Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

201–210 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#201

Earlier quoted context omitted.

Bad actors are already trying to get that data, no?

Yes, but what does that have to do with the structure of a bounty?

Bounty programs are very noisy. I don't even have a bug bounty program, and have several messages from confused people in my inbox asking about one. The "bugs" they propose are not bugs in my programs---for example, one reports that data can be uploaded to a collaboration system, downloaded, and then executed in a user-provided interpreter---and that this interpreter may surprise the user with its behavior.

Any better ideas of how to structure a bounty to get bugs and not confused users?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#202
post #184

Earlier quoted context omitted.

Isn't the goal of security to remove the lowest hanging fruit and keep at it?

In one sense, sure. But IMO regulating the IoT "industry" in a general way is a bad idea because it will just shift the low hanging fruit around some, while ultimately stifiling innovation, which is what is needed for any deep, meaningful security to happen in the long term .

I cannot take this idea that "innovation" will be stifled because people were told to actually give a shit about what they were doing. Honestly, if it means that fly by nite groups aren't releasing their "innovations" out there, I'd consider it a pretty good trade.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#203
The Moral botnet doesn't have anything to do with the "security industry", largely because the vendors involved ignored each and every recommendation made by said industry since at least the 90's if not earlier.

The blame for this debacle falls squarely on the heads of the vendors who produced these trusting (if not downright gullible) devices in the first place.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#204

Earlier quoted context omitted.

Bad actors are already trying to get that data, no?

Yes, but what does that have to do with the structure of a bounty?

Saying something is theoretically possible with automated vulnerability scanners (which have incredibly high type 1 error due to out of date headers due to lazy programmers and misconfigured webservers) and showing that it's actually possible are completely different things. A whitehat proving he can get user access or MITMing data they created as a proof of concept is completely benign. I've yet to hear this as the source of a leak of customer data.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#205
post #77

Earlier quoted context omitted.

> When I was your age I was leaving the security industry before it was cool I'm not interested in leaving the security industry. I'd rather work to change it. I'm a millennial, I guess :) > The "security industry" is not in fact chartered with stopping things like Mirai. So Mirai is a weird complaint to level at it. No one "chartered" the industry to do anything. You're right, a metal box or an AV isn't going to pre…

No? I am having a hard time seeing any intersection between either of the major two branches of the security industry (PC security and network security) and IoT botnets. There's a major failure happening, but it's not attributable to the security industry. It's a failure of the computing industry as a whole.

If there will always be crap out there, everyone's going to need an immune system. Long term, we can wish for a fancy adaptive one. In the short term, we probably just get an analogue to inflammation---something like the DDoS network scrubbing industry.

That doesn't try to stop IoT botnets; it just extracts rent for keeping some people safe from them.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#206
post #18
post #4

My toaster has to be certified that it meets certain minimum safety standards. It really seems that IoT and safety critical software/firmware should be required to pass a similar (bare minimum) certification.

Toaster is required to pass safety standards because of the there is strong economic incentive (UL requirements) to do it. Without UL, it can't get on the shelf on any stores in US. There are no such thing and UL security requirements for IOT device. Time for such regulation? But "internet + regulation" normally raise a lot of objections internally from the IT industry. If someone (MSFT) proposes secure boot are requ…

> If someone (MSFT) proposes secure boot are required for all IOT devices, the first one to oppose it likely be EFF. :-)

Rightfully so. Anyone who argues signing without user override is necessary to achieve devices secure against external attackers is outright lying.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#207
post #158

As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…

I don't follow your comment. I'm not sure how you can claim that Solid state relay is fake. Also poor security practices in IoT devices and counterfeits sounds like 2 completely different topics. Let me play the devil's advocate: How can you be sure [1] is fake? To me the picture looks like the real one reported in [2]. It is also 2.5x the price of the fake one reported in [2]. You also say there are lots of unhappy…

Animats said "There's a problem at the China end with crap low-end devices driving out the good ones"

That is the connection between the two topics. You go on Amazon and no one is selling quality. A lawsuit would kill the crap products and you are left with the certified / branded / or otherwise 'proven' good products.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#208

Earlier quoted context omitted.

> You could have no security and just get lucky and never get hacked. It's been a decade and more since that was even remotely true (if it ever was). Back in 2008 the average survival time of an unpatched internet facing XP box was around 4 minutes [0]. Pwning an unpatched XP box was (very marginally) harder than pwning a system with no security at all. The Morris worm (Edit: which is heavily mentioned in TFA, my bad…

>>Back in 2008 the average survival time of an unpatched internet facing XP box was around 4 minutes [0]. Yep. And that's just the average. It was much, much lower for high-value targets, such as universities. The first thing we did at my Network Security class back in 2006 was to hook up an unpatched XP machine to the Internet. It got pwned in about 30 seconds.

What I don't get about this is how the new system is discovered in the first place, assuming the attacker is not already on the network. Sure, gain fast access, but why would you let the traffic on to the local net to discover the machine (except for examples). I can see a box stuck on a home connection getting pwned quick, but surely a Uni network would be blocking rdp traffic, or external pings, or whatever it was that was being used to find and pwn XP computers so quickly??

Wouldn't multiple attackers have to be effectively flooding the network with pings or service/port access attempts to find a new computer so fast?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#209

As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…

Given that most of the ddos attacks come from China, isn't it a reasonable assumption that the Chinese manufacturers are complicit in keeping the system broken?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#210

As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…

Given that most of the ddos attacks come from China, isn't it a reasonable assumption that the Chinese manufacturers are complicit in keeping the system broken?

Do most of the ddos attacks actually come from China? I thought they came from botnets of pwned PC's all over the world.
Post reply on HN