Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

31–40 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#31

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

It's even more slimey in the enterprise space.

I'd like to think that the majority of people involved with the industry in some way have good intentions, but once you start involving, sales, marketing, and certain executives...

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#32
post #18
post #4

My toaster has to be certified that it meets certain minimum safety standards. It really seems that IoT and safety critical software/firmware should be required to pass a similar (bare minimum) certification.

Toaster is required to pass safety standards because of the there is strong economic incentive (UL requirements) to do it. Without UL, it can't get on the shelf on any stores in US. There are no such thing and UL security requirements for IOT device. Time for such regulation? But "internet + regulation" normally raise a lot of objections internally from the IT industry. If someone (MSFT) proposes secure boot are requ…

> There are no such thing and UL security requirements for IOT device.

UL 2900-1.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#33
post #7

The "security industry" was never significantly involved in improving product security and software quality. They have roots in profiting from the deplorable state of PC security. Centralised firewalls, "intranets", and anti-virus products are not sustainable solutions to any of these problems - they're just so ingrained in the mindset of IT profiessionals that they self-perpetuate.

Endpoint security traces back to antivirus and PC security. Firewalls do not --- firewalls trace back to the Unix culture.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#34

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

The solution isn't to have random security consultants come in and kludge up your process and generate useless reports of irrelevant statistics. The solution is to have a red team on staff permanently, to offer bug bounties based on actual access, to install on-server monitoring for outdated packages (like Appcanary, the authors of this piece), to monitor outbound packets for suspicious behaviour (this is currently t…

"Offer bug bounties based on actual access" why?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#35
post #7

The "security industry" was never significantly involved in improving product security and software quality. They have roots in profiting from the deplorable state of PC security. Centralised firewalls, "intranets", and anti-virus products are not sustainable solutions to any of these problems - they're just so ingrained in the mindset of IT profiessionals that they self-perpetuate.

Good firewalls can make good security easier.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#36
post #3
post #2

> The major botnet of 2016 is simpler than the botnet of 1988. That, right there, is a damning indictment not only of our industry but also of our culture. We know how to secure systems. It's not magic. But — unlike for example physical hygiene — we haven't made the decision to make computer hygiene part of our culture. We look down on people who don't wash their hands, but we don't look down on people who use poor p…

Worst of all, they think people who haven't learned about security deserve what happens to them...

For the sake of argument, why don't they deserve what happens to them?

Most people don't understand how their car works. But if you own a car and you neglect to change the oil for 50k miles, or you put diesel into your tank and ruin your car, we don't blame the automotive industry for not informing you on proper maintenance. Just like with computers, the information is out there, and it's not the job of the automaker to make sure you know it.

Why are computers different?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#37

Completely incorrect claim, the IoT industry doesn't spend a penny on security, and therefore will be vulnerable to these type of attacks. If anything this is proof that the security industry does work, these attacks are happening on devices where there is no security budget - not on servers with large investments in security.

How many pennies would've been needed to insert a simple page forcing you to change user/password combo and to choose a reasonably strong password after first boot ?

In the case of Mirai it's not even a cost issue, just lacking good practices.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#38
post #30

I think it's erroneous to blame the security industry wholesale, tempting as it may be. Let's set blame aside for now. What caused this botnet? - The tendency of IoT/smart-device vendors to eschew engineering discipline - The tendency of _all_ companies to eschew security as an optional extra rather than the cost of admittance to the marketplace - The historical tendency of big companies /not/ being burned to the gro…

Though I agree with you, and really admire what you're trying to do. I find most security researchers admire too much their "rock star" status to care about the rest of the industry. Maybe a good starting point would be an attitude change?

I probably know too many folks who don't have that "rock star" attitude to see it as an immediate problem, and therefore am not qualified to provide an informed suggestion here.

But I would agree that, where the attitude does exist, it needs to be changed.

Less rock stars, more janitors/mechanics.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#40
post #18
post #4

My toaster has to be certified that it meets certain minimum safety standards. It really seems that IoT and safety critical software/firmware should be required to pass a similar (bare minimum) certification.

Toaster is required to pass safety standards because of the there is strong economic incentive (UL requirements) to do it. Without UL, it can't get on the shelf on any stores in US. There are no such thing and UL security requirements for IOT device. Time for such regulation? But "internet + regulation" normally raise a lot of objections internally from the IT industry. If someone (MSFT) proposes secure boot are requ…

UL isn't a regulatory body. UL testing is voluntary. You may know this, but perhaps many others don't.

I think a UL for internet connected devices is a fantastic idea. Just need to figure out how to get companies to volunteer for such testing. The way it works for UL is that they provide some insulation from litigation. Perhaps if users could litigate IOT manufacturers for inadequate security testing, something similar would materialize for that industry as well?

Post reply on HN