5 ms·
There aren't even any poor security practices. It's just security theatre and the DOC is overreacting.
by lima 3y ago
There aren't even any poor security practices. It's just security theatre and the DOC is overreacting.
- demondemidi 3y agoThe article said the default admin password wasn’t changed. Thats not security theater that’s a legit goof. Why so cynical?
- zogrodea 3y agoIt does sound very much like an overreaction, from the manufacturer of these devices. "The man who made the devices said there’s little someone inside could actually do with a hacked Securebook. They’d need to fashion a USB port, be able to install another operating system, and get access to a docking station, said Jeremy Schwartz, Justice Tech president. Even when the devices are docked, they’re not connected to the wider internet. "
- oofbey 3y agoWhen a critical part of a security system is defeated, saying “that’s okay we have other layers of security so they probably can’t do much” would be IMHO pretty horrible security practice. Taking the laptops away is horrible, but from a security perspective it’s not over reacting.
- SargeDebian 3y agoAssessing the balance between risk and the cost of mitigation sounds like it should be part of the basics.
- demondemidi 3y agoEh, true. But then both sides of the political spectrum would have been up their asses had they just said, "relax, its no big deal." Not something you want to hear from a prison (even a not-for-profit prison).
- striking 3y agoIt doesn't even help you get to the end of the exploit chain. To boot anything they still needed to tap the touchpad USB lines and attach preimaged external USB storage. It's a goof but it's not a goof worth making 1200 incarcerated people's lives harder.
- pcthrowaway 3y agoWhy is it so bad to let prisoners have internet access or unrestricted access to a device anyway? Sure, they can commit crimes with it. But prisons obviously don't care about their charges committing crimes or they would take serious measures to prevent violence.
- tyingq 3y agoThe bios password is known now, and you can't change it locally. Security practices aside, it does sound like collecting them and doing an update is required.
- baobabKoodaa 3y agoThe secure boot password was stored as a SHA-1 hash. The machine was designed in a way that the password effectively can not be changed. Those are poor security practices.
- oofbey 3y agoThese devices must now all be treated as if they’re rooted. That’s a gigantic security problem. Casual analysis here says “well it would be hard to install a new OS, so it’s not a big deal.” That is a terrible security assumption. We don’t know what other changes could be done to a rooted device, but anybody with a sensible security mindset would assume something undesirable is possible. So, the outcome might be harsh, but it is NOT overreacting to promptly deal with secure devices becoming easily rooted.