3 ms·
The thing that's security theater isn't encrypting at rest in general. The thing that's security theater is encrypting insecurely, or failing to authenticate y
by CiPHPerCoder 2y ago
The thing that's security theater isn't encrypting at rest in general.
The thing that's security theater is encrypting insecurely, or failing to authenticate your access patterns, such that an attacker with privileged access to your database hardware can realistically get all the plaintext records they want.
- indymike 2y ago>> The thing that's security theater isn't encrypting at rest in general > The thing that's security theater is encrypting insecurely Security theater should be defined as: Doing things that outwardly appear to improve security but have de minimus or less effect on actual security. The 93 section questionnaire from bigco's IT department is security theater. Filling it out does zero to improve security for bigco or myco or my users.
- CiPHPerCoder 2y ago> Doing things that outwardly appear to improve security but have de minimus or less effect on actual security. Right. And that's exactly the situation the article describes. The accusation of "security theater" was only levied when IT departments reached for the "full disk encryption" potion to mitigate the ailment of "attacker has active, online access to our database via SQL injection", when that's not at all what it's designed to prevent. They can insist that they're "encrypting their database", but does it actually matter for the threats they're worried about? No. Thus, security theater. The same is true of insecure client-side encryption.
- PeterisP 2y agoIDK, I have multiple times seen significant practical security improvements as a direct consequence of some "93 section questionnaire" because the very first section had a few questions "Are you doing this simple, well-known best practice thing?", which they were not, because it took some time, effort and/or money and they just didn't care. But once the questionnaire mattered, they started doing it just so they could legally answer "yes" to that question. Things like finally changing the default admin passwords on that service they installed a year ago, and testing backup recovery to find out that it actually can't be done due to a bug in the backup script skipping some key data.
- ozim 2y agoI do agree, well my boss would most likely never allow me to spend time on security until he got hit by "93 section questionnaire" from big co. Once contract with big co was on the line I got permission to do security and do it good. Even though 80% of questionnaire was not applicable it still did the good job.