly broken software engineering? How can we measure that to see just how bad things really are? [0] https://weis2019.econinfosec.org/wp-content/uploads/sites/6/2019/05/WEIS_2019_paper_25.pdf https://weis2019.econinfosec.org/wp-content/uploads/sites/6/...
- 1oooqooq 3y agoquestion is cyclical because cyber crime doesn't exist without incompetence. There's very little cyber crime that happens by bribing someone. Most of it is just walking past an open door. > How can we measure that to see just how bad things really are? hence, cost of incompetence = cost of all cybercrime + n.
- rainclouds 3y agoCyber crime definitely exists without incompetence. Defense is a costly vast landscape compared to attacking. Sure incompetence causes issues and major drives my blood pressure, but the problem doesn’t go away if incompetence goes away.
- worik 3y ago> Defense is a costly vast landscape compared to attacking Yes. But. There are many defensive tactics that are not free but are cheap. Keeping system software updated is one https://infosec.exchange/@wdormann/111880313720252008 https://infosec.exchange/@wdormann/111880313720252008
- sublinear 3y ago> There's very little cyber crime that happens by bribing someone If competence was the norm the bribes, violence, etc. become the preferred tactics
- nonrandomstring 3y agoThis is a really excellent point. Someone on Bruce Schniere's site noted that about the Anderson study... that the increase in cyber-crime perfectly tracks the decrease in street crime. As online fraud goes up, robberies go down. If crime remains a constant then having shitty software security is a safety valve - and fixing computer security means physical crime would rise again. Interesting hypothesis.
- lbatx 3y agoThis sort of implies the street criminals become cyber criminals, which seems to not be a matching skill set. Call me skeptical of the study I admittedly haven't read.
- nonrandomstring 3y ago> This sort of implies the street criminals become cyber criminals, Does it? I never considered that. It seems obvious to me that they aren't the same actual people. We have more EV cars on the road displacing ICE vehicles, but that doesn't imply that the old cars "transformed" into electric ones.
- wannacboatmovie 3y agoIs this the same legacy product which used to be Pulse which used to be Juniper which used to be Netscreen?
- sam_lowry_ 3y agoYes
- deleted 3y ago[deleted]
- riffic 3y agoisn't it ironic how crapware sold in the name of "security" effectively increases your attack surface?
- batch12 3y agoBy definition, everything installed increases your attack surface. The decision to use it or not should be a risk-based one considering the value of what you get from using the product against the additional exposure. Having a single, properly secured and managed VPN appliance is much better than many unmanaged or kinda-managed entry points into a network.
- josephcsible 3y agoIt's not VPN vs. no VPN. It's crapware like Ivanti and Zscaler vs. sane things like OpenVPN and WireGuard.
- batch12 3y agoMaybe I've missed it (very likely), is there an enterprise-grade product that allows easy management of WireGuard or OpenVPN for say 20-30k users/endpoints and that integrates easily with Active Directory and a centralized MFA provider? Do these products provide support agreements? To be fair, I have no love for Ivanti or Zscaler, but I do understand why companies choose them over some standalone, open source products.
- formerly_proven 3y ago[flagged]
- nimbius 3y agoso far no word on ivantis website about the CVE or exploit, or even a fix. forcing CISA to walk out of the gate with a nuclear-option mitigation is pretty insulting to the corporations/governments that spend millions on this hokum each year to achieve certification or ATO. then again SolarWinds was effectively crucified before their customers and somehow --unaccountably-- still manages to hold a 4.5 in the gartner ratings and enjoys widespread use still to this day in government and private industry. it feels like security certification at this level is mostly a performative art.
- ecshafer 3y agoMost Government and Corporate security / IT just aren't some awesome hacker or security analyst. Most just follow some corporate flow chart for security. I once worked at a company that allowed IE only as a browser for security reasons, eventually they allowed Chrome, but not Firefox again for security reasons, their reasoning was: Microsoft and Google are Billion dollar companies. If you try and bring some solid open source software, well where is the X certification? Even though just from using the corporate certified software for 10 seconds you can tell its not good.
- nonrandomstring 3y ago> their reasoning was: Microsoft and Google are Billion dollar companies. Did you ever see that written down. Or was it an assumption or rumour? I ask because I specifically advise against that thinking and debunk the "big company = trustworthy" fallacy. But what I find is that actually there is appropriate low trust of US big-tech amongst the C level, but they are compelled to use Microsoft or whatever for non-technical/non-security reasons.
- AvocadoPanic 3y agoThe list of 'approved' software vendors doesn't say it's because their billion dollar companies, but if it's from a company on the list that's enough. No further vetting required.
- IHEARTANAL 3y agoAh, again Ivantis. Just like on 12/2023 and after. "support your local ransomware group"
- egberts1 3y agoWhat is Ivanti Secure Access? it is where you make administrative changes/adjustments for user access. it sits on your edge and controls what users connect to on the lan. the "ivanti secure access client" is the client-side software used to create a vpn/l4 connection to the corporate network via the appliance (physical or virtual)