6 ms·
Nvidia Corporate Network Breached
- alexivanovs 12y agoI still stand by this: https://news.ycombinator.com/item?id=8800034 https://news.ycombinator.com/item?id=8800034 and this is only the very beginning, it's time to realize that all your favorite networks and sites have been compromised way before they're being announced to the public. Big breaches like the Sony one are like gasoline being added to fire, script-kiddies and even some of the more educated hackers feel obliged to share what they've been able to achieve as well. It's basic human psychology. And the only reason I know what I am talking about is because I have been in that situation myself.
- ars 12y agoSo, what do we do if we live in a world where it's impossible to prevent this type of thing? Is there anything we can do? Or just keep plugging holes as they come up? For example I no longer expect my email address not to leak - it doesn't matter who you send it to (which company or person) eventually it will leak. There are only a few rare exceptions, which is the opposite of the kind of world you want, but it's the reality. For email, instead of concealing the address we focus on filtering the spam. Is there something that can be done for passwords? Personal information? Other things?
- higherpurpose 12y agoPassword managers such as Lastpass along with a 2-factor auth for each user should be pretty good (preferably not SMS-based as these can be relatively easily bypassed with SS7 access, but based on Yubikey-like hardware tokens or such). Also, after these hacks I would hope most companies will be considering adopting end-to-end email and chat encryption policies ASAP, to protect sensitive information (such as the dealings between Sony and MPAA) from getting out in such a leak - even if that means the top execs not having access to everyone's emails and chats anymore. Right now most companies prefer to spy on their employees, which makes them highly vulnerable to this type of leak in case of a hack. It also proves the point that surveillance is a bad "cybersecurity" policy (NSA and most other "security" agencies believe it's the solution to hacking, somehow). They might want to reconsider that and encrypt everything end-to-end. They also need to compartmentalize a lot more. You can't have a "network of 50,000 computers" in a company, like I think Sony had. I also believe it's already quite common for large corporations to have employees access the Internet only through a VM along with solid whitelisting policies (although I'm pretty sure Sony didn't do that and there are probably many more like them). So yeah, I think the main point would be to keep security as close to an individual employee as possible, as opposed to having everything accessed company-wide, with virtually no protections within the network itself, just outside of it.
- MichaelApproved 12y agoWhat happens when lastpass gets hacked?
- vosper 12y agoI don't store my critical passwords in LastPass. So my email and banking passwords are not there. So I have to remember 4 passwords: 1 x email, 2 x bank, 1 x LastPass. That's not so bad, and means that if LastPass is hacked I can still reset everything.
- rlvesco7 12y agoIn theory, your passwords are encrypted locally before they are uploaded. They claim that they are unable to see your passwords. That said, they are right next door to Langley, VA so who knows.
- MichaelApproved 12y agoHow is that possible when they allow you to share passwords with other people?
- jdsnape 12y agoI think a slight change in approach is needed. In a lot of cases, your network had a hard outer perimeter which was treated as unbreakable, and within that was considered 'trusted'. I think we're now finding that doesn't scale very well as it only takes one hole and it's broken. It's better to treat the network as some level of 'untrusted' and protect your servers/computers better as individual units accordingly.
- marak830 12y agoThis. I think its definatly time we started treating our internal networks as unsafe. Not as easier for the end user, but if done correctly a lot safer for everyone. A little depressing, but its what would have had to happen eventually.
- calpaterson 12y ago"De-perimeterisation" in security-ese https://en.wikipedia.org/wiki/De-perimeterisation https://en.wikipedia.org/wiki/De-perimeterisation
- hga 12y agoIn military terms, it's switching from a crust defense (the perimeter) to defense in depth. There are situations where the former can make sense, such as a siege, where e.g. a penetration is quickly obvious and you can use your interior lines of communications to rush reserves to the action. The key, of course, is the "quickly obvious". Prior to the stats of the art allowing that (which sounds difficult and painful in principle), defense in depth is obviously the way to go. But you've got to achive it in some why where e.g. compromise of "bob@nvidia.com" + password doesn't quickly get you past any defense, or any that's relevant to bob.
- niels_olson 12y agoThe military's defense in depth can get crazy though. Without going into details, the smart people you want to do interesting things frequently end up so severely hamstrung they give up before starting.
- harshreality 12y agoStop reusing passwords 2-factor Network compartmentalization. For example, in the Sony Pictures hack, why does HR's network need to be accessible from the same internal network that everyone else is on?
- tmm 12y agowhy does HR's network need to be accessible from the same internal network that everyone else is on? Convenience I guess. Every book I've ever seen on network design and system administration talks about "departmental" servers and segmenting corporate networks at functional borders, but in practice I've never seen it. It's hard enough to get people to use different network shares for different data (e.g. personal, departmental, project related) instead of one global, world-writable share. This occurs at every level, from small businesses to the largest corporate and government networks. On top of that, even if you compartmentalize, there really isn't any technical method to prevent Sally in HR from emailing a list of personal email addresses, phone numbers and addresses to Sam in the Communications department so he can send out Christmas cards to everyone. And, Sally being a non-technical user will probably just "hide" the social security and salary columns in that spreadsheet instead of deleting them and then will blame Bob in IT when that list of salaries ends up on the global network share and eventually printed out and taped to the wall in the hallway.
- Meekro 12y agoThe internet is still very young, and I'd like to think that we will learn to do better. Most systems are already much more resilient than they were 10 years ago. Things like Ubuntu's auto-updates are making the average web server more secure. Specialization is also starting to play more of a role. Various hosting and cloud companies have pitched themselves as experts in security, and large ones like Amazon have never been hacked directly. Companies that specialize in something other than IT (like Sony) can rely on cloud firms' expertise rather than trying to figure it out themselves (and repeating past mistakes in the process). Software companies also put a higher priority on security than ever before. New software like Google Chrome is setting a high standard for security, and insecure stuff like Adobe Flash is shunned. It's increasingly obvious that even the best programmers in the world can't always write secure C software, but new memory-managed languages are playing a greater role. Google's Go is quickly being adopted to write software that runs anywhere, nearly as fast as C, but with proper memory management. I could provide more examples, but my point is that we're doing more than playing whack-a-mole with the exploit of the day. We've invented (and widely deployed) new ideas that make things permanently better, and there are more such ideas in the pipeline. Call me an optimist, but I think we will see massive improvements over the next few decades.
- jpeg_hero 12y agoInteresting. Some random website is hacked and user account and passwords are revealed. In the user accounts notice there is a "bob@nvidia.com" with associated password. If you are the hacker, might as well type that in to nvidia's corporate system right? Scary.
- Ixiaus 12y agoPasswords are clearly a badly broken model. Even if each entity handles your password safely (you can easily argue that most don't) the weakest link in the chain is still the human being.
- akerl_ 12y agoUse password manager -> generate high entropy passwords -> Victory. It's pretty easy to keep your password manager secure against the threats that most people actually face, and this removes the worst elements: password reuse and low-entropy passwords.
- themartorana 12y agoIt does, but a "good" password manager is the cost of a Twitter, Facebook, Gmail, Pandora, Spotify, and iTunes accounts combined times infinity. 1Password is probably my favorite app/suite of apps ever. And I willingly shelled out for them. But most people balk at paying $.99 to remove advertising in mobile games, so I don't see this catching on. (Plus sync, plus backups, plus...)
- citruspi 12y ago> a "good" password manager is the cost of a Twitter, Facebook, Gmail, Pandora, Spotify, and iTunes accounts combined times infinity. It can be, but it doesn't have to be. There's perfectly good password managers[0] which are free and open source. The problem in this case is getting people who aren't technically literate to use them. [0] http://www.passwordstore.org http://www.passwordstore.org
- 12y ago
- sargun 12y agoI have a different view on security. A lot of people are talking about defense in depth, and security being enforced by the network. I think although that kind of works, it's largely a mistake. Security, as enforced by middleboxes is fundamentally flawed, especially as we see the proliferation of systems that are too complex, and rapidly changing for middleboxes to understand. Although, they can be a tool in laying defensive trenches, they are nothing more than a simple barrier. I think that endpoint security is what needs to be enhanced. Looking at what's been disclosed about malware recently (APTs: https://en.wikipedia.org/wiki/Advanced_persistent_threat https://en.wikipedia.org/wiki/Advanced_persistent_threat), we need to focus on a few things: 1) Isolating components: Components, and processes themselves should be isolated from one another, and the operating system. A web server should be able to run malicious code without fear of it easily getting root access. We have tools to make this possible today, like Apparmor, and SELinux. The fact that distributing Apparmor, or SELinux profiles with applications today isn't normal, makes me sad. 2) Modularization: We should do our best to split the components of a system up into small, well-understood pieces. Rather than trying to combine multiple components into one monolithic process, breaking up components into their individual components. I think Cloudflare's work around Keyless SSL was great, but we've had HSMs for years -- that could have easily avoided such disasters as Heartbleed. 3) Decent abstractions: With the advent of further distributed systems, and modularization, we're going to see more and more interfaces between systems crop up. Largely, CISOs are limited to what the systems, and networking team can do. These limits typically manifested themselves at layer 4 on the network side of the house, and limited layer 7 capabilities like URL filtering, and file system ACLs. I think we need better stories around resource access and authorization. For years, we've had systems like Kerberos which would have been a great building block, but yet goes unused. I hope we see X509, and GPG become more ubiquitous for access management, and encryption.
- thanksgiving 12y ago> Rather than trying to combine multiple components into one monolithic process, breaking up components into their individual components. Why does this only apply in the user space? The first thing I thought if when I read this sentence was systemd...
- 12y ago
- tinco 12y agoWeird that the author would attack password post-its with passwords on them as some sort of terrible practice. If Nvidia's employees would've all have multiple passwords on post-it's on their monitors they would likely never have been hacked at all. Better to have 5 passwords on a post-it on your monitor, safely within the guarded walls of your HQ office, than 1 password shared between your Playstation game account and your gmail.
- akerl_ 12y agoThat's a false dichotomy. There are, thankfully, options besides {write multiple passwords on post-it note} and {use same password everywhere}. Nvidia, and in fact all of us, should be teaching folks to not reuses passwords and also to store them securely. It's almost 2015, and password managers are available for pretty much any platform, they're secure against the threats commonly faced by most people, and they're easy to use.
- tinco 12y agoFor a company like nvidia password managers (like lastpass) are a lot less secure than post-it notes. I'm not trying to sketch a dichotomy, obviously there are more secure ways of storing your passwords, like keeping the post-it's in a personal locker.
- hobs 12y agoHow? I legit don't get this. Is it the fact they have one password for all passwords? Secondly, you are basically ignoring physical security when you discuss post-it's as a means to secure a password. What happens when the "delivery man" or "pizza girl" shows up to do deliver their package and steal all your passwords? While most work places get physical security dead wrong, these are simple first steps.
- tinco 12y agoYes, I'm purposefully ignoring physical security, because I'm thinking of the kind of threats nvidia faces. It is important to have a security policy that fits your threat level, and the engagement of your employees. You can expect from an upper management person that he has a fast lock screen and an encrypted disk and a tight firewall on his laptop. In those conditions it makes absolute sense to recommend a password manager, preferably with a hardware security key. That's a fully decked-out APT resistant upper management guy or sysadmin. This is also the sort of target that would be the subject of a 'pizza girl' covert operative, so yes having passwords on post-its would be horrible. But that's not the type most likely got Nvidia. The other 50.000 employees is what is getting our big corporations in trouble. A poorly secured Windows laptop with out of date software, and no control on third party applications, that's a terrible place for a password manager. How easy is it to write a tool that extracts passwords from the manager if your tool got sysadmin rights by posing as a Java plugin installer, or a cracked video game? The sort of hacker that targets those employees is not necessarily an APT, more likely as mentioned before the passwords of these employees were gotten from big fly-by password leaks like the PSN hack. This sort of hacker wouldn't even look at your physical security, they don't care about your physical security, they're likely across an ocean from you, and likely wouldn't even drive by your office if it was in the same town as they are. The game is seggregating your security levels, and minimizing attack surface where possible. Standardizing a password manager across 50.000 low-tech employees sounds like a bad idea to me.
- sseveran 12y agoMaybe companies could stop using reversible encryption to store passwords and use a salted one way hash like grownups. I have so many different passwords that for sites I use irregularly I just have to reset them everytime. Also 2-factor auth is a plus.