Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

171–180 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#171

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

> You could have no security and just get lucky and never get hacked. It's been a decade and more since that was even remotely true (if it ever was). Back in 2008 the average survival time of an unpatched internet facing XP box was around 4 minutes [0]. Pwning an unpatched XP box was (very marginally) harder than pwning a system with no security at all. The Morris worm (Edit: which is heavily mentioned in TFA, my bad…

>>Back in 2008 the average survival time of an unpatched internet facing XP box was around 4 minutes [0].

Yep. And that's just the average. It was much, much lower for high-value targets, such as universities. The first thing we did at my Network Security class back in 2006 was to hook up an unpatched XP machine to the Internet. It got pwned in about 30 seconds.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#172
post #55

Earlier quoted context omitted.

I'm asking: why would you make a bounty conditional on "access" at all? What's the win? A bug is a bug. If it has the potential for access, it's worth the bounty. All a demonstrated access requirement does is encourage strangers to violate the privacy of your customers. It seems like an incredibly reckless idea.

Bad actors are already trying to get that data, no?

Yes, but what does that have to do with the structure of a bounty?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#173
post #54

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

Basically some developers need to go to jail for gross negligence.

[deleted]

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#174

As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…

As someone who has dozens of these cheap SSRs, thanks for this. A lot of them don't even have English labels on them. I'll be sure to not use them in any critical situation or something that might be fire-prone.

Tear-down reports indicate that the big problem is way overrated current ratings. Real SSRs start at 5A, which isn't too expensive, and prices go up with the current rating. Fake SSRs start at 25A, and have maybe 10A components inside. Past 10A or so, you have to add a heat sink, which a lot of the fake vendors don't mention.

If you want cheap SSRs, it may be better to order them directly from, say, LIRRD in China.[1] They make solid-state and mechanical relays under their own name, and have UL certification in their own name. There's a minimum order (40 units), but they will send samples. The prices are about as good as the fakes.

[1] https://www.alibaba.com/product-detail/UL-ROHS-dc-to-ac-sing...

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#175
post #7

The "security industry" was never significantly involved in improving product security and software quality. They have roots in profiting from the deplorable state of PC security. Centralised firewalls, "intranets", and anti-virus products are not sustainable solutions to any of these problems - they're just so ingrained in the mindset of IT profiessionals that they self-perpetuate.

I get what you're going for but you're actually wrong. Both firewalls centralised or not (configure to prevent all access outbound apart from approved nodes) and intranets (put IoT in isolation) would actually prevent Mirai from both spreading and attacking anyone. But most people are not implementing either, because home router is all you need...

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#176

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

Fire the current crop of security cert vendors and start designing them practically. I may be in the minority, but every {insert security title here} I've ever encountered seems to have an alphabet soup after their name and no hard skills.

Makes me feel bad for the competent security researchers having to share their field with glorified PowerPoint designers.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#178
post #15

Maybe we need liability for software vendors? With exemption for those who provide full source code.

X writes secure code, Y writes secure code, Z integrates both parts in a secure way. X creates a secure update. X releases an update which makes a race condition with Y leading to elevated privileges possible in Z's product. Who's liable for the issue now?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#179

Earlier quoted context omitted.

This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…

Seems to me that the core of insurance is actuarial analysis of the potential risks and costs... and I don't think anyone has a good model or good data for when and why security problems occur. For the time being (and perhaps for the rest of time) we need a security crash reporting agency, analogous to a transportation crash reporting agency, e.g. the US NTSB. Getting standard reporting on security breaches might be…

This. We model death rates somewhat accurately. Health care costs somewhat less so. Macro financial systems somewhat less so. I'd put "assign risk to a moderate sized enterprise's network of data systems" at more complex than all of those.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#180

Great example of how to promote your company. Provide genuinely insightful and useful information that will help people even of they don't use your product. It's almost like good karma.

I prefer when people do that without trying to discredit whole industry which wasn't even involved in the problem. If anyone remotely interested in security was included in the IoT production, we wouldn't be talking about Mirai.
Post reply on HN