19 ms·
The six dumbest ideas in computer security (2005)
- jrm4 2y agoMissed the most important. "You can have meaningful security without skin-in-the-game." This is literally the beginning and end of the problem.
- lsb 2y agoDefault permit, enumerating badness, penetrate and patch, hacking is cool, educating users, action is better than inaction
- Etheryte 2y agoI think commenting short summaries like this is not beneficial on HN. It destroys all nuance, squashes depth out of the discussion, and invites people to comment solely on the subtitles of a full article. That's not the kind of discussion I would like HN to degrade into — if I wanted that, I'd go to Buzzfeed. Instead I hope everyone takes the time to read the article, or at least some of the article, before commenting. Short tldrs don't facilitate that.
- smokel 2y agoAs much as I agree with this, I must admit that it did trigger me to read the actual article :) I assume that in a not-so-distant future, we get AI powered summaries of the target page for free, similar to how Wikipedia shows a preview of the target page when hovering over a link.
- deleted 2y ago[deleted]
- arcbyte 2y agoWhile i agree with all the potential downsides you mentioned, i still lean heavily on the side of short summaries being extremely helpful. This was an interesting title, but having seen the summary and discussion, im not particularñy keen to read it. In fact i would never have commented on this post except to reputation yours.
- omoikane 2y agoLooks like lsb was the one who submitted the article, and this comment appears to be submitted at the same time (based on same timestamp and consecutive id in the URL), possibly to encourage people to read the article in case if the title sounded like clickbait.
- chuckadams 2y agoOne one hand I agree, on the other is that the article itself is pretty much a bunch of grumpy and insubstantial hot takes …
- gnabgib 2y ago(2015) Previous discussions: 2015 (114 points, 56 comments) https://news.ycombinator.com/item?id=8827985 https://news.ycombinator.com/item?id=8827985 2023 (265 points, 202 comments) https://news.ycombinator.com/item?id=34513806 https://news.ycombinator.com/item?id=34513806
- philipwhiuk 2y agoFrom the 2015 submission: > Perhaps another 10 years from now, rogue AI will be the primary opponent, making the pro hackers of today look like the script kiddies. Step on it OpenAI, you've only got 1 year left ;)
- umanghere 2y ago> 4) Hacking is Cool Pardon my French, but this is the dumbest thing I have read all week. You simply cannot work on defensive techniques without understanding offensive techniques - plainly put, good luck developing exploit mitigations without having ever written or understood an exploit yourself. That’s how you get a slew of mitigations and security strategy that have questionable, if not negative value.
- blablabla123 2y agoThat. Also not educating users is a bad idea but it also becomes quite clear that the article was written in 2005 where the IT/security landscape was a much different one.
- crngefest 2y agoI concur with his views on educating users. It’s so much better to prevent them from doing unsafe things in the first place, education is a long and hard undertaking and I see little practical evidence that it works on the majority of people. >But, but, but I really really need to do $unsafething No in almost all cases you don’t - it’s just taking shortcuts and cutting corners that is the problem here
- blablabla123 2y agoThe attacks with the biggest impact are usually social engineering attacks though. It can be as simple as shoulder surfing, tailgating or as advanced as an AI voice scam. Actually these are widely popularized since the early 90s by people like Kevin Mitnick
- TacticalCoder 2y agoI don't think the argument is that dumb. For a start there's a difference between white hack hackers and dark hat hackers. Then here he's talking specifically about people who do pentesting known exploits on broken systems. Think about it this way: do you think Theo Deraadt (from OpenBSD and OpenSSH fame) spends his time trying to see if Acme corp is vulnerable to OpenSSH exploit x.y.z, which has been patched 3 months ago? I don't care about attacking systems: it is of very little interest to me. I've done it in the past: it's all too easy because we live in a mediocre work full of insecure crap. However I love spending some time making life harder for dark hat hackers. We know what creates exploits and yet people everywhere are going to repeat the same mistakes over and over again. My favorite example is Bruce Schneier writing, when Unicode came out, that "Unicode is too complex to ever be secure". That is the mindset we need. But it didn't stop people using Unicode in places where we should never have used it, like in domain names for examples. Then when you test an homoglyphic attack on IDN, it's not "cool". It's lame. It's pathetic. Of course you can do homglyphic attacks and trick people: an actual security expert (not a pentester testing known exploits on broken configs) warned about that 30 years ago. There's nothing to "understand" by abusing such exploit yourself besides "people who don't understand security have taken stupid decisions". OpenBSD and OpenSSH are among the most secure software ever written (even if OpenSSH had a few issues lately). I don't think Theo Deraadt spends his time pentesting so that he can be able to then write secure software. What strikes me the most is the mediocrity of most exploits. Exploits that, had the software been written with the mindset of the person who wrote TFA, would for the most part not have been possible. He is spot on when he says that default permit and enumerate badness are dumb ideas. I think it's worth trying to understand what he means when he says "hacking is not cool".
- iandanforth 2y agoAnd yet the consequence of letting people like this run your security org is that it takes a JIRA ticket and multiple days, weeks, never to be able to install 'unapproved' software on you laptop. Then if you've got the software you need to do your job you're stuck in endless cycles of "pause and think" trying to create the mythical "secure by design" software which does not exist. And then you get hacked anyway because someone got an email (with no attachments) telling them to call the CISO right away, who then helpfully walks them through a security "upgrade" on their machine. Caveats: Yes there is a balance and log anomaly detection followed by actual human inspection is a good idea!
- strangecharm2 2y ago[flagged]
- dale_glass 2y ago"We're Not a Target" isn't a minor dumb. It's the standpoint of every non-technical person I've ever met. "All I do with my computer is to read cooking recipes and upload cat photos. Who'd want to break in? I'm boring." The best way I found to change their mind is to make a car analogy. Who'd want to steal your car? Any criminal with an use for it. Why? Because any car is valuable in itself. It can be sold for money. It can be used as a getaway vehicle. It can be used to crash into a jewelry shop. It can be used for a joy ride. It can be used to transport drugs. It can be used to kill somebody. A criminal stealing a car isn't hoping that there are Pentagon secrets in the glove box. They have an use for the car itself. In the same way, somebody breaking into your computer has uses for the computer itself. They won't say no to finding something valuable, but it's by no means a requirement.
- jampekka 2y agoA major dumb is that security people think breaking in is the end of the world. For vast majority of users it's not, and it's a balance between usability and security. I know it's rather easy to break through a glass window, but I still prefer to see outside. I know I could faff with multiple locks for my bike, but I rather accept some risk for it to be stolen for the convenience. If there's something I really don't want to risk stolen, I can take it into a bank's vault. But I don't want to live in a vault.
- deleted 2y ago[deleted]
- dale_glass 2y ago> A major dumb is that security people think breaking in is the end of the world. For vast majority of users it's not, and it's a balance between usability and security. End of the world? No. But it's really, really bad. When you get your stolen car back, problem over. But your broken into system should in most cases be considered forever tainted until fully reinstalled. You can't enumerate badness. That the antivirus got rid of one thing doesn't mean they didn't sneak in something it didn't find. You could be still a DoS node, a CSAM distributor, or a spam sender.
- oschvr 2y ago> "If you're a security practitioner, teaching yourself how to hack is also part of the "Hacking is Cool" dumb idea." lol'd at the irony of the fact that this was posted here, Hacker News...
- smokel 2y agoAt the risk of stating the obvious, the word "hacker" has (at least) two distinct meanings. The article talks about people who try to break into systems, and Hacker News is about people who like to hack away at their keyboard to program interesting things. The world might have been a better place if we used the terms "cracker" and "tinkerer" instead.
- jrm4 2y agoDoubt it; it's utterly naive and wishful thinking to think that those two things are easily separable; it's never as simple as Good Guys wear White, Bad Guys wear Black, which is the level of intelligence this idea operates at.
- smokel 2y agoIt might be naive, but I'm not the only one in using this distinction. See the "Definitions" section of https://en.wikipedia.org/wiki/Hacker https://en.wikipedia.org/wiki/Hacker
- strangecharm2 2y ago[flagged]
- moring 2y ago> Think about it for a couple of minutes: teaching yourself a bunch of exploits and how to use them means you're investing your time in learning a bunch of tools and techniques that are going to go stale as soon as everyone has patched that particular hole. No, it means that you learn practical aspects alongside theory, and that's very useful.
- move-on-by 2y agoI also took issue with this point. One does not become an author without first learning how to read. The usefulness of reading has not diminished once you publish a book. You must learn how known exploits work to be able to discover unknown exploits. When the known exploits are patched, your knowledge of how they occurred has not diminished. You may not be able to use them anymore, but surely that was not the goal in learning them.
- Sohcahtoa82 2y agoNot necessarily. There are a lot of script kiddies that don't know a damn thing about what TCP is or what an HTTP request looks like, but know how to use LOIC to take down a site.
- dvfjsdhgfv 2y ago> The cure for "Enumerating Badness" is, of course, "Enumerating Goodness." Amazingly, there is virtually no support in operating systems for such software-level controls. Really? SELinux and AppArmor have existed since, I don't know, late nineties? The problem is not that these controls don't exist, it's just they make using your system much, much harder. You will probably spent some time "teaching" them first, then actually enable, and still fight with them every time you install something or make other changes in your system.
- ivlad 2y ago> You will probably spent some time "teaching" them first SELinux works well out of the box in RHEL and its derivatives since many years. You comment shows, you did not actually try it. > fight with them every time you install something or make other changes in your system If you install anything that does not take permissions into account, it will break. Try running nginx with nginx.conf permissions set to 000, you will not be surprised, it does not work.
- dvfjsdhgfv 2y agoI'm glad SELinux works better than in the past and at the same time I'm sorry it didn't from the start as many people were frustrated by it at that time (e.g. [0]). On the other hand, it looks like some people still get upset by it[1]. [0] https://news.ycombinator.com/item?id=13398582 https://news.ycombinator.com/item?id=13398582 [1] https://www.ctrl.blog/entry/selinux-unmanageable.html https://www.ctrl.blog/entry/selinux-unmanageable.html
- zepolen 2y ago[flagged]
- kazinator 2y agoPenetrate and Patch is a useful exercise, because it lets the IT security team deliver some result and show they have value, in times when nothing bad is happening and everyone forgets they exist.
- jeffrallen 2y agomjr (as I always knew him from mailing lists and whatnot) seems to have given up on security and enjoys forging metal instead now. > Somewhere in there, security became a suppurating chest wound and put us all on the treadmill of infinite patches and massive downloads. I fought in those trenches for 30 years – as often against my customers (“no you should not put a fork in a light socket. Oh, ow, that looks painful. Here, let me put some boo boo cream on it so you can do it again as soon as I leave.”) as for them. It was interesting and lucrative and I hope I helped a little bit, but I’m afraid I accomplished relatively nothing. Smart guy, hope he enjoys his retirement.
- lobsang 2y agoMaybe I missed it, but I was surprised there was no mention of passwords. Mandatory password composition rules (excluding minimum length) and rotating passwords as well as all attempts at "replacing passwords" are inherintly dumb in my opinion. The first have obvious consequences (people writing passwords down, choosing the same passwords, adding 1) leading to the second which have horrible / confusing UX (no I don't want to have my phone/random token generator on me any time I try to do something) and default to "passwords" anyway. Please just let me choose a password of greater than X length containing or not containing any chachters I choose. That way I can actually remember it when I'm not using my phone/computer, in a foreign country, etc.
- belinder 2y agoMinimum length is dumb too because people just append 1 until it fits
- rekabis 2y agoI would love to see most drop-in/bolt-on authentication packages (such as DotNet’s Identity system) to adopt “bitwise complexity” as the only rule: not based on length or content, only the mathematical complexity of the bits used. KeePass uses this as an estimate of password “goodness”, and it’s altered my entire view of how appropriate any one password can be.
- Terr_ 2y agoIIRC the key point there is that it's contextual to whatever generation method scheme you used--or at least what method you told it was used--and it assumes the attacker knows the generation scheme. So "arugula" will score is very badly in the context of a passphrase of English words, but scores better as a (supposedly) random assortment of lowercase letters, etc.
- jamesfinlayson 2y agoI'm told that at work we're not allowed to have the same character appear three or more times consecutively in a password (I have never tried).
- cwbrandsma 2y agoPenatrate and Patch: because if it doesn’t work the first time then throw everything away, fire the developers, hire new ones, and start over completely.
- Zak 2y agoI'd drop "hacking is cool" from this list and add "trusting the client". I've seen an increase in attempts to trust the client lately, from mobile apps demanding proof the OS is unmodified to Google's recent attempt to add similar DRM to the web. If your network security model relies on trusting client software, it is broken.
- strangecharm2 2y agoIt's not about security, it's about control. Modified systems can be used for nefarious purposes, like blocking ads. And Google wouldn't like that.
- Zak 2y agoIt's about control for Google and friends. If your bank's app uses SafetyNet, it's probably about some manager's very confused concept of security.
- account42 2y ago> If your bank's app uses SafetyNet, it's probably about some manager's very confused concept of security. Or about making the auditor for the government-imposed security certification happy with the least amount of effort. It's always more work to come up with good answers why you are not doing the industry standard thing.
- Zak 2y agoIt only became a standard practice because of a misguided desire to rely on trusting the client.
- billy99k 2y agoThis is a mostly terrible 19-year old list. Here is an example: "Your software and systems should be secure by design and should have been designed with flaw-handling in mind" Translation: If we lived in a perfect world, everything would be secure from the start. This will never happen, so we need to utilize the find and patch technique, which has worked well for the companies that actually patch the vulnerabilities that were found and learn from their mistakes for future coding practices. The other problem is that most systems are not static. It's not release a secure system and never update it again. Most applications/systems are updated frequently, which means new vulnerabilities will be introduced.
- CookieCrisp 2y agoI agree, an example that if you say something dumb with enough confidence a lot of people will think it's smart.
- dartos 2y agoThe CTO at my last company was like this. In the same breath he talked about how he wanted to build this “pristine” system with safety and fault tolerance as priority and how he wanted to use raw pointers to shared memory to communicate between processes which both use multiple threads to read/write to this block of shared memory because he didn’t like how chatty message queues are. He also didn’t want to use a ring buffer since he saw it as a kind of lock
- SoftTalker 2y agoThat sounds pretty deep in the weeds for a CTO. Was it a small company?
- dartos 2y agoIt was. I was employee number 10. Just started and was entirely bankrolled by that CTO The CTO sold a software company he bootstrapped in 2008 and afaik has been working as an exec since. The CEO, a close friend of Mr CTO, said that the system was going to be Mr CTO’s career encore. (Read: they were very full of themselves) The CIO quit 4 days before I started for, rumor has it, butting heads with the CTO. Mr CTO ended up firing (with no warning) me and another dev who were vocal about his nonsense. (Out of 5 devs total) A 3rd guy quit less than a month after. That’s how my 2024 started
- CM30 2y agoI think the main problem is that there's usually an unfortunate trade off between usability and security, and most of the issues mentioned as dumb ideas here come from trying to make the system less frustrating for your average user at the expense of security. For example, default allow is terrible for security, and the cause of many issues in Windows... but many users don't like the idea of having to explicitly permit every new program they install. Heck, when Microsoft added that confirmation, many considered it terrible design that made the software way more annoying to use. 'Default Permit', 'Enumerating Badness' and 'Penetrate and Patch ' are all unfortunately defaults because of this. Because people would rather make it easier/more convenient to use their computer/write software than do what would be best for security. Personally I'd say that passwords in general are probably one of the dumbest ideas in security though. Like, the very definition of a good password likely means something that's hard to remember, hard to enter on devices without a proper keyboard, and generally inconvenient for the user in almost every way. Is it any wonder that most people pick extremely weak passwords, reuse them for most sites and apps, etc? But there's no real alternative sadly. Sending links to email means that anyone with access to that compromises everything, though password resets usually mean the same thing anyway. Physical devices for authentication mean the user can't log in from places outside of home that they might want to login from, or they have to carry another trinket around everywhere. And virtually everything requires good opsec, which 99.9% of the population don't really give a toss about...
- bpfrh 2y agomeh passwords where a good idea for a long time. The first 10(20?) years there where no devices without a good keyboard. The big problem imho was the idea that passwords had to be complicated and long, e.g. a random, alpanumeric, some special chars and at least 12 characters long, while a better solution would have been a few words. Edit: To be clear I agree with most of your points about passwords, just wanted to point out that we often don't appreciate how much tech changed after the smartphone introduction and that for the environemnt before that (computer/laptops) passwords where a good choice.
- CM30 2y agoThat's a fair point. Originally devices generally had decent keyboards, or didn't need passwords. The rise of not just smartphones, but tablets, online games consoles, smart TVs, smart appliances, etc had a pretty big impact on their usefulness.
- tonnydourado 2y agoI've seen "Penetrate and Patch" play out a lot on software development in general. When a new requirement shows up, or technical debt starts to grow, or performance issues, the first instinct of a lot of people is to try and find the smallest, easiest possible change to achieve the immediate goal, and just move to the next user story. That's not a bad instinct by itself, but when it's your only approach, it leads to a snowball of problems. Sometimes you have to question the assumptions, to take a step back and try to redesign things, or new addition just won't fit, and the system just become wonkier and wonkier.
- mrbluecoat 2y ago> sometime around 1992 the amount of Badness in the Internet began to vastly outweigh the amount of Goodness I'd be interested in seeing a source for this. Feels a bit anecdotal hyperbole.
- julesallen 2y agoIt's a little anecdotal as nobody was really writing history down at that point but it feels about the right timing. The first time the FTP server I ran got broken into was about then, it was a shock as why would some a-hole want to do that? I wasn't aware until one of my users tipped me off a couple of days after the breach. They were sharing warez rather than porn at least, having the bandwidth to download even crappy postage stamp 8 bit color videos back then would take you hours. When this happened I built the company's first router a few days later and put everything behind it. Before that all the machines that needed Internet access would turn on TCP/IP and we'd give them a static IP from the public IP range we'd secured. Our pipe was only 56k so if you needed it you had to have a really good reason. No firewall on the machines. Crazy, right? Very different times for sure.
- strangecharm2 2y ago[flagged]
- al2o3cr 2y agoMy guess is that this will extend to knowing not to open weird attachments from strangers. I've got bad news for ya, 2005... :P
- kstrauser 2y agoHacking is cool. Well, gaining access to someone else's data and systems is not. Learning a system you own so thoroughly that you can find ways to make it misbehave to benefit you is. Picking your neighbor's door lock is uncool. Picking your own is cool. Manipulating a remote computer to give yourself access you shouldn't have is uncool. Manipulating your own to let you do things you're not suppose to be able to is cool. That exploration of the edges of possibility is what make moves the world ahead. I doubt there's ever been a successful human society that praised staying inside the box.
- janalsncm 2y agoWe can say that committing crimes is uncool but there’s definitely something appealing about knowing how to do subversive things like pick a lock, hotwire a car, create weapons, or run John the Ripper. It effectively turns you into a kind of wizard, unconstrained by the rules everyone else believes are there.
- kstrauser 2y agoWell put. There’s something inherently cool in knowledge you’re not suppose to have.
- jay_kyburz 2y agoYou have to know how to subvert existing security in order to build better secure systems. You _are_ supposed to know this stuff.
- kstrauser 2y agoSome people think we shouldn’t because “what if criminals also learn it?” Uh, they already know the best techniques. You’re right: you and I need to know those things, too, so we can defend against them.
- Sohcahtoa82 2y agoAnd sometimes, knowing that information is useful for legit scenarios. When my grandma was moving across the country to move in with my mom, she got one of those portable on-demand storage things, but she put the key in a box that got loaded inside and didn't realize it until the POD got delivered to my mom's place. I came over with my lock picks and had it open in a couple minutes.
- teleforce 2y agoThis article is quite old and has been submitted probably every year since it's published with past submissions well into double pages. For modern version and systematic treatment of the subject check out this book by Spafford: Cybersecurity Myths and Misconceptions: Avoiding the Hazards and Pitfalls that Derail: https://www.pearson.com/en-us/subject-catalog/p/cybersecurity-myths-and-misconceptions-avoiding-the-hazards-and-pitfalls-that-derail/P200000007269/9780137929153 https://www.pearson.com/en-us/subject-catalog/p/cybersecurit...
- nottorp 2y ago> #4) Hacking is Cool Hacking is cool. Why the security theater industry has appropriated "hacking" to mean accessing other people's systems without authorization, I don't know.
- Kamq 2y ago> Why the security theater industry has appropriated "hacking" to mean accessing other people's systems without authorization, I don't know. A lot of early remote access was done by hackers. Same with exploiting vulnerabilities. One of my favorite is the Robin Hood worm: https://users.cs.utah.edu/~elb/folklore/xerox.txt https://users.cs.utah.edu/~elb/folklore/xerox.txt TL;DR: Engineers from Motorola exploited a vulnerability illustrate it, and they did so in a humorous way. Within the tribe of hackers, this is pretty normal, but the only difference between that and stealing everything once the vulnerability has been exploited is intent. Normies only hear about the ones where people steal things. They don't care about the funny kind.
- kstrauser 2y agoFrom Britannia: https://www.britannica.com/topic/hacker https://www.britannica.com/topic/hacker > Indeed, the first recorded use of the word hacker in print appeared in a 1963 article in MIT’s The Tech detailing how hackers managed to illegally access the university’s telephone network. I get what you’re saying, but I think we’re tilting at windmills. If “hacker” has a connotation of “breaking in” for 61 years now, then the descriptivist answer is to let it be.
- nottorp 2y agoOhh here it is: https://www.catb.org/~esr/faqs/hacker-howto.html https://www.catb.org/~esr/faqs/hacker-howto.html
- supertrope 2y agoIf owners are able to tweak or upgrade the machine themselves, it will hurt sales of next year’s model. If “hacking” helped corporations make money they would spend billions promoting it. The old meaning of hacking has been replaced with “maker.”
- jibe 2y ago"We're Not a Target" deserves promotion to major.
- dasil003 2y agoI was 5 years into a professional software career when this was written, at this point I suspect I'm about the age of the author at the time of its writing. It's fascinating to read this now and recognize the wisdom coming from experience honed in the 90s and the explosion of the internet, but also the cultural gap from the web/mobile generation, and how experience doesn't always translate to new contexts. For instance, the first bad idea, Default Permit, is clearly bad in the realm of networking. I might quibble a bit and suggest Default Permit isn't so much an idea as the natural state of when one invents computer networking. But clearly Default Deny was a very very good idea and critical idea necessary for the internet's growth. It makes a lot of sense in the context of global networking, but it's not quite as powerful in other security contexts. For instance, SELinux has never really taken off, largely because it's a colossal pain in the ass and the threat models don't typically justify the overhead. The other bad idea that stands out is "Action is Better Than Inaction". I think this one shows a very strong big company / enterprise bias more than anything else—of course when you are big you have more to lose and should value prudence. And yeah, good security in general is not based on shiny things, so I don't totally fault the author. That said though, there's a reason that modern software companies tout principles like "bias for action" or "move fast and break things"—because software is malleable and as the entire world population shifted to carrying a smartphone on their person at all times, there was a huge land grab opportunity that was won by those who could move quickly enough to capitalize on it. Granted, this created a lot of security risk and problems along the way, but in that type of environment, adopting a "wait-and-see" attitude can also be an existential threat to a company. At the end of the day though, I don't think there's any rule of thumb for whether action vs inaction is better, each decision must be made in context, and security is only one consideration of any given choice.
- worik 2y agoThis true in a very small part of our business Most of us are not involved in a "land grab", in that metaphorical world most of us are past "homesteading " and are paving roads and I filling infrastructure Even small companies should take care when building infrastructure "Go fast and break things" is, was, an irresponsible bad idea. It made Zuck rich, but that same hubris and arrogance is bringing down the things he created
- michaelmrose 2y ago> Educating Users This actually DOES work it just doesn't make you immune to trouble any more than a flu vaccine means nobody gets the flu. If you drill shit into people's heads and coach people who make mistakes you can decrease the number of people who do dumb company destroying behaviors by specifically enumerating the exact things they shouldn't do. It just can't be your sole line of defense. For instance if Fred gives his creds out for a candy bar and 2FA keeps those creds from working and you educate and or fire Fred not only did your second line of defense succeed your first one is now stronger without Fred.
- AtlasBarfed 2y ago#1) Great, least secure privilege, oh wait, HOW LONG DOES IT TAKE TO OPEN A PORT? HOW MANY APPROVALS? HOW MANY FORMS? Least secure privilege never talks about how security people in charge of granting back the permissions do their jobs at an absolute sloth pace. #2) Ok, what happens when goodness becomes badness, via exploits or internal attacks? How do you know when a good guy becomes corrupted without some enumeration of the behavior of infections? #3) Is he arguing to NOT patch? #4) Hacking will continue to be cool as long as modern corporations and governments are oppressive, controlling, invasive, and exploitative. It's why Hollywood loves the Mafia. #5) ok, correct, people are hard to train at things they really don't care about. But "educating users", if you squint is "organizational compliance". You know who LOVES compliance checklists? Security folks. #6) Apparently, there are good solutions in corporate IT, and all new ones are bad. I'll state it once again: my #1 recommendation to "security" people is PROVIDE SOLUTIONS. Parachuting in with compliance checklists is stupid. PROVIDE THE SOLUTION. But security people don't want to provide solutions, because they are then REALLY screwed when inevitably the provided solution gets hacked. It's way better to have some endless checklist and shrug if the "other" engineers mess up the security aspects. And by PROVIDE SOLUTIONS I don't mean "offer the one solution for problem x (keystore, password management), and say fuck you if someone has a legitimate issue with the system you picked". If you can't provide solutions to various needs of people in the org, you are failing. Corporate Security people don't want to ENGINEER things, again they just want to make compliance powerpoints to C-suite execs and hang out in their offices.
- bawolff 2y ago> If you're a security practitioner, teaching yourself how to hack is also part of the "Hacking is Cool" dumb idea. Think about it for a couple of minutes: teaching yourself a bunch of exploits and how to use them means you're investing your time in learning a bunch of tools and techniques that are going to go stale as soon as everyone has patched that particular hole. I would strongly disagree with that. You can't defend against something you don't understand. You definitely shouldn't spend time learning some script-kiddie tool, that is pointless. You should understand how exploits work from first principles. The principles mostly won't change or at least not very fast, and you need to understand how they work to make systems resistant to them. One of the worst ideas in computer security in my mind is cargo culting - where people just mindlessly repeat practises thinking it will improve security. Sometimes they don't work because they have been taken out of their original context. Other times they never made sense in the first place. Understanding how exploits work stops this.
- strangecharm2 2y agoTrue security can only come from understanding how your system works. Otherwise, you're just inventing a religion, and doing everything on faith. "We're fine, we update our dependencies." Except you have no idea what's in those dependencies, or how they work. This is, apparently, a controversial opinion now.
- grahar64 2y ago"Educating users ... If it worked, it would have worked by now"
- ang_cire 2y agoIt does work, but user training is something that- whether for security or otherwise- is a continuous process. New hires. Training on new technologies. New operating models. etc etc etc... IT is not static; there is no such thing as a problem that the entire field solves at once, and is forever afterward gone. When you're training an athlete, you teach them about fitness and diet, which underpins their other skills. And you keep teaching and updating that training, even though "being fit" is ancillary to their actual job (i.e. playing football, gymnastics, etc). Pro athletes have full-time trainers, even though a layman might think, "well haven't they learned how to keep themselves fit by now?"
- woodruffw 2y agoSome of this has aged pretty poorly -- "hacking is cool" has, in fact, largely worked out for the US's security community.
- hot_gril 2y agoYeah, we're not gonna convince people in other countries that hacking is uncool. Better to have the advantage.
- janalsncm 2y ago> hacking is cool Hacking will always be cool now that there’s an entire aesthetic around it. The Matrix, Mr. Robot, even the Social Network.
- chha 2y ago> If you're a security practitioner, teaching yourself how to hack is also part of the "Hacking is Cool" dumb idea. Think about it for a couple of minutes: teaching yourself a bunch of exploits and how to use them means you're investing your time in learning a bunch of tools and techniques that are going to go stale as soon as everyone has patched that particular hole. If only this was true... Injection has been on Owasp Top 10 since its inception, and is unlikely to go away anytime soon. Learning some techniques can be useful just to do quick assessments of basic attack vectors, and to really understand how you can protect yourself.
- deleted 2y ago[deleted]
- tracerbulletx 2y agoHacking is cool.
- uconnectlol 2y ago> Please wait while your request is being verified... Speaking of snakeoil
- jojobas 2y ago>My prediction is that the "Hacking is Cool" dumb idea will be a dead idea in the next 10 years. 19 years later, hacking is still cool.
- mikewarot 2y agoMy "security flavor of the month" is almost universally ignored... Capability Based Security/Multilevel Secure Computing. If it's not ignored, it's mis-understood. It's NOT the UAC we all grew to hate with Windows 8, et al. It's NOT the horrible mode toggles present on our smartphones. It's NOT AppArmor. I'm still hoping that Genode (or HURD) makes something I can run as my daily driver before I die.
- zzo38computer 2y agoI also think that capability based security is a good idea, and that proxy capabilities should also be possible. (This would include all I/O, including measuring time.) But, how the UI is working with capability based security, is a separate issue (although I have some ideas). (Furthermore, I also think that capability based security with proxy capabilities can solve some other problems as well (if the system is designed well), including some that are not directly related to security features. It can be used if you want to use programs to do some things that it was not directly designed to do; e.g. if a program is designed to receive audio directly from a microphone, you can instead add special effects in between by using other programs before a program receives the audio data, or use a file on the computer instead (which can be useful in case you do not have a microphone), etc. It can also be used for testing; e.g. to test that a program works correctly on February 29 even if the current date is not February 29, or if the program does have such a bug, to bypass it by telling that program (and only that program) that the date is not February 29; and you can make fault simulations, etc.)
- deleted 2y ago[deleted]
- tptacek 2y agoWe're doing this again, I see. https://hn.algolia.com/?q=six+dumbest+ideas+in+computer+security https://hn.algolia.com/?q=six+dumbest+ideas+in+computer+secu... You can pick this apart, but the thing I always want to call out is the subtext here about vulnerability research, which Ranum opposed. At the time (the late 90s and early aughts) Marcus Ranum and Bruce Schneier were the intellectual champions of the idea that disclosure of vulnerabilities did more harm than good, and that vendors, not outside researchers, should do all of that work. Needless to say, that perspective didn't prove out. It's interesting that you could bundle up external full-disclosure vulnerability research under the aegis of "hacking" in 2002, but you couldn't do that at all today: all of the Big Four academic conferences on security (and, obviously, all the cryptography literature, though that was true at the time too) host offensive research today.
- ggm 2y agoMaybe they were right for their time? I'm not arguing that, I just posit that post fact rationalisation about decisions made in the past have to be considered against the evidence in the past. Things network exploded size-wise and the numbers of participants in the field exploded too.
- michaelt 2y agoIt was 100% a reasonable-sounding theory before we knew any better. In the real world if you saw someone going around a car park, trying the door of every car you'd call the cops - not praise them as a security researcher investigating insecure car doors. And in the imagination of idealists, the idea of a company covering up a security vulnerability or just not bothering to fix it was inconceivable. The problems were instead things like how to distribute the security patches when your customers brought boxed floppy disks from retail stores. It just turns out that in practice vendors are less diligent and professional than was hoped; the car door handles get jiggled a hundred times a day, the people doing it are untraceable, and the cops can't do anything.
- ericpauley 2y agoCompletely agree that offensive research has (for better or for worse) become a mainstay at the major venues. As a result, we’re continually seeing negative externalities from these disclosures in the form of active exploitation. Unfortunately vendors are often too unskilled or obstinate to properly respond to disclosure from academics. For their part academics have room to improve as well. Rather than the pendulum swinging back the other way, I anticipate that the majors will eventually have more involved expectations for reducing harm from disclosures, such as by expanding the scope of the “vendor” to other possible mitigating parties, like OS or Firewall vendors.
- rkagerer 2y ago#7 Authentication via SMS
- esjeon 2y ago> Educating Users isn't dumb, because "users" are proven to be the weakest link in the whole security chain. Users must be aware of the workplace security, just like how they should be trained w/ the workplace safety. Also, there's no security to deal with if the system is unusable by the users. The trade-off b/w usability and security is simply unsolvable, and education is a patch to that problem.
- dingody 2y agoI don’t entirely agree with the author’s viewpoint on “Hacking is Cool.” There was a time when I thought similarly, believing that “finding some system vulnerabilities is just like helping those system programmers find bugs, and I can never be better than those programmers.” However, I gradually rejected this idea. The appeal of cybersecurity lies in its “breadth” rather than its “depth.” In a specific area, a hacker might never be as proficient as a programmer, but hackers often possess a broad knowledge base across various fields. A web security researcher might simultaneously discover vulnerabilities in “PHP, JSP, Servlet, ASP.NET, IIS, and Tomcat.” A binary researcher might have knowledge of “Windows, Android, and iOS.” A network protocol researcher might be well-versed in “TCP/IP, HTTP, and FTP” protocols. More likely, a hacker often masters all these basic knowledge areas. So, what I want to say is that the key is not the technology itself, nor the nitty-gritty of offense and defense in some vulnerabilities, but rather the ability to use the wide range of knowledge and the hacker’s reverse thinking to challenge seemingly sound systems. This is what our society needs and it is immensely enjoyable.
- cratermoon 2y agoThe real dumbest idea in computer security is "we'll add security later, after the basic functionality is complete"
- Hendrikto 2y agoThis is full of very bad takes. > I know other networks that it is, literally, pointless to "penetration test" because they were designed from the ground up to be permeable only in certain directions and only to certain traffic destined to carefully configured servers running carefully secured software. ”I don‘t need to test, because I designed, implemented, and configured my system carefully.“ might be the actual worst security take I ever heard. > […] hacking is a social problem. It's not a technology problem, at all. This is security by obscurity. Also it‘s not always social. Take corporate espionage and nation states for example.
- Jean-Papoulos 2y ago>As a younger generation of workers moves into the workforce, they will come pre-installed with a healthy skepticism about phishing and social engineering. hahahahahaha
- voidUpdate 2y agoI'm not sure if I'm completely misunderstanding #4 or if it's wrong. Pentesting an application is absolutely a good idea, and its not about "teaching yourself a bunch of exploits and how to use them" in the same way programming isn't just "learning a bunch of sorting algorithms and how to use them". It's about knowing why an exploit works, and how it can be adapted to attack something else and find a new vulnerability, and then it goes back to the programming side of working out why that vulnerability works and how to fix it
- munchausen42 2y agoAbout 'Default Deny': 'It's not much harder to do than 'Default Permit,' but you'll sleep much better at night.' Great that you, the IT security person, sleeps much better at night. Meanwhile, the rest of the company is super annoyed because nothing ever works without three extra rounds with the IT department. And, btw., the more annoyed people are, the more likely they are to use workarounds that undermine your IT security concept (e.g., think of the typical 'password1', 'password2', 'password3' passwords when you force users to change their password every month). So no, good IT security does not just mean unplugging the network cable. Good IT security is invisible and unobtrusive for your users, like magic :)
- clwg 2y agoGood IT security isn't invisible; it's there to prevent people from deploying poorly designed applications that require unfettered open outbound access to the internet. It's there to champion MFA and work with stakeholders from the start of the process to ensure security from the outset. Mostly, it's there to identify and mitigate risks for the business. Have you considered that all your applications are considered a liability and new ones that deviate from the norm need to be dealt with on a case by case basis?
- darby_nine 2y agoI think the idea is that if you don't work with engineering or product, people will perceive you as friction rather than protection. Agreeing on processes to deploy new applications should satisfy both parties without restrictions being perceived as an unexpected problem.
- RHSeeger 2y agoBut it needs to be a balance. IT policy that costs tremendous amounts of time and resources just isn't viable. Decisions need to be made such that it's possible for people to do their work AND safety concerns are address; and _both_ of them need to compromise some. As a simplified example - You have a client database that has confidential information - You have some employees that _must_ be able to interact with the data in that database - You don't want random programs installed on a computer <that has access to that database> to leak the information You could lock down every computer in the company to not allow application installation. This would likely cause all kinds of problems getting work done. You could lock down access to the database so nobody has access to it. This also causes all kinds of problems. You could lock down access to the database to a very specific set of computers and lock down _those_ computers so additional applications cannot be installed on them. This provides something close to a complete lockdown, but with far less impact on the rest of the work. Sure it's stupidly simple example, but it just demonstrates the idea that compromises are necessary (for all participants)
- amelius 2y ago> "Let's go production with it now and we can secure it later" - no, you won't. A better question to ask yourself is "If we don't have time to do it correctly now, will we have time to do it over once it's broken?" I guess the idea is generally that if we go in production now we will make profits, and with those profits we can scale and hire real security folks (which may or may not happen).
- amelius 2y agoAlso needs mention: - Having an OS that treats users as "suspicious" but applications as "safe". (I.e., all Unix-like systems)
- vrighter 2y agoxdg-desktop-portal was created to allow applications running in a sandbox to access system resources. Nowadays, more and more, regular applications have to pass through this piece of crap to do their usual work, one which by design was never intended for them, but for flatpakked applications. Oh the joy of going through the bluetooth pairing process for my controller, or physically getting up and connecting a physical wire to it, only for the system to wait until I'm in the game and touch the controller and immediately the game hangs because a pop up appears asking me if i want to give permission to my damn controller to control stuff. Or having to manually reposition my windows every single time, because a window knowing where it is is somehow "insecure" I'm the one putting the software on there and deciding what to run. If I run it, then it's because I wanted the application to do what it does. If someone else is in the position of running software on my machine, they're already on the other side of the airtight hatchway. They can already give themselves the permissions they need. They can just click yes on any pop up that appears. Yes, the applications should be considered safe. Because the OS cannot possibly make any informed assumptions about what's legitimate and what's malicious. To me it feels like I can't do certain stuff on my PC because someone else might misuse something on theirs. How is that my problem?
- zzo38computer 2y ago> xdg-desktop-portal was created to allow applications running in a sandbox to access system resources. There are many problems with it; I do not use it on my computer. A better sandbox system would be possible, but xdg-desktop-portal is not designed very well. > Oh the joy of going through the bluetooth pairing process for my controller, or physically getting up and connecting a physical wire to it, only for the system to wait until I'm in the game and touch the controller and immediately the game hangs That is also a problem of a bad design. If a permission is required, it should be possible to set up the permissions ahead of time (and to configure it to automatically grant permission if you do not want to restrict it; possibly could even be the default setting), instead of waiting for that to ask you and to hang like that. > Or having to manually reposition my windows every single time, because a window knowing where it is is somehow "insecure" I would think that the window manager should know where the windows are and automatically position them if you have configured it to remember where they are. (The windows themself should not usually need to know where they are, since the window manager would handle it instead, and the applications should not need to know what window manager is in use, since different window managers will work in different ways and if the application program assumes it knows how it works then that can be a problem.) > I'm the one putting the software on there and deciding what to run. If I run it, then it's because I wanted the application to do what it does. Yes, although sometimes you do not want it to do what it does, which is why it should be possible to configure the security, preferably with proxy capabilities. > Because the OS cannot possibly make any informed assumptions about what's legitimate and what's malicious. I agree, although that is why it must be possible for the operator to specify such things. I think that proxy capabilities would be the way to be done (which, in addition to improving security, also allows more control over the interaction between the programs and other parts of the system). > To me it feels like I can't do certain stuff on my PC because someone else might misuse something on theirs. Yes, it seem like that, because it is the badly design of some programs, protocols, etc.
- Arch-TK 2y ago> #3) Penetrate and Patch This is one of the reasons why I feel my job in security is so unfulfilling. Almost nobody I work with really cares about getting it right to begin with, designing comprehensive test suites to fuzz or outright prove that things are secure, using designs which rule out the possibility of error. You get asked: please look at this gigantic piece of software, maybe you get the source code, maybe it's written in Java or C#. Either way, you look at <1% of it, you either find something seriously wrong or you don't[0], you report your findings, maybe the vendor fixes it. Or the vendor doesn't care and the business soliciting the test after purchasing the software from the vendor just accepts the risk, maybe puts in a tissue paper mitigation. This approach seems so pointless that it's difficult to bother sometimes. edit: > #4) Hacking is Cool I think it's good to split unlawful access from security consultancy. You don't learn nearly as much about how to secure a system if you work solely from the point of view of an engineer designing a system to be secure. You can get much better insight into how to design a secure system if you try to break in. Thinking like a bad actor, learning how exploitation works, etc. These are all things which strictly help. [0]: It's crazy how often I find bare PKCS#7 padded AES in CBC mode. Bonus points if you either use a "passphrase" directly, or hash it with some bare hash algorithm before using various lengths of the hash for both the key and IV. Extra bonus points if you hard code a "default" password/key and then never override this in the codebase.
- regularfry 2y agoIt's very easy for a big organisation with a leadership that needs to show it is doing something to pass down a mandate that relies on throwing money at the problem for little tangible benefit. "Everything needs to be pen tested" is the sort of thing that sounds like the right thing to do if you don't understand the problem space; it's exactly as wrong as using lines of code as a productivity metric. All it does is to say, very expensively, "there are no obvious vulnerabilities". If it even manages that. What you want to say is "there are obviously no vulnerabilities" but if you're having to strap that onto a pre-existing bucket of bugs then it's a complete rebuild. And nobody has time for that when there's an angry exec breathing down your neck asking why the product keeps getting hacked. The fundamental problem is the feature factory model of software development. Treating software design and engineering as a cost to be minimised means that anything in the way of getting New Shiny Feature out of the door is Bad. And that approach, where you separate product design from software implementation, where you control what happens in the organisation with budgetary controls and the software delivery organisation is treated as subordinate because it is framed as pure cost, drives the behaviour you see.
- ricktdotorg 2y agoit's 2024! if you run your own infrastructure in your own DC and your defaults are NOT: - to heavily VLAN via load type/department/importance/whatever your org prefers - default denying everything except common infra like DNS/NTP/maybe ICMP/maybe proxy arp/etc between those VLANs - every proto/port hole poked through is a security-reviewed request then you are doing it wrong. "ahh but these ACL request reviews take too long and slow down our devs" -- fix the review process, it can be done. spend the time on speeding up the security review, not on increasing your infrastructure's attack surface.
- motohagiography 2y agowhat has changed since 2005 is that these ideas are no longer dumb, but describe the factors of the dynamic security teams have to manage now. previously, security was an engineering and gating problem when systems were less interdependent and complex, but now it's a policing and management problem where there is a level of pervasive risk that you find ways to extract value from. I would be interested in whether he still thinks these are true, as if you are doing security today, you are doing exactly these things. - educating users: absolutely the most effective and highest return tool available. - default permit: there are almost no problems you can't grow your way out of. there are zero startups, or even companies, that have been killed by breaches. - enumerating badness: when managing a dynamic, you need measurements. there is never zero badness, that's what makes it valuable. the change in badness over time is a proxy for the performance of your organization. - penetrate and patch: having that talent on your team yields irreplacable expereince. the only reason most programmers know about stacks and heaps today is from smashing them. - hacking is cool: 30 years later, what is cooler, hacking or marcus?
- kuharich 2y agoPast comments: https://news.ycombinator.com/item?id=28068725 https://news.ycombinator.com/item?id=28068725
- trey-jones 2y agoMost security-oriented articles are written by extremely security-minded people. These people in my experience ignore the difficulties that a purely security-oriented approach imposes on users of the secure software. I always present security as a sliding scale. On one end "Secure", and on the other "Convenient". Purely Secure software design will almost never have any users (because it's too inconvenient), and purely Convenient software design will ultimately end up the same (because it's not secure enough). That said, this is a good read for the most part. I heavily, heavily disagree with the notion that trying to write exploits or learn to exploit certain systems as a security professional is dumb (under "Hacking is C00L"). I learned more about security by studying vulnerabilities and exploits and trying to implement my own (white hat!) than I ever did by "studying secure design". As they say, "It takes one to know one." or something.
- delusional 2y ago> These people in my experience ignore the difficulties that a purely security-oriented approach imposes on users Your scale analogy is probably more approachable, but I'm a little more combative. I usually start out my arguments with security weenies with something along the lines of "the most secure thing would be to close up shop tomorrow, but we're probably not going to get sign-off on that." After we've had a little chuckle at that, we can discuss the compromise we're going to make. I've also had some luck with changing the default position on them by asserting that if they tell me no, then I'll just do it without them, and it'll have whatever security I happen to give it. I can always find a way, but they're welcome to guide me to something secure. I try to avoid that though, because it tends to create animosity.