I work in the infosec field and I think it is unfair to blame the whole industry. I think the whole technology field is to blame here (although I really don't like to play the blame game). By the way, I have been around the security industry for around 10 years, and the same exact conversation has been going on. 10 years ago it was the Web, then around 7 years ago it was Mobile, now it is IOT, several years from now,…
I'm fond of the idea of fines. Having seen what audits mean, I trust them about as far as I can throw a full-size African elephant bull.
The Mirai Botnet Is Proof the Security Industry Is Broken
141–150 of 260 posts
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#142Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#143Earlier quoted context omitted.
"How many pennies would've been needed to insert a simple page forcing you to change user/password combo and to choose a reasonably strong password after first boot ?" These are written by outsourced developers who don't know anything about security. They wouldn't even think to develop something as simple as that. You are obviously unaware of how this works, companies would have to hire consultants/penetration tester…
Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery. In your app you already have a setup wizard, right ? Add one more page to the end "Hey, we're almost done! We just need to make sure your device is secure. Please choose a username and (strong) password." Edit: Because if you have a logi…
Then you are not talking about the security industry or its failure to work are you? Its a failure in the development industry to have basic security awareness.
If you don't engage the security industry for pentests or consulting. You can't go any blame them when you get hacked.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#144Earlier quoted context omitted.
However, if it is a very wide spread problem then they will eventually install a light on your dash to notify you to change your oil. My wife's car currently does this. Since this is the first car she's ever owned, it's good because I don't think she would have known. We also have check engine lights and indicators for when a turn signal light bulb stops working. New cars even keep track of things like tire pressure.…
> However, if it is a very wide spread problem then they will eventually install a light on your dash to notify you to change your oil. My wife's car currently does this. Since this is the first car she's ever owned, it's good because I don't think she would have known. We also have check engine lights and indicators for when a turn signal light bulb stops working. New cars even keep track of things like tire pressur…
> Not knowing better or being too busy is not an excuse to be a party to a DDoS attack.
I feel you contradicted yourself here. In one way you excuse it, but you also claim users should know better. When it comes to having a strong password, I feel this is where it's acceptable to place blame. When, for example, they went to their favorite website which has a malicious ad that takes advantage of the latest exploit. Can they really be blamed? Average end users expect their smart thermostat to give them capabilities advertised. Some can't even imagine that it's basically a small computer.
> that violate the contract you signed with your ISP
How many people really read these agreements? It's assumed that if your computer works it's in spec. Whatever arbitrary clause they came up with to allow them to legally track your every move is a different conversation.
I won't divulge into throwing analogies back and forth. I'll just say this, I know plenty of Dr's, people who are much smarter than me that don't know a thing about networking. They're running their own practice and stay concerned about being up to date and not getting sued. That's their job. Building software that is easy enough to use while keeping people secure is ours. There's no excuse, it's hard and it's yet another aspect programmers need to learn. But it rests on our shoulders.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#145Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#146It's not the failure of the security industry, it's the success of market forces over the security industry. Normal folk want to consume new gadgets because that's the culture we have. So it's a race to put new gadgets with new features in front of people. Sure, as a customer I could insist on my manufacturer having taken security seriously and having their products thoroughly tested and reviewed and hardened and pat…
For example, the NSA's security -- not some underfunded, minor agency, but the NSA itself, the world's leading cybersecurity agency -- has had its security breached on a large scale basis, multiple times.
And that is just the beginning of the very long list. It's not unique to the US, either; other governments are the same or even worse in terms of security.
Given that government cannot even create working policies to secure systems that it directly controls, even in agencies with practically unlimited budgets and the strongest possible security mandate, how on earth can it be expected to create policy for anyone else, to supervise systems it does not even control, for commercial users with tiny or no budgets?
Issuing nice-sounding legal regulations that say 'go forth and be secure' will accomplish nothing.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#147Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#148I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…
This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#149I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…
Basically some developers need to go to jail for gross negligence.
At the end of the day a few people who can't afford super lawyers go to jail, and meanwhile ubercorp producing cheap routers with bad security continue with business as usual.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#150As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…