The "security industry" was never significantly involved in improving product security and software quality. They have roots in profiting from the deplorable state of PC security. Centralised firewalls, "intranets", and anti-virus products are not sustainable solutions to any of these problems - they're just so ingrained in the mindset of IT profiessionals that they self-perpetuate.
Endpoint security traces back to antivirus and PC security. Firewalls do not --- firewalls trace back to the Unix culture.
The Mirai Botnet Is Proof the Security Industry Is Broken
181–190 of 260 posts
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#182Earlier quoted context omitted.
UL isn't a regulatory body. UL testing is voluntary. You may know this, but perhaps many others don't. I think a UL for internet connected devices is a fantastic idea. Just need to figure out how to get companies to volunteer for such testing. The way it works for UL is that they provide some insulation from litigation. Perhaps if users could litigate IOT manufacturers for inadequate security testing, something simil…
Retailers (Walmart) require UL for insurance propose. UL is created for by Insurance companies to gauge the safety of the products. At the end, the real cause is "The force of Lawyers" is strong for product safety in US. :-) "The force of the lawyers for IOT" is still weak. :-) The force of the Jedi (IT, hackers, SW Dev, EFF, OSF) still strong, for now.... The Empire will win when and if enough Jedi (SW Dev) turn to…
Silly FUD like this does nothing to help.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#183Earlier quoted context omitted.
This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…
This solves one incentive problem, but not (in my opinion) the main one. The people responsible for security (i.e. corporate IT departments) are quite often not the same people who would suffer in the event of one (i.e. customers). Therefore, security professionals are mainly incentivized to appear trustworthy. Actually being trustworthy is certainly the easiest way to do this, at least up to a point. But it tends to…
If someone company gets hacked, a consumer's gets leaked, and 3 years later that info is used to steal that person's ID, how is that consumer supposed to determine the root cause?
The real problem is that the effects of bad security are very far downstream from the initial problems in space, time, and individuals affected, so proper feedback to those responsible happens very slowly or not at all.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#184As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…
With IoT, this may catch the low hanging fruit, sure. Negligence for poor defaults, fine? But then attackers will just evolve to the next lowest fruit. Keep in mind that to some attackers, finding a software or hardware bug to exploit (and weaponising that), even in highly "secure" systems, is probably just a step or two beyond playing with default credential lists. The author of this article compares the complexity…
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#185Earlier quoted context omitted.
Endpoint security traces back to antivirus and PC security. Firewalls do not --- firewalls trace back to the Unix culture.
[citation needed]
People were building firewalls in 1988, several years before there was even Trump Winsock, let alone a reason for PCs to need to filter Internet traffic.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#186The only way out of this mess is regulation of what types of devices can be sold and how they must be secured. The electronics industry and online retailers need to get together and figure this out and come up with a UL for IoT, or the government will step in and make them all a lot more unhappy.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#187Earlier quoted context omitted.
In some respect, there's been a level of insurance like requirements for some segments. PCI DSS. It's been a decade of so since I had to deal with it, but the requirements were for the most part no nonsense good practices, and instituted a base level of security that was good. Separated DB and application servers. Specific SQL access credentials. Firewalls with pinhole access. Restricted network access for some serve…
The problem I had with PCI DSS is that you could check the boxes and if you are never audited, you don't actually have to fix those problems. I worked for a place that ran that way for ~3 years.
1: http://www.focusonpci.com/site/index.php/pci-101/pci-noncomp...
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#188Earlier quoted context omitted.
This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…
I'd buy infosec insurance, if such a device existed. Premiums go down the more secure your site, the security work itself being a standardized checklist. Forces the snake-oil salesmen out because they'd have to pay out in the event of a breach. Like you, I have no idea what I'm talking about, but as OP demonstrated you can do everything right and get unlucky, or do nothing right and get lucky. Sounds perfect for some…
That shit will bring out the snake-oil men harder than anything. It means those peeps will do all they can to get the auditors to think you are more secure.
Instead, have a requirement of some compliance, with penalties for breaking compliance.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#189As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…
IANAL, so I wonder if that would actually work. Especially since everyone always attaches the standard no-warranty disclaimers to software (and we're talking about vulnerabilities in the software on these devices).
Maybe we need to give the FCC power similar to the CPSC.. they can issue recalls of unsafe products (or in the case of the FCC, products that interfere with our communications infrastructure), and they can even have them stopped at the border by customs.
Losing the ability to sell your product in the US is a pretty powerful incentive to get it right
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#190Earlier quoted context omitted.
> Sure, as a customer I could insist on my manufacturer having taken security seriously and having their products thoroughly tested and reviewed and hardened and patchable and all that good stuff How exactly would you insist on that? Ask them? Aren't they going to tell you, "Yes, it's very secure, no worries"?
> How exactly would you insist on that? How about "show me three different independent security audits by researchers or firms I trust who didn't find major issues in your product"? Sure, there needs to be a sizable group of people demanding that (and be willing to have it be the difference between a $500 and a $5K smart TV), but it is possible. For corporate IoT in certain settings, it might even be plausible.
Note that open-sourcing the firmwares would go great lengths in building a better world: Less spying, more upgradeability, more confidence in the tools, easier pentests and a legacy of new code for future generations.