How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.
Not sure that solves the problem either, perhaps UK has more stringent laws, or perhaps the US does. But if it's not universal a sufficiently large market can still be exploited to attack another. The internet is global. We need global regulations.
The Mirai Botnet Is Proof the Security Industry Is Broken
21–30 of 260 posts
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#22How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#23> The major botnet of 2016 is simpler than the botnet of 1988. That, right there, is a damning indictment not only of our industry but also of our culture. We know how to secure systems. It's not magic. But — unlike for example physical hygiene — we haven't made the decision to make computer hygiene part of our culture. We look down on people who don't wash their hands, but we don't look down on people who use poor p…
Who is "our culture"?
Are you part of the same "our culture" as the people who made and shipped these things?
Since you're pretty much rhetorically constrained to answer "yes"... would those people agree with the answer you give?
The culture I am actually part of is not perfect, certainly. The people who are in my culture still write the simplest cross-site-scripting attacks like they get paid bonuses for them. But the vast bulk of the people involved in the production of the hardware that the Mirai botnet took over would probably not agree that I am in "their culture", regardless of what I claim about it, and they'd probably feel the same way about you is my guess.
Even if "we" do everything you would suggest, perfectly, Mirai still happens. Therefore, those suggestions can't be the solution. We must still address these problems via other mechanisms.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#24I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…
You'll still get hacked, but you'll be far better off.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#25The security industry has absolutely nothing to do with the existence of a botnet that can take down massive internet infrastructure. The security industry just puts bandaids on shitty products. It's the internet architects/designers that are responsible for botnets.
In order to make the internet very simple, very compatible, and decentralized and distributed, the design allows a baby monitor to send arbitrary traffic to any device on the global network. There is no good reason for this. The reason is, anything else would be complicated, and complicated things become expensive and troublesome. But that's not a good reason to allow baby monitors to take down internet services.
The solution would be to segregate critical equipment address and protocol by function, and to put in strict controls in all routers to prevent illegitimate traffic from reaching the wrong equipment. This would not only improve security, it would make allocation of address space and application ports make some kind of practical sense, and allow for improvements in the way applications communicate over the internet, to say nothing of improved management of traffic.
But nobody's going to change the design, so whatever.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#26Yeah, no. Mirai doesn't have shit to do with the security industry. The security industry are the people who you hire to secure your things, victims of Mirai did not take advantage of the services provided by the security industry. More like, The Mirai Botnet Is Proof the Security Industry Is Going To Be Doing Fucking Great
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#27I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…
I think it more likely that it's a few honest, knowledgeable people screaming to be heard above many honest, well-intentioned, but misguided people screaming to be heard above the din of snake oil salesmen.
It's much easier to believe the wrong thing and sell it yourself than it is to be a confidence man. And on the same note, it's much easier to crucify a malicious hacker than it is to ruin the life of a guy who supports his wife and kids who just happened to make the economic call that running everything as root was okay.
To your point on economics, I think the old joke about two guys being chased by a bear applies to the economic mindset. One company is seen tying its shoes (for the sake of the metaphor let's add to the joke that he's otherwise naked), and the other company says slyly "I don't think you're going to outrun that bear." "We don't have to," replies the naked company, "we just have to outrun you."
It's going to be hard to justify the extra 80% effort on the remaining 20% when management and sales only want to go 21% just so they can outlast their competitors.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#28How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.
Not sure that solves the problem either, perhaps UK has more stringent laws, or perhaps the US does. But if it's not universal a sufficiently large market can still be exploited to attack another. The internet is global. We need global regulations.
Similar with lead free solder.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#29> The major botnet of 2016 is simpler than the botnet of 1988. That, right there, is a damning indictment not only of our industry but also of our culture. We know how to secure systems. It's not magic. But — unlike for example physical hygiene — we haven't made the decision to make computer hygiene part of our culture. We look down on people who don't wash their hands, but we don't look down on people who use poor p…
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#30I think it's erroneous to blame the security industry wholesale, tempting as it may be. Let's set blame aside for now. What caused this botnet? - The tendency of IoT/smart-device vendors to eschew engineering discipline - The tendency of _all_ companies to eschew security as an optional extra rather than the cost of admittance to the marketplace - The historical tendency of big companies /not/ being burned to the gro…
Maybe a good starting point would be an attitude change?