5 ms·
Author here - if you have any questions, please do let me know!
by ahubert 2y ago
Author here - if you have any questions, please do let me know!
- wyldberry 2y agoNo questions, but as a security person, I found this to be aligned with the view of many of the people i consider to have a good pulse on the warfare side of security. You're certainly not alone in these thoughts and efforts to fix.
- nonrandomstring 2y agoVery good. Well said and most enjoyable.
- skybrian 2y agoThis is off topic, but I’m idly curious about the history of shipbuilding regulatory changes after the Titanic. Where did Brenno de Winter learn about them?
- auct 2y agoWhat were the vulnerabilities in your 1600 lines imgur alternative?
- ahubert 2y agohttps://github.com/berthubert/trifecta/blob/main/README.md#known-problems https://github.com/berthubert/trifecta/blob/main/README.md#k... has a list. The most painful one for me is that I did not know .svg files can contain javascript that gets executed in the site context if you can get someone to click on a link to your .svg file!
- softsound 2y agoThat's one of the reasons SVG is often a third party plug-in with WordPress it's because of all the security involved.
- yread 2y agoCSP would help against that. But at that time alpine.js was incompatible with CSP... Anyone tried using the new csp alpine.js build? https://laravel-news.com/alpinejs-csp https://laravel-news.com/alpinejs-csp
- RGamma 2y agoGood to see there's still some people vouching for old-school programming virtues. Among all the capital-driven centralization, scaling and complexification dominating the conversation I thought I was going crazy...
- mike_hearn 2y agoYou talked a lot about how bad it is for governments to outsource stuff to Huawei and a handful of US clouds, but didn't really touch on what drive all those decisions beyond claiming it's due to non-technical leadership. It'd be great to see a somewhat deeper analysis than that in future. There are plenty of tech companies that also outsource a lot to the cloud, so it has to be more complicated than that, and there are European mini-clouds that don't get much love from European governments also. The basic problem is fundamental: outsourcing is a very common thing you find in all walks of life, it is often the most reasonable choice due to comparative advantage. This is the reason I eventually gave up on "decentralization" as a worthwhile technical goal (after years spent working on Bitcoin). Everyone is trying to outsource everything that isn't their key competitive advantage, and that's because specialization is the heart of progress. The costs of centralization are obvious in terms of loss of resiliency, but when people aren't actually needing that resiliency for entire lifetimes it's hard to convince anyone to take the loss of progress that decentralization may appear to entail. So what to do? As you found with your 1,600 line imgur alternative just starting over to make stuff be secure is ... hard. You wrote in C++ (not the most security conscious choice) and some of those vulnerabilities are very basic, like the one where you discover that due to a bug some users are getting empty passwords. You also sort of assume that your users will keep your app up to date, but we know they won't. So simply demanding programs be smaller isn't going to work. You'll just speedrun the history of vulnerabilities. Indeed, one reason to outsource stuff to a handful of giant providers is that they do a much better job of security overall. Yeah Microsoft may have problems with Chinese hackers, but government IT routinely has problems with greedy teenagers. So MS is still ahead of the pack. IMO the most critical thing is really whole-systems analysis to find sources of unnecessary complexity and fix it. That won't necessarily turn the tide, but it can at least help. As a trivial example, HTTP stacks don't understand the concept of load balancing. They're still stuck in a world where every website is run by a single computer. That entails a lot of server-side complexity like dedicated LBs, maybe even DNS LB, replicated databases, health checks, drain periods etc just to avoid users seeing little dinosaurs due to normal maintenance. The complexity of this is overwhelming. When users accepted things like "This service will be offline on Sunday due to maintenance" you could get away with it but now people expect everything to be 24/7, so that complexity drives people to the cloud where it's somewhat handled for them. Thus an obvious quick win - extend HTTP and DNS to understand IP address globbing and maybe even static route matching. If a connection to a server fails, have the stack transparently fail over to another one. Now you can scrap your server side LBs and reverse proxies but still have an HA service.
- sublimefire 2y agoAs an SWE I do agree somewhat with what you say but this story is not complete. If you look at the attacks on Ukraine and the cybersecurity damage done it was fairly small in the grand scheme of things. Another important thing is that Microsoft helped them to fight back as well, so it was not a terrible investment. Was there any quantifiable risk assessment done to understand the potential damages if Russians carried out similar attacks in the Netherlands?
- dralley 2y ago> As an SWE I do agree somewhat with what you say but this story is not complete. If you look at the attacks on Ukraine and the cybersecurity damage done it was fairly small in the grand scheme of things. It's worth mentioning that the most expensive and extensive malware attack in history was caused by one of such Russian cyberattacks hitting systems which (at the time) they weren't intended to. Causing severe shipping delays and billions of dollars in damage. https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/ https://www.wired.com/story/notpetya-cyberattack-ukraine-rus... If such attacks were intentional, you could cause much worse problems. For example, doing this https://www.cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years https://www.cisa.gov/news-events/news/attack-colonial-pipeli... except without offering a ransom fee to undo the damage, and doing it in parallel across more industries.
- sweetjuly 2y agoWhy don't we see these attacks though? I know they're worryingly practical and the West certainly has enough enemies (especially from extremist groups who don't have the same peace keeping concerns as a nation state), and yet we don't see groups just sabotaging critical infrastructure and businesses left and right. Is it really just difficulty/a lack of skill?
- dralley 2y agoI mean, we do and have, they just haven't yet been explicitly targeted at critical infrastructure. When they hit critical infrastructure, it has been more of an accident, that gets papered over by just paying the ransom (because it was a financially motivated attack) or the US government getting sufficiently pissed off to intervene directly state-to-state (which kinda happened with the Colonial Pipeline one in 2021). If the attacks were targeted, were destructively motivated instead of financially motivated, there was no "kill switch", government threats ceased to work, etc... it'd be pretty bad.
- time0ut 2y agoFirst, thank you for the article and discussion. Do you have any thoughts on the role and practicality of deterrence in this space?
- ahubert 2y agoNo, not really - however, based on this post, several people contacted me with questions like these. I asked around and got recommended https://www.amazon.co.uk/Cyber-Persistence-Theory-Redefining-Cyberspace-ebook/dp/B09YHZ4X3X https://www.amazon.co.uk/Cyber-Persistence-Theory-Redefining... for a more theoretical basis. Haven't read it yet though.
- time0ut 2y agoInteresting. I will have to read it. Though from the description it does not sound hopeful. Thank you.
- baxtr 2y agoIs there a video version of this available?
- ahubert 2y agoSadly no - but the transcript is near verbatim.
- dkek 2y agoNot a question. However as a fellow european, having worked for large "national/eu important companies", this article resonated a lot with me and my frustrations. Granted I don't do anything "security" related. Everything in "it infrastructure" has been outsourced to India, at best Poland. You have competent people in eu offices that don't have the power to use their own hardware. You have to beg for weeks to barely skilled ticket masters from outsourcing companies, endless meetings. All eu staff is relegated to feature factories or process managers. Zero ops. "It's not our core competency." I refuse to ever again work for the large "of national security" european companies. It's soul crushing. And it is very clear nobody cares. It hurts me everytime I read how tens of billions are allocated for whatever EU soverignity. I have been in way too many 10 managers 2 engineers teams with way too many long meetings begging teams from $indian_outsourcing_company to let me do my job.
- halletr 2y agoExcellent talk. Thank you for highlighting risks, and explaining the need for robust infrastructure with clear, vivid images. Our systems need communicators like you. There is one story I would like to clarify. The transcript says > there were 4,000 wind turbines that could no longer be operated. I tried to learn more about this. What I have found differs in some key details, suggesting that the turbines did stay in operation, and that the number was 5,800 turbines, not 4,000. What was lost appears to be the ability to do remote monitoring and remote control. https://cyberconflicts.cyberpeaceinstitute.org/law-and-policy/cases/viasat https://cyberconflicts.cyberpeaceinstitute.org/law-and-polic... Can you comment on these differences? It's worth resolving them, as I will definitely be sharing your transcript with other people.
- Havoc 2y agoIs there an audio recording of this available?
- dopylitty 2y agoIf you ever give this talk in the US you can mention the fact that apparently US farmers are unable to farm without GPS[0] Surely it's no problem that their food supply depends entirely on a finicky and easily jammed system of satellites. 0: https://www.404media.co/solar-storm-knocks-out-tractor-gps-systems-during-peak-planting-season/ https://www.404media.co/solar-storm-knocks-out-tractor-gps-s...