Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

181–190 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#181
post #33
post #7

The "security industry" was never significantly involved in improving product security and software quality. They have roots in profiting from the deplorable state of PC security. Centralised firewalls, "intranets", and anti-virus products are not sustainable solutions to any of these problems - they're just so ingrained in the mindset of IT profiessionals that they self-perpetuate.

Endpoint security traces back to antivirus and PC security. Firewalls do not --- firewalls trace back to the Unix culture.

[citation needed]

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#182
post #91
post #40

Earlier quoted context omitted.

UL isn't a regulatory body. UL testing is voluntary. You may know this, but perhaps many others don't. I think a UL for internet connected devices is a fantastic idea. Just need to figure out how to get companies to volunteer for such testing. The way it works for UL is that they provide some insulation from litigation. Perhaps if users could litigate IOT manufacturers for inadequate security testing, something simil…

Retailers (Walmart) require UL for insurance propose. UL is created for by Insurance companies to gauge the safety of the products. At the end, the real cause is "The force of Lawyers" is strong for product safety in US. :-) "The force of the lawyers for IOT" is still weak. :-) The force of the Jedi (IT, hackers, SW Dev, EFF, OSF) still strong, for now.... The Empire will win when and if enough Jedi (SW Dev) turn to…

> No more IOT, raspberryPI, OpenWRT.... only Intel/Qualcomm/MSFT licensed UEFI controlled SecureBoot (Windows CE) devices, Lock down Chromebooks from Google will be allowed.

Silly FUD like this does nothing to help.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#183
post #117

Earlier quoted context omitted.

This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…

This solves one incentive problem, but not (in my opinion) the main one. The people responsible for security (i.e. corporate IT departments) are quite often not the same people who would suffer in the event of one (i.e. customers). Therefore, security professionals are mainly incentivized to appear trustworthy. Actually being trustworthy is certainly the easiest way to do this, at least up to a point. But it tends to…

The incentive problem goes even deeper than that, because customers themselves also don't have a good way to measure the costs of breaches.

If someone company gets hacked, a consumer's gets leaked, and 3 years later that info is used to steal that person's ID, how is that consumer supposed to determine the root cause?

The real problem is that the effects of bad security are very far downstream from the initial problems in space, time, and individuals affected, so proper feedback to those responsible happens very slowly or not at all.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#184

As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…

With IoT, this may catch the low hanging fruit, sure. Negligence for poor defaults, fine? But then attackers will just evolve to the next lowest fruit. Keep in mind that to some attackers, finding a software or hardware bug to exploit (and weaponising that), even in highly "secure" systems, is probably just a step or two beyond playing with default credential lists. The author of this article compares the complexity…

Isn't the goal of security to remove the lowest hanging fruit and keep at it?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#185
post #33

Earlier quoted context omitted.

Endpoint security traces back to antivirus and PC security. Firewalls do not --- firewalls trace back to the Unix culture.

[citation needed]

Not really, no. But: the first commercial firewall was Ranum's DEC SEAL. Ranum is an old-school Unix programmer. The first book on firewalls is "Firewalls and Internet Security", by Bellovin and Cheswick, who previously created one of the first firewalls (predating DEC SEAL) and possibly coined the name. Both of them are, as you'd expert, Unix nerds.

People were building firewalls in 1988, several years before there was even Trump Winsock, let alone a reason for PCs to need to filter Internet traffic.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#186
The success of Mirai is hardly the fault of the security industry. The security industry has been howling about lax default device security for decades, and how dumb it is to put your TV directly on the Internet, much less your refrigerator or your lightswitch. The electronics industry is the correct target.

The only way out of this mess is regulation of what types of devices can be sold and how they must be secured. The electronics industry and online retailers need to get together and figure this out and come up with a UL for IoT, or the government will step in and make them all a lot more unhappy.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#187

Earlier quoted context omitted.

In some respect, there's been a level of insurance like requirements for some segments. PCI DSS. It's been a decade of so since I had to deal with it, but the requirements were for the most part no nonsense good practices, and instituted a base level of security that was good. Separated DB and application servers. Specific SQL access credentials. Firewalls with pinhole access. Restricted network access for some serve…

The problem I had with PCI DSS is that you could check the boxes and if you are never audited, you don't actually have to fix those problems. I worked for a place that ran that way for ~3 years.

Yeah, it is a sort of honor system, but I'm sure if you were hacked, and they see you aren't compliant, it won't go well for you. The fines get steep fairly quick[1][2]. Considering it mentions you might be charged $50-$90 per card even if you are compliant. Although I think those are actually fees for the issuers, I can't imagine they don't have a way to pass then along to merchants.

1: http://www.focusonpci.com/site/index.php/pci-101/pci-noncomp...

2: https://www.pcicomplianceguide.org/pci-faqs-2/#15

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#188

Earlier quoted context omitted.

This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…

I'd buy infosec insurance, if such a device existed. Premiums go down the more secure your site, the security work itself being a standardized checklist. Forces the snake-oil salesmen out because they'd have to pay out in the event of a breach. Like you, I have no idea what I'm talking about, but as OP demonstrated you can do everything right and get unlucky, or do nothing right and get lucky. Sounds perfect for some…

> Premiums go down the more secure your site

That shit will bring out the snake-oil men harder than anything. It means those peeps will do all they can to get the auditors to think you are more secure.

Instead, have a requirement of some compliance, with penalties for breaking compliance.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#189

As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…

someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers

IANAL, so I wonder if that would actually work. Especially since everyone always attaches the standard no-warranty disclaimers to software (and we're talking about vulnerabilities in the software on these devices).

Maybe we need to give the FCC power similar to the CPSC.. they can issue recalls of unsafe products (or in the case of the FCC, products that interfere with our communications infrastructure), and they can even have them stopped at the border by customs.

Losing the ability to sell your product in the US is a pretty powerful incentive to get it right

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#190

Earlier quoted context omitted.

> Sure, as a customer I could insist on my manufacturer having taken security seriously and having their products thoroughly tested and reviewed and hardened and patchable and all that good stuff How exactly would you insist on that? Ask them? Aren't they going to tell you, "Yes, it's very secure, no worries"?

> How exactly would you insist on that? How about "show me three different independent security audits by researchers or firms I trust who didn't find major issues in your product"? Sure, there needs to be a sizable group of people demanding that (and be willing to have it be the difference between a $500 and a $5K smart TV), but it is possible. For corporate IoT in certain settings, it might even be plausible.

You should be on top. Just as we have FCC approvals before you connect a device to 3G, landlines or to the power grid, we'll have to have approvals for all devices connected to the internet. And the top test of the list is a penetration test by a preapproved firm.

Note that open-sourcing the firmwares would go great lengths in building a better world: Less spying, more upgradeability, more confidence in the tools, easier pentests and a legacy of new code for future generations.

Post reply on HN