Earlier quoted context omitted.
404 for every link to the standards. Awesome!
You have to buy them... http://www.comm-2000.com/ProductDetail.aspx?UniqueKey=31733
[1]: http://ulstandards.ul.com/downloads/news-announcing-ul-2900-...
251–260 of 260 posts
Earlier quoted context omitted.
404 for every link to the standards. Awesome!
You have to buy them... http://www.comm-2000.com/ProductDetail.aspx?UniqueKey=31733
[1]: http://ulstandards.ul.com/downloads/news-announcing-ul-2900-...
Earlier quoted context omitted.
That's why we need the regulation in order to make them give a fuck.
What I'm ultimately arguing here is that: even after the regulators step in and make make them give a fuck, I mean really give a fuck, and they are forced to fix the low hanging fruits, these botnets or other similar machinations, will still exist. In fact, if we assume the regulations work and actually make things harder to exploit, we can add in the knowledge that the price for using and creating IoT botnets will g…
Earlier quoted context omitted.
What I'm ultimately arguing here is that: even after the regulators step in and make make them give a fuck, I mean really give a fuck, and they are forced to fix the low hanging fruits, these botnets or other similar machinations, will still exist. In fact, if we assume the regulations work and actually make things harder to exploit, we can add in the knowledge that the price for using and creating IoT botnets will g…
I completely and totally disagree. You're basically saying that, because it will become harder in the future, we shouldn't even try.
Earlier quoted context omitted.
I'd buy infosec insurance, if such a device existed. Premiums go down the more secure your site, the security work itself being a standardized checklist. Forces the snake-oil salesmen out because they'd have to pay out in the event of a breach. Like you, I have no idea what I'm talking about, but as OP demonstrated you can do everything right and get unlucky, or do nothing right and get lucky. Sounds perfect for some…
> Premiums go down the more secure your site That shit will bring out the snake-oil men harder than anything. It means those peeps will do all they can to get the auditors to think you are more secure. Instead, have a requirement of some compliance, with penalties for breaking compliance.
Earlier quoted context omitted.
"How many pennies would've been needed to insert a simple page forcing you to change user/password combo and to choose a reasonably strong password after first boot ?" These are written by outsourced developers who don't know anything about security. They wouldn't even think to develop something as simple as that. You are obviously unaware of how this works, companies would have to hire consultants/penetration tester…
Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery. In your app you already have a setup wizard, right ? Add one more page to the end "Hey, we're almost done! We just need to make sure your device is secure. Please choose a username and (strong) password." Edit: Because if you have a logi…
This is utterly ignorant of the facts, Mirai took advantage of weak passwords to spread, but was not dependent upon them.
Maybe we need liability for software vendors? With exemption for those who provide full source code.
X writes secure code, Y writes secure code, Z integrates both parts in a secure way. X creates a secure update. X releases an update which makes a race condition with Y leading to elevated privileges possible in Z's product. Who's liable for the issue now?
Earlier quoted context omitted.
I completely and totally disagree. You're basically saying that, because it will become harder in the future, we shouldn't even try.
Well I think we can agree to disagree on regulation as the method of fixing the issue. Of course we should do something . I'll admit I'm not sure what though and have no better proposal. I just believe regulation is too blunt an instrument.
Earlier quoted context omitted.
> Premiums go down the more secure your site That shit will bring out the snake-oil men harder than anything. It means those peeps will do all they can to get the auditors to think you are more secure. Instead, have a requirement of some compliance, with penalties for breaking compliance.
Honus is on the auditors to know what works and what doesn't. Auditors tell you "these are the things you must do to be compliant". Then the oilmen have to sell to people who lose money if they're wrong.
You need some kind of incentive that derives directly from the end goal (less breaches), rather than some derivative (better standards compliance). Auditors certainly have their place, but we need more than them.
edit: Also, you probably meant 'onus' rather than 'honus'.
Earlier quoted context omitted.
> However, if it is a very wide spread problem then they will eventually install a light on your dash to notify you to change your oil. My wife's car currently does this. Since this is the first car she's ever owned, it's good because I don't think she would have known. We also have check engine lights and indicators for when a turn signal light bulb stops working. New cars even keep track of things like tire pressur…
> And likewise, if someone sabotages your car or has a remote exploit for your computer, I find it hard to dish out blame. > Not knowing better or being too busy is not an excuse to be a party to a DDoS attack. I feel you contradicted yourself here. In one way you excuse it, but you also claim users should know better. When it comes to having a strong password, I feel this is where it's acceptable to place blame. Whe…
There might be a meaningful difference to me between a remote kernel hole versus using a default password, but for most people there is no difference there.
So you've changed my mind, to an extent. I don't think that we should "blame" them, but at the same time, if you entrust a large part of your life into computers and are not aware of the risks you're putting yourself in, I do think you deserve some blame for believing the advertising pitch without researching on your own-- and that kind of blame is relevant for everything, from cars to tablets to vacuum cleaners. I think doing your due diligence is relevant to any topic, and people who don't put it in will reap what they sow. But that blame is more superficial-- you shouldn't have to become a mechanic to buy your car and you don't have to be a programmer to buy an IP camera.
Have you checked out this Mirai vulnerability scanner? Something everyone should do – whether a random home user or a large enterprise (and how many have CISOs?). It scans your IP and can pinpoint vulnerable devices: https://www.incapsula.com/mirai-scanner.html