13 ms·
CISA boss: Makers of insecure software are the real cyber villains
- boomboomsubban 2y agoThat is rich coming from a former NSA Tailored Access Operations agent. She had no problems paying companies to release insecure software, including some that have signed the "secure by design" pledge.
- davisr 2y agoThat is important context, but I still agree with what she's said in this article. It's also rich that Cisco especially -- a company known for hard-coding backdoors into their products for decades -- is "taking a pledge" to do better.
- boomboomsubban 2y agoI agree that software should often get more tests to improve security. I don't think supporting companies that sign a meaningless pledge improves anything and I question her motives in trying to shame people who use companies that have not signed this pledge.
- rockskon 2y agoSo I'm aware she worked for the NSA but this is the first I'm hearing of her working for TAO. I had thought she worked at the NSA's IAD (defensive side) pre-merge of the offensive and defensive sides.
- keepamovin 2y agoI see it as the opposite: as ex Deputy Head of TAO Easterly is no retard. And there's a difference between defective software that leads to vulns exploited by crime gangs and NOBUS backdoors that the good guys use to keep you safe. Sounds bullshit, right? That's how far the public discourse on cyber has diverged from the reality, which is part of the issue. Easterly's push for renaming cyber actors and flaws is smart. Bad quality comes from mindset, attitude. And names are important, as programmers should know! :) I would prefer it if she had a GitHub profile tho. Always cool if you do that.
- croes 2y agoI think NSA and CISA have different objectives.
- rawgabbit 2y ago>"We don't have a cyber security problem – we have a software quality problem. We don't need more security products – we need more secure products." Uhmmm. The foundation of a lot of the modern economy is built on Windows and the Crowdstrike fiasco has shown, Windows requires a security software to save it from itself by running at the kernel level. If we truly want secure products, we should shutdown all Windows machines?
- davisr 2y ago> If we truly want secure products, we should shutdown all Windows machines? There should be a period where you put a question mark.
- juunpp 2y agoPrecisely.
- lmz 2y agoCrowdstrike also provided software for Linux systems. It's something you install to satisfy auditors and they would demand the same of any OS unless such functionality was built-in.
- idle_zealot 2y agoRunning the world's critical infrastructure on verified, small, readable codebases rather than a diaspora of unvetted closed-source programs sprinkled across Windows and Linux systems sounds like a good start.
- sublinear 2y agoWhat a joke. This role deserves way better, but I understand it's only been around since 2018.
- acdha 2y agoThis seems like a very pat dismissal of what upon reading further seems like a very reasonable critique of the industry. Vendors have been seriously exploiting their ability to decline responsibility for their product development decisions and that often has significant negatives for affected users.
- sublinear 2y agoI think we've all seen bad software. I agree it's a problem. What I question is where the blame is being placed. > Naturally, if writing flawless code was super easy, it would be done without fail. Some developers are clearly careless or clueless, leading to vulnerabilities and other bugs, and sometimes skilled humans with the best intentions simply make mistakes. In any case, Easterly isn't happy with the current defect rate. To be fair this is the author of the article saying this. However just about all the examples of guideline adherence are about product features, not bugs. The software quality problem squarely lies with incompetent management and idiots with checklists. That this role is currently being filled by someone with a military background doesn't help at all.
- acdha 2y agoI think that’s a good example of the problem with The Register, but I think we should try to focus more on Easterly’s quoted statements which accurately identify the problem as corporate.
- notepad0x90 2y ago"Technology vendors are the characters who are building problems..." there are vendors building problems into their products? isn't that a crime? What a silly take. "House developers that build weak doors into houses are the real problem, not the burglars" Security is an age-old problem, it is not a new concept. What is different with information security is the complexities and power dynamics changed drastically. I mean, really! She should know better, the #1 attack vector for initial access is still phishing or social-engineering of some kind. Not a specific vulnerability in some software.
- acdha 2y agoHint: she didn’t say that they were building them intentionally. Skimping is building a problem even if nobody had a Jira ticket saying they had to leave out bounds checking.
- notepad0x90 2y agoMost vulnerabilities are not there because someone was deliberately negligent either. I see no evidence of a trend where vendors are "skimping" on anything.
- acdha 2y agoYou don’t think the vendors who are years behind on dependency updates are skimping? Not the ones who are still struggling to ship patches on a better than quarterly cadence? Not the ones who still ship 90s-style C code to enterprise customers who are paying high prices for their security products? Not the ones still writing new code in memory unsafe languages? Not the ones who still tell customers to disable SELinux? Not the ones who still refuse to use the sandboxing features in modern operating systems? Companies love the idea that you can’t hold the liable for any defect they didn’t intentionally build in, but software is the extreme outlier where they were able to avoid consumer safety regulations and thus the expense of hiring people who can even tell when something is risky. Shift the cost back to the supplier would restore the market feedback mechanism which is currently missing, greatly improving the health of the industry.
- userbinator 2y agoWhy does software require so many urgent patches? Conspiracy theory: creating new bugs they can always fix later is a good source of continued employment. Of course there's also the counterargument that insecurity is freedom: if it weren't for some insecurity, the population would be digitally enslaved even more by companies who prioritise their own interests. Stallman's infamous "Right to Read" is a good reminder of that dystopia. This also ties in with right-to-repair. The optimum amount of cybercrime is nonzero.
- wredue 2y agoIt isn't malice dude. Unfortunately, it really is just that 70% of developers are utterly incompetent.
- tsimionescu 2y agoIf having security vulnerabilities in code you wrote or reviewed is a sign of incompetence, then there has probably never been a competent developer in the history of the industry.
- wredue 2y agoI wouldn’t say that. There are some not obvious things like timing attacks that you probably shouldn’t feel bad about. If you’re still writing sql injections though, yeah, you’re terrible.
- tonetegeatinst 2y agoOne thing is software development is not really focused on secure software. If Microsoft ca n manage to call recall a engineered product feature where those M$ folks get payed stacks to work on, can't even both securing the data in rest, and then decide its a great idea to use cloud computing for recall, then I can totally see "security software engineer" becoming a separate field. Securing software seems to be hard especially in web development. You got to worry about regular development, then all these crazy different exploit methods like xss,SQL injection, data sanitation, etc....and then you got to get this site working for multiple browsers, you need to jugle all of this. And if an api or some 3rd party tool gets compromised how do you prevent that except a crystal ball a bottle of burbon and a clairvoyant chant? Also their was iirc people submitting bogus CVE reports to increase the mental drain on people and overwhelm the human link which is always the weakest.
- hn_throwaway_99 2y agoAt this point, I have to wonder what is even the point of missives like this. There are only two things that will solve the software quality problem: 1. Economic incentives. It's all just mindless blather unless you're actually talking about ways that software vendors will be held liable for bugs in their products. If you're not talking about that, what you're saying is basically "ok pretty please" useless. 2. Reducing the complexity of making products secure in the first place. Making truly secure software products is incredibly hard in this day and age, which is one reason why demanding software product liability is so scary. Professional structural engineers, for example, are used to taking liability for their designs and buildings. But with software security the complexity is nearly infinitely higher, and making it secure is much harder to guarantee. The other thing that people often ignore, or at least don't want to admit, is that the "move fast and break things" ethos has been phenomenally successful from a business perspective. The US software industry grew exponentially faster than anyplace else in the world, even places like India that doubled down on things like the "Software Capability Maturity Model" in the early 00s, and honestly have little to show for it.
- juunpp 2y ago3. Legal incentives. When somebody dies or fails to receive critical care at a hospital because a Windows XP machined got owned, somebody should probably face something along the lines of criminal negligence.
- rockskon 2y agoWill Microsoft face liability if someone dies or fails to receive critical care because some infrastructure system auto-rebooted to apply an update and lost state/data relating to that patient's care?
- transpute 2y agoDan Geer on prioritizing MTRR over MTBF (2022): Metrics as Policy Driver: Do we steer by Mean Time Between Failure (MTBF) or Mean Time To Repair (MTTR) in Cybersecurity? Choosing Mean Time Between Failure (MTBF) as the core driver of cybersecurity assumes that vulnerabilities are sparse, not dense. If they are sparse, then the treasure spent finding them is well-spent so long as we are not deploying new vulnerabilities faster than we are eliminating old ones. If they are dense, then any treasure spent finding them is more than wasted; it is disinformation. Suppose we cannot answer whether vulnerabilities are sparse or dense. In that case, a Mean Time To Repair (MTTR) of zero (instant recovery) is more consistent with planning for maximal damage scenarios. The lesson under these circumstances is that the paramount security engineering design goal becomes no silent failure – not no failure but no silent failure – one cannot mitigate what one does not recognize is happening.
- Animats 2y agoA previous head of cyber security was fired when he said something like that.
- jdougan 2y agoI dunno. "Evil Ferret" and "Scrawny Nuisance" sound pretty good in our irony filled world.
- consumer451 2y agoI used to be an IT guy at a structural and civil engineering firm. Those were real professional engineers with stamps and liability. As long as "SWEs" do not have stamps and legal liability, they are not real (professional) engineers, IMHO. My point is that I believe to earn the title of "Software Engineer," you should have a stamp and legal liability. We done effed up. This breach of standards might be the great filter. edit: Thanks to the conversation down-thread, the possibly obvious solution is a Software Professional Engineer, with a stamp. This means full-stack is actually full effing stack, not any bullshit. This means that ~1% to ~5% of SWE would be SWPE, as it is in other engineering domains. A SWPE would need to sign off on anything actually important. What is important? Well we figured that out in other engineering domains. It's time for software to catch the f up.
- bruce511 2y agoOk, so overnight all programmers stop calling themselves Engineers. [1] What problem does that solve? I fix bugs all day, but I don't call myself a Software Doctor. Frankly whether software people call themselves engineers or not matters to pretty much no-one (except actual engineers who have stamps and liabilities.) Creating a bunch of requirements and liability won't suddenly result in more programmers getting certified and taking on liability. It'll just mean they stop using that title. I'm not sure that achieves anything useful. We'd still have the exact same software coming from the exact same people. [1] for the record I think 'software engineer' is a daft title anyway, and I don't use it. I don't have an engineering degree. On the other hand I have a science degree and I don't go around calling myself a data scientist either.
- consumer451 2y agoThat's fine, it just means that devs without stamps can't sign off on anything actually important. In real engineering, there is a difference between an Engineer and a Professional Engineer. The latter has a stamp. I realize that this is the nearly the opposite of our current environment. It is a lot more regulation, a lot more professional standards... but it worked for civil and structural, and those standards were written in blood. Maybe what I am asking for is a PE for SWE, those people have stamps, and it would be really hard to get a SW PE. Anything deemed critical (like security), by regulation, would require a SW PE stamp. [0] Software did in-fact eat the world. Why shouldn't it have any legal/professional liability like civil and structural engineering? [0] In this case, full stack, actually means full freaking stack = SWPE
- deleted 2y ago[deleted]
- johndhi 2y agoWhat she is asking for is a radical economic restructuring of a free market. It's attitudes like hers that lead to the federal government having the worst software imaginable. It just doesn't work unless everyone agrees to do it .. so good luck
- acdha 2y agoLiability for a defective product is a “radical restructuring”? It’s something we have in almost every other category of business - not perfectly but pervasive enough that software is really conspicuous as an outlier.
- EnigmaFlare 2y agoAbsolutely. OEM car parts suppliers have liability not just for their own product but whatever consequences happen downstream, like the cost of recalls, etc. And that makes sense becase liability is on the companies that are in the best position to ensure their product is correct. Vendors of engineering software used by car makers, on the other hand, have no such liability. It's software so its the user's responsibility.
- usrusr 2y agoNow imagine software priced like OEM car parts. We'd all be running some heirloom version of Turbo Pascal.
- acdha 2y agoYou know that some of the most profitable companies in the world are software companies, right? Putting more resources into security and robustness wouldn’t mean a copy of Excel costs $5,000, it’d mean that Microsoft’s profit margins go down slightly and they ship new features slightly slower. The incredible leverage of software engineering would still mean that they’re amortizing those costs across a billion users.
- dhx 2y agoWhere does CISA/NIST recommend (for software developers) or require (for government agencies integrating software) specific software/operating system hardening controls? * Where do they require software developers to provide and enforce seccomp-bfp rules to ensure software is sandboxed from making syscalls it doesn't need to? For example, where is the standard that says software should be restricted from using the 'ptrace' syscall on Linux if the software is not in the category of [debugging tool, reverse engineering tool, ...]? * Where do they require government agencies using Kubernetes to use a "restricted" pod security standard? Or what configuration do they require or recommend for systemd units to sandbox services? Better yet, how much government funding is spent on sharing improved application hardening configuration upstream to open source projects that the government then relies upon (either directly or indirectly via their SaaS/PaaS suppliers)? * Where do they provide a recommended Kconfig for compiling a Linux kernel with recommended hardening configuration applied? * Where do they require reproducible software builds and what distributed ledger (or even central database) do they point people to for cryptographic checksums from multiple independent parties confirming they all reproduced the build exactly? * Where do they require source code repositories being built to have 100% inspectable, explainable and reproducible data? As xz-utils showed, how would a software developer need to show that test images, test archives, magic constants and other binary data in a source code repository came to be and are not hiding something nefarious up the sleeve. * Where do they require proprietary software suppliers to have source code repositories kept in escrow with another company/organisation which can reproduce software builds, making supply chain hacks harder to accomplish? * ... (similar for SaaS, PaaS, proprietary software, Android, iOS, Windows, etc) All that the Application Security and Development STIG Ver 6 Rel 1[1] and NIST SP 800-53 Rev 5[2] offer up is vague statements of "Application hardening should be considered" which results in approximately nothing being done. [1] https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_ASD_V6R1_STIG.zip https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_ASD_... [2] https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
- tptacek 2y agoI don't know how meaningful those countermeasures really are. Like, you're basically looking at the space of Linux kernel LPEs, and you're bringing it down to maybe 1/3rd the "native" rate of vulnerabilities --- but how does that change your planning and the promises you can make to customers?
- waihtis 2y agoI hope she starts the crackdown with easily the biggest impact offender here, Microsoft
- gavinhoward 2y agoI don't quite agree, but I do somewhat agree. We need to professionalize and actually accept liability for our work. [1] [1]: https://gavinhoward.com/2024/06/a-plan-for-professionalism/ https://gavinhoward.com/2024/06/a-plan-for-professionalism/
- forgetfreeman 2y agoPretty sure I'm going to burn some karma on this one but what the hell. To the best of my knowledge there is no evidence in over four decades of commercial software development that supports the assertion that software can be truly secure. So to my mind this suggests the primary villains are the individuals and organizations that have pushed software into increasingly sensitive areas of our lives and vital institutions.
- gavinhoward 2y agoAs someone who thinks the industry should professionalize, I actually agree with you somewhat; we pushed too far, too fast, and into territory that software has no business being in.
- irundebian 2y agoWhat's the definition of truly secure?
- forgetfreeman 2y agoThe world economy is hemorrhaging over a trillion dollars USD annually to cybercrime, so however you choose to define it it clearly doesn't exist.
- irundebian 2y agoIf you defined it as absence of runtime errors, it exists.
- forgetfreeman 2y agoEven if that's true (massive if) it's a meaningless assertion. You've still got to deal with several tiers of hardware vulns, the OS space, and figure out a way to provably secure any network traffic generated. "hello world" tends to be pretty secure in theory but it isn't particularly useful.
- tonetegeatinst 2y agoI think sometimes cyber is still seen as an unnecessary cost. Plenty of places do bare minimum for security, and most of the time its after an incident that budgets suddenly get raised. Software, hardware, policy, and employee training are all things one must focus on. You can't just start making rdx or fireworks without the proper paperwork, permits, licenses, fees, and a lawyer around to navigate everything. You run a business without investing anything into IT and cybersecurity, you just make it easier for an incident to occur. And remember, just because your product isn't IT or cyber security dosnt mean its losing money, it a cost of doing buissness in our regulated market. You mishandle HIPPA, PII or sensitive info, and the customers realize you didn't take basic steps to stop this, you open yourself to a lawsuit. Think about it like this, investing in it every day means your lowering that risk, however much you think is reasonable to pay for, and every day its paying for itself.
- swiftcoder 2y agoWas about half way through before I realised that the article was not, in fact, satirical. Half-expected to see harddrive in the URL.
- z3phyr 2y agoUsing the same logic, one can argue "SOFTWARE IS PROVIDED AS IS". It should be up-to the user to choose the correct software based on their security policy. I write software for fun and skillz, making computers do extraordinary things. If I start following regulation, then there is no fun for me and no software that does extraordinary things. No ma'am Doom or Second Reality would not have been possible with this attitude.
- croes 2y agoThe users choice affects third parties, so it's not that simple. I bet you won't recommend to install your software on essential systems. >No ma'am Doom or Second Reality would not have been possible with this attitude. Same is true for many kinds of malware.
- z3phyr 2y ago> Same is true for many kinds of malware. Would you prefer to not have Doom at all? (Over only some malware not existing)
- hermannj314 2y agoI strongly disagree. If someone puts cyanide in the coffee pot, we don't blame the engineer that designed the coffee pot for not making it cyanide proof. Criminals are the criminals, not a developer that didn't code defensively enough. The fact that a government official is blaming developers for crimes they don't commit is fascist level rhetoric.
- croes 2y agoWe did blame KIA for their shitty car locks. And your example is a bad one, because you would blame the engineer if sells it as cyanide proof. Software vendors claim their software is safe that only high sophisticated criminals could break their software. In reality it's often just script kiddies.
- DangitBobby 2y agoIn the comment you responded to, they made no mention of the engineer expecting or claiming it is cyanide proof, so your response makes no sense. Is the person in the article saying only people who claim that software is free of defects should be held liable? I would never make a claim that software I've written is 100% secure, and I would stop writing software if I were held criminally liable for defects.
- hermannj314 2y agoNo member of the US government proposed locking up mechanics that build KIAs for the crime of theft of motor vehicles. (And if I am wrong, and they did, then I would be against that as well) An official of the US government is saying they want software developers to be treated as criminals if their software can be exploited. That is an insane proposal.
- Log_out_ 2y agoSo in a hypothetical world were the paranoid reign supreme and all software ia safe and unuseable cause usage is not a protection goal, do they declare a revolution in the name of useability and economic speed to overthrow the evil protectors?
- amai 2y agoYou won't earn a prize for most secure, fewest bugs or longest uptime in our industry. Days without incident is not a metric the software industry cares about, because it doesn't matter. Our customers are vendor-locked in and because we have a market monopoly they can't do anything than accepting our conditions. If only the state would regulate our industry, but that won't happen, because we will call the regulator a communist and then every regulation will be deleted from the agenda.