4 ms·
> Defense in depth is an idea that has probably done about as much harm as it's done good Citation needed?
by dataflow 2y ago
> Defense in depth is an idea that has probably done about as much harm as it's done good
Citation needed?
- tptacek 2y agoI'm not going to give you a citation. Historically, "defense in depth" has been a way to inoculate security tooling from critique or even assessment; things don't need to work at all in a "defense in depth" regime, because you can always say there's some marginal "fail2ban"-level utility to any countermeasure and retain it on that basis. It has in cases prevented meaningful defenses from being deployed, and has crudded up lots of people's attack surfaces. You see this most clearly in endpoint security, where "defense in depth" loaded everyone up with security and AV agents that were all riddled with memory corruption vulnerabilities.
- kibwen 2y agoBoth of the following can be true simultaneously: 1. The term "defense in depth" can be popularly abused by irresponsible people looking to pass the buck on security. 2. An application that is intended to withstand being exposed to the public internet becomes strictly more secure when it isn't exposed to the public internet. I can buy that the government contractors who fall into the former category are sufficiently numerous and sufficiently gormless that this memo is intended to be used as a weapon to drag them kicking and screaming towards default-secure applications. But for people who are already responsible enough that they're doing the right thing, keep using a VPN. Redundancy is resiliency.
- ethbr1 2y agoThe problem is you can't simultaneously say "secure things via network access" AND "ensure everything has strong auth" -- invariably that collapses to the easier/cheaper of the two. So the superior realpolitik approach is to mandate the latter and remain silent about the former. Best case, they'll do both. Worst case, at least now they do the important one.
- tptacek 2y agoThe idea behind the OMBZT memo is that, in the OMB's setting, concealing applications with VPNs made them less secure: at a large enough scale, it becomes inevitable that an attacker in any threat model is going to get on the other side of the VPN. One reason half the industry nodded along with that observation is that anyone who's ever done a site-wide pentest knows that the pentest is about to go explosively game-over as soon as someone finds an SSRF and pivots into the perimeter. People contract out "internal" pentests, where attackers start with a VPN connection, but they only do it to make a point to management: "we're fucked". People on message boards massively overindex on the "VPN" term in the memo. You can readily do a BeyondTrust-style individually-authenticated security architecture using VPN technology. The underlying theme is 1:1 user:app authentication.
- dataflow 2y ago> You see this most clearly in endpoint security, where "defense in depth" loaded everyone up with security and AV agents that were all riddled with memory corruption vulnerabilities There's no way you can seriously argue AVs have caused remotely as much damage as they've mitigated or prevented. Especially not without any kind of citation to back it up. > It has in cases prevented [...] A lot of things go wrong "in cases". In cases, governments give poor recommendations. In cases, HN users give nonsensical opinions. In cases, police end up killing civilians instead of criminals. In cases, criminals go free because they refuse to testify against themselves. I could go on, but you could use this kind of argument to dismantle just about anything you don't like. Especially when you absolve yourself of the need to provide any kind of evidence of the relative harms.
- tptacek 2y agoNot only do I argue that, but it's a banal argument among security practitioners.
- dataflow 2y ago> Not only do I argue that, but it's a banal argument among security practitioners. Well that's great to know. Do all security practitioners also believe whatever they hear from each other without question? Or do they only expect us mortals to treat them that way?
- tptacek 2y agoIf you're not a practitioner and you'd like to learn things, I recommend asking questions, rather than saying "citation needed".
- freeone3000 2y agoHave you heard a similar argument to “we don’t need authentication to this application because it’s only accessible on the VPN”? It allows some pretty sloppy thoughts about security. Treating apps as if they were public is correct because the damage is more likely to be done with someone who already has access.
- dataflow 2y ago> Have you heard a similar argument to “we don’t need authentication to this application because it’s only accessible on the VPN”? Not personally. I've only read anecdotes like these online. But that's not even the point. People make stupid arguments about everything all the time. Have you heard a similar argument to "We don't need regulation because the market will take care of it"? Surely you don't hear that and conclude "let's get rid of the market"? (Or, I guess this is HN, so maybe you do...)
- deleted 2y ago[deleted]