Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

51–60 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#51

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

Those sort of information asymmetry problems (in this case, you can't know the quality of the service you're buying until it's far too late) are a textbook case of market failure [1] [2]. You can improve the outcome sometimes with some smart regulation.

But in the security industry there are multiple levels of this problem:

- The end user doesn't generally know how hardened the product he buys is

- The manufacturer is rarely certain how high quality the security auditing/services he is buying

- How much to invest in securing a product is not an easy decision.

I'm of course simplifying a lot here, but you asked for the economics of those problems, and hopefully this was interesting to some.

[1] http://www.sfu.ca/~allen/leffler2.pdf [2]https://www.iei.liu.se/nek/730g83/artiklar/1.328833/AkerlofM...

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#52
post #34

Earlier quoted context omitted.

The solution isn't to have random security consultants come in and kludge up your process and generate useless reports of irrelevant statistics. The solution is to have a red team on staff permanently, to offer bug bounties based on actual access, to install on-server monitoring for outdated packages (like Appcanary, the authors of this piece), to monitor outbound packets for suspicious behaviour (this is currently t…

"Offer bug bounties based on actual access" why?

Maybe misworded, but actual access is a clear line on the spectrum that starts at reporting a potential DDOS attack on an endpoint to dumping all your users credit cards and passwords. Access to a server isn't necessarily access to a DB, but it's usually serious enough to warrant cash, no matter who you are.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#53
The security industry has been "broken" for as long as there has been a security industry. When I left Network Associates in 1999 to start a chat company, leaving the security industry to do something non-security was already a cliche.

It's true, the 1U rackmount netsec industry does virtually nothing to prevent consumer electronics vendors from shipping terribly insecure code. I don't like the netsec industry either. But: so what?

The reality is, very few companies are buying 1U rackmount snake oil (or Nth generation antivirus products like endpoint protection tools) to stop things like Mirai. We're not even talking about the same budget. The "security industry" is not in fact chartered with stopping things like Mirai. So Mirai is a weird complaint to level at it.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#54

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

Basically some developers need to go to jail for gross negligence.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#55
post #34

Earlier quoted context omitted.

"Offer bug bounties based on actual access" why?

Maybe misworded, but actual access is a clear line on the spectrum that starts at reporting a potential DDOS attack on an endpoint to dumping all your users credit cards and passwords. Access to a server isn't necessarily access to a DB, but it's usually serious enough to warrant cash, no matter who you are.

I'm asking: why would you make a bounty conditional on "access" at all? What's the win? A bug is a bug. If it has the potential for access, it's worth the bounty. All a demonstrated access requirement does is encourage strangers to violate the privacy of your customers. It seems like an incredibly reckless idea.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#56

I think it's erroneous to blame the security industry wholesale, tempting as it may be. Let's set blame aside for now. What caused this botnet? - The tendency of IoT/smart-device vendors to eschew engineering discipline - The tendency of _all_ companies to eschew security as an optional extra rather than the cost of admittance to the marketplace - The historical tendency of big companies /not/ being burned to the gro…

> Solving the core problems is good for society, but society doesn't reward this behavior.

I'd like to think that we can solve collective action problems like this as a society and be rewarded for it.

We have to figure out how to fight this problem the way we fought smallpox and polio.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#57
post #8

How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.

That'll work until the database of device credentials is breached from company X which provides call center support services for manufacturers A through Z and needs said credentials at hand.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#58
post #49

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

That's a great point regarding the economics of why IoT manufacturers don't invest all that much on security. Here's another one. It's an externality. Botnet attacks don't harm the IoT manufacturers. They don't even harm the IoT products or their users. They harm completely innocent bystanders like DNS/github. What possible incentive do IoT manufacturers have to invest money on initiatives that bring no benefits to t…

Externalities are usually solved through pigouvian taxes.

But since we can't really know in advance what product will/won't be secure (or at least it's incredibly difficult in the constantly goalpost moving security industry) the only way I can see this happening is if, say DYN could sue the IoT manufacturers for negligence or something of the like.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#59
post #4

My toaster has to be certified that it meets certain minimum safety standards. It really seems that IoT and safety critical software/firmware should be required to pass a similar (bare minimum) certification.

But most of those safety standards are meant to protect the device and its user during a normal use, not against malicious attempts to destroy it or pervert its usage.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#60

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

This sounds like an insurance problem.

You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather.

If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of security breaches, this market might look much less broken.

You could potentially get to that state by having some major existing insurance companies offer "digital threat insurance", and require anyone who claims on it to be using the security services provided by one of their vetted providers.

Yes, you'd be building the sort of major corporate bureaucracy that HN hates, but you'd also be properly aligning everyone's incentives, and shifting the responsibility for the Hard Problem of determining who was selling real security software to a smaller number of better-resourced people. Perhaps there's a reason why major corporates are the norm in big, serious markets.

Edit: disclaimer, I'm an armchair theorist and have no skin in the game - perhaps this already exists or there's a good reason why it doesn't work

Post reply on HN