Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

21–30 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#21
post #14
post #8

How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.

Not sure that solves the problem either, perhaps UK has more stringent laws, or perhaps the US does. But if it's not universal a sufficiently large market can still be exploited to attack another. The internet is global. We need global regulations.

If the US or EU did that, it would still be a very good start simply due to the size of those markets.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#22
post #8

How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.

If you want to go after the simple stuff then blocking significant outbound traffic at the ISP level from a home user account until they agree it's something they want to do is the most straightforward solution. No need to change much infrastructure, no need to test devices, and no need to have costly manufacturing processes. You could even let specific traffic through (Facebook live streaming, online gaming services, etc).

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#23
post #2

> The major botnet of 2016 is simpler than the botnet of 1988. That, right there, is a damning indictment not only of our industry but also of our culture. We know how to secure systems. It's not magic. But — unlike for example physical hygiene — we haven't made the decision to make computer hygiene part of our culture. We look down on people who don't wash their hands, but we don't look down on people who use poor p…

"That, right there, is a damning indictment not only of our industry but also of our culture."

Who is "our culture"?

Are you part of the same "our culture" as the people who made and shipped these things?

Since you're pretty much rhetorically constrained to answer "yes"... would those people agree with the answer you give?

The culture I am actually part of is not perfect, certainly. The people who are in my culture still write the simplest cross-site-scripting attacks like they get paid bonuses for them. But the vast bulk of the people involved in the production of the hardware that the Mirai botnet took over would probably not agree that I am in "their culture", regardless of what I claim about it, and they'd probably feel the same way about you is my guess.

Even if "we" do everything you would suggest, perfectly, Mirai still happens. Therefore, those suggestions can't be the solution. We must still address these problems via other mechanisms.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#24

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

The solution isn't to have random security consultants come in and kludge up your process and generate useless reports of irrelevant statistics. The solution is to have a red team on staff permanently, to offer bug bounties based on actual access, to install on-server monitoring for outdated packages (like Appcanary, the authors of this piece), to monitor outbound packets for suspicious behaviour (this is currently the hardest part, imo, since, other than detecting major viruses, it's largely domain and network specific), and to have an automated "take the servers off the internet" button for serious 0-days and leaked credentials. Also, always use HTTPS / HSTS lists and two factor authentication.

You'll still get hacked, but you'll be far better off.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#25
It's actually proof that internet architecture in general is broken. Well, not broken; it was broken, and then healed in a weird way so there's extra cartilage sticking out causing annoyances and won't move as easily anymore.

The security industry has absolutely nothing to do with the existence of a botnet that can take down massive internet infrastructure. The security industry just puts bandaids on shitty products. It's the internet architects/designers that are responsible for botnets.

In order to make the internet very simple, very compatible, and decentralized and distributed, the design allows a baby monitor to send arbitrary traffic to any device on the global network. There is no good reason for this. The reason is, anything else would be complicated, and complicated things become expensive and troublesome. But that's not a good reason to allow baby monitors to take down internet services.

The solution would be to segregate critical equipment address and protocol by function, and to put in strict controls in all routers to prevent illegitimate traffic from reaching the wrong equipment. This would not only improve security, it would make allocation of address space and application ports make some kind of practical sense, and allow for improvements in the way applications communicate over the internet, to say nothing of improved management of traffic.

But nobody's going to change the design, so whatever.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#26
post #10

Yeah, no. Mirai doesn't have shit to do with the security industry. The security industry are the people who you hire to secure your things, victims of Mirai did not take advantage of the services provided by the security industry. More like, The Mirai Botnet Is Proof the Security Industry Is Going To Be Doing Fucking Great

Amen, the Security Industry is doing great, security is doing poorly.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#27

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

> It's a few honest people screaming to be heard above the din of snake-oil salesmen...

I think it more likely that it's a few honest, knowledgeable people screaming to be heard above many honest, well-intentioned, but misguided people screaming to be heard above the din of snake oil salesmen.

It's much easier to believe the wrong thing and sell it yourself than it is to be a confidence man. And on the same note, it's much easier to crucify a malicious hacker than it is to ruin the life of a guy who supports his wife and kids who just happened to make the economic call that running everything as root was okay.

To your point on economics, I think the old joke about two guys being chased by a bear applies to the economic mindset. One company is seen tying its shoes (for the sake of the metaphor let's add to the joke that he's otherwise naked), and the other company says slyly "I don't think you're going to outrun that bear." "We don't have to," replies the naked company, "we just have to outrun you."

It's going to be hard to justify the extra 80% effort on the remaining 20% when management and sales only want to go 21% just so they can outlast their competitors.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#28
post #14
post #8

How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.

Not sure that solves the problem either, perhaps UK has more stringent laws, or perhaps the US does. But if it's not universal a sufficiently large market can still be exploited to attack another. The internet is global. We need global regulations.

The law just needs to apply in a large enough region. Here in the US we got high efficiency switching wall warts instead of the slightly cheaper ones that idled away $4/yr because the EU demanded them, so manufacturers had to upgrade.

Similar with lead free solder.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#29
post #2

> The major botnet of 2016 is simpler than the botnet of 1988. That, right there, is a damning indictment not only of our industry but also of our culture. We know how to secure systems. It's not magic. But — unlike for example physical hygiene — we haven't made the decision to make computer hygiene part of our culture. We look down on people who don't wash their hands, but we don't look down on people who use poor p…

I guess it's important for some people to keep flogging Microsoft hatred but what does Windows have to do with anything here?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#30

I think it's erroneous to blame the security industry wholesale, tempting as it may be. Let's set blame aside for now. What caused this botnet? - The tendency of IoT/smart-device vendors to eschew engineering discipline - The tendency of _all_ companies to eschew security as an optional extra rather than the cost of admittance to the marketplace - The historical tendency of big companies /not/ being burned to the gro…

Though I agree with you, and really admire what you're trying to do. I find most security researchers admire too much their "rock star" status to care about the rest of the industry.

Maybe a good starting point would be an attitude change?

Post reply on HN