Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

111–120 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#111
post #49

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

That's a great point regarding the economics of why IoT manufacturers don't invest all that much on security. Here's another one. It's an externality. Botnet attacks don't harm the IoT manufacturers. They don't even harm the IoT products or their users. They harm completely innocent bystanders like DNS/github. What possible incentive do IoT manufacturers have to invest money on initiatives that bring no benefits to t…

It's going to take networks with infected devices being cut away from the Internet like infested tree limbs before things get better.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#112

Earlier quoted context omitted.

Why would anyone in their right mind attack IoT products directly (ie. disabling/destroying them), when using them as a large botnet is far, far more lucrative? Well... Perhaps once IoT webcams are used for blackmail - but even that is a much more difficult task than "really big botnet attack really big sites" so the incentive isn't there

The same reason we got ILOVEYOU? I know profit motivated attacks have eclipsed entertainment motivated ones, but that's partly been about the work required to get a 'strong' exploit going. Mirai used an easier access vector than Morris to get full ownership of target devices, so it wouldn't be hard for one person to copy and abuse. I don't think this is going to become the norm - messing up a refrigerator isn't a luc…

The best we can get out of direct attacks on IoT are new "security products that protect your IoT devices" in a reactive manner. Windows antivirus all over again.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#113
> The major botnet of 2016 is simpler than the botnet of 1988. There’s something wrong in how we do security, and at Appcanary, we think it’s a complete lack of focus on the basics.

Or a complete focus on making money. Capitalism has refined itself over 30 years, and firms realize that security is expensive, making products is a lot cheaper than it used to be, and even if you invested in security, there could still be something unforeseen that compromises your system.

Nobody wants to be Sony or Microsoft and their litany of security woes.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#114

This is not a failure of the security industry - the security industry is targeted at the enterprise, largely not the host of the vulnerable IoT devices involved. Don't get me wrong, there are tons of ways in which the security industry fails (the biggest IMHO is buying/selling things that only get implemented in a half-@$$ed manner or not at all), but this is like blaming the Airline industry for a train wreck. Perh…

I think you are making a great point here: different sectors have different security needs.

At the consumer level, I think users really need help from their ISPs. My provider (Cox.net) already emails me if they detect outbound activity matching virus activity. Though I can't say it doesn't make me at least a little nervous about their inspection of my traffic habits, this ISP level intervention is at least something concrete that could happen in the near term to blunt these types of attacks.

For Enterprises, I see the big failing is mostly around the focus on external threats (APT+Scary Hackers) with no consideration for the much greater danger of internal threats [1]. This is the "dumb" stuff like someone quitting to move to a competitor and the day before they give notice they copy every file off the file server to a thumb drive "just in case they need it". Or even the new scary forms of user assisted ransomware.

1 - The guy that runs HaveIBeenPwned.com has a free course on this I've been sending around https://info.varonis.com/the-enemy-within that explains it in terms an executive might understand.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#115
post #6

I like how the author complains about cyberpocalypse conference talks then goes on to say the security industry is broken... Hard coded creds and the allowance of default creds isn't the security industry, it's the manufacturer.

"You didn't fix this problem a third-party created! You are at fault!"

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#116

Earlier quoted context omitted.

Maybe we need liability for software vendors? That's a common suggestion, but since no-one knows how to make completely secure systems yet, I don't think it's that simple. If you're talking about a general presumption that anyone selling software that has a security vulnerability becomes liable for any consequential losses, then it seems likely to result in only large businesses with the war chest to fight a liabilit…

> That's a common suggestion, but since no-one knows how to make completely secure systems yet We also do not know how to make completely secure cars, but still car makers are liable for faulty construction.

But not for someone who robbed a bank and used the car as a getaway vehicle.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#117

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…

This solves one incentive problem, but not (in my opinion) the main one. The people responsible for security (i.e. corporate IT departments) are quite often not the same people who would suffer in the event of one (i.e. customers). Therefore, security professionals are mainly incentivized to appear trustworthy.

Actually being trustworthy is certainly the easiest way to do this, at least up to a point. But it tends to push people toward public, visible security measures over private, invisible ones, regardless of their relative effectiveness.

It cuts both ways, too. Even if you do everything right, if you do get hacked that trust is gone and no insurance payout can buy it back. And I'm not sure any customer is going to react well to "Yeah we lost your data, but Goldman Sachs claims it's not our fault".

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#118
post #8

How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.

That'll work until the database of device credentials is breached from company X which provides call center support services for manufacturers A through Z and needs said credentials at hand.

That is a failure condition, but it is strictly better than what we commonly have now: universal default passwords.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#119
post #15

Maybe we need liability for software vendors? With exemption for those who provide full source code.

A proposal I saw and liked was liability for software vendors based on what they charge for the software, so open source software doesn't have the problem, but people who bundle a load of open source software together, slap a management interface on it and charge loads of cash for that, do.

What if I give away the software and then sell support contracts?
Post reply on HN