6 ms·
Someting I’ve been thinking about, esp since that crowdstrike debacle. Why do major distributors of infrastructure (msft in case of crowdstrike, DHS/TSA here) n
by preciousoo 2y ago
Someting I’ve been thinking about, esp since that crowdstrike debacle. Why do major distributors of infrastructure (msft in case of crowdstrike, DHS/TSA here) not require that vendors with privileged software access have passed some sort of software distribution/security audit? If FlyCASS had been required to undergo basic security testing, this (specific) issue would not exist
- bronco21016 2y agoMoney. Eventually the lobbyists would make it so cumbersome to get the certification that only the defense industry darlings would be able to do anything. Look at Boeing Starliner for an example of how they run a “budget”.
- vips7L 2y agoIn the case of msft/crowdstrike isn't this exactly the opposite of what HN rallies against? The users installed crowdstrike on their own machines. Why should microsoft be the arbiter of what a user can do to their own system?
- preciousoo 2y agoMicrosoft determines who they give root access signing keys to
- snarfy 2y agoBecause the EU required them to.
- preciousoo 2y agoI’ve read that story, it inspired my question. Such a requirement wouldn’t be out of bounds with the regulation
- advael 2y agoThey automatically occupy that position because in practice no user of a microsoft system can audit the entire "supply chain" of that system, unlike one built from open-source components. Any "control" someone has over "their own" system is ultimately incomplete when there is a company that owns and controls the operating system itself and has the sole power to both fix and inspect it
- Dalewyn 2y ago>no user of a microsoft system can audit the entire "supply chain" of that system, Yes you can, you can access the source code to audit it. https://en.wikipedia.org/wiki/Shared_Source_Initiative https://en.wikipedia.org/wiki/Shared_Source_Initiative
- woodruffw 2y agoThey often do. The value of those kinds of blanket security audits is questionable, however. (This is one of the reasons I'm generally pro-OSS for digital infrastructure: security quickly becomes a compliance game at the scale of government, meaning that it's more about diligently completing checklists and demonstrating that diligence than about critically evaluating a component's security. OSS doesn't make software secure, but it does make it easier for the interested public to catch things before they become crises.)
- deepsun 2y agoWell, the value is ok, if considered seriously. Also, any certificate bears a certificator company name. We can always say "company A was hacked despite having its security certified by company B". So that company B at least share some blame.
- ethbr1 2y agoIn practice, most commercial attestations/certifications contain enough weasel language that the certifier isn't responsible for anything missed (i.e. reasonable effort only). But yes, there are many standards for this (e.g. SOC Type 2 reports). In defense of their utility, the good ones tend to focus on (a) whether a control/policy for a sensitive operation exists at all in the product/company & (b) whether those controls implemented are effectively adhered to during an audited period.
- r00fus 2y agoWe're talking about getting a judgement in the court of public opinion not a court of law, and no one is exempt from the former.
- ipaddr 2y agoMany live in a special labelled class that cannot be criticized
- AmericanChopper 2y ago
- sandworm101 2y agoThey do. But market forces have pushed the standards down. Once upon a time a "pen test team" was a bunch of security ninjas that showed up at your office and did magic things to point out security flaws you didn't know were even a thing. Now it is a online service done remotely by a machine running a script looking for known issues.
- b112 2y ago"I made my fortune with nmap, you can too."
- ethbr1 2y agoGreat, now my YouTube recommendations are also on HN...
- advael 2y agoUnfortunately we're in kind of the worst of all possible worlds here too. Not only do we want to "automate" these kinds of tests, but governments have bought into the "security through obscurity" arguments of tech giants, so the degree to which these automations can even be meaningfully improved is gated in practice by whoever owns the tech itself approving of some auditor (whether automated or human) even looking at it. The author of this article takes the serious risk of retaliation by even looking into this
- paulddraper 2y agoOf course they require that. Now, why wasn't the requirement enforced? Or why didn't the audit turn this up? Good questions. But all of those are going to have some kind of requirement, e.g. FedRAMP.
- preciousoo 2y agoGood to know, didn’t know this program existed, but makes a lot of sense that it does. Why it wasn’t enforced is an incredibly huge question now
- niklasrde 2y agoPart of the reason why Crowdstrike have access, why MS wasn't allowed to shut them out with Vista was a regulatory decision, one where they argued that somebody needs to do the job of keeping Windows secure in a way that biased Microsoft can't. So, I guess you could have some sort of escrow third party that isn't Crowdstrike or MS to do this "audit"? Or see this for a much better write up: https://stratechery.com/2024/crashes-and-competition/ https://stratechery.com/2024/crashes-and-competition/
- preciousoo 2y agoReplied in another comment, but I’m aware of the regulation that made msft give access. To my knowledge though, there’s nothing in the regulation that stops them from saying “you have to pass xyz (reasonable) tests before we allow you to distribute kernel level software to millions of people”
- immibis 2y agoSo, all companies must gatekeep like Apple? By law?
- not2b 2y agoMS could have provided security hooks similar to BPF in Linux, and similar mechanisms with Apple, rather than having Crowdstrike run arbitrary buggy code at the highest privilege level.
- IcyWindows 2y agoCrowdstrike configured Windows to not start if their driver could not run successfully. That's not the default option for kernel drivers on Windows, so this was an explicit choice on Crowdstrike's part.
- cratermoon 2y agoThey could have, however the timeline the regulators gave Microsoft to comply was incompatible with the amount of work required to build such system. With a legal deadline hanging over their heads Microsoft chose to hand over the keys to their existing tools.
- cratermoon 2y agoOh they usually do require some kind of proof of security certification. However the checkbox audits to get those certs and the kinds of solutions employed to allow them to check off the boxes are the real problem.
- edm0nd 2y agoI do believe that is the point of having things like FedRAMP and StateRAMP. Your company must meet said requirements to become a vendor for certain agencies or even be able to submit an RFP for governmental agencies.
- indymike 2y agoSigh. The company is a different problem than the product. Sally in accounting who has pii on her desk is a totally different problem than that the team that wrote insecure code 15 years ago.
- astura 2y agoI've delivered software to the US government. My software has always been required to undergo security auditing.