Live data from Hacker News

Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

forbes.com

21–30 of 40 posts

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#21
post #8

Earlier quoted context omitted.

Use their same language back at them and talk about your "compensating controls". That's auditor lingo for I know A is the standard control but by doing B and/or C instead I have adequately addressed the risk.

So, what would be the compensating control for infecting yourself with malware?

For a system in the scope of the audit, if you can demonstrate that the files coming in are checked for malware before they get on your critical systems, this is one example of a compensating control.

Further, if you can demonstrate in auditable fashion that there are no browsers or other network connections or other typical vectors for infection, that can be a compensating control.

[Edit]

Or if you can demonstrate that your email system will drop all attachments and links, that would be another (annoying) way.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#22
post #16

Earlier quoted context omitted.

From your HN user profile, "At Nektra we are providing solutions that require Windows system internals and reverse engineering skills." http://www.nektra.com

Yes, that is the reason I made the disclosure. Almost all of our work involves intercepting, modifying, and integrating third party applications with Windows when Windows doesn't provide APIs to do this.

So are you using undocumented windows APIs or hooks?

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#24
post #20
post #12

Earlier quoted context omitted.

Which auditor, and for what regulation?

Most certifications, and in particular, ISO 27001 asks if you have anti-malware running. Now, the thing about ISO and many of the other certifications, if you can demonstrate some mitigating control, say aggressive network monitoring, or pre-scanning files before they get loaded onto your target system, then you can pass. For example, http://www.iso27001security.com/html/27002.html on 12.2 mentions this, along with a…

Will ask whether your EC2 instances have anti-malware on them?

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#25
post #10

Earlier quoted context omitted.

I have filled out a few applications for tech e&o and cyber liability insurance over the past week and they all had a question about antivirus on the servers, workstations, and phones. I answered truthfully (no) and wonder if that is going to hurt me.

It will be interesting what an insurance company thinks is needed. If having an antivirus can create possibly more security holes than it closes - then from an insurance perspective they would not want you to have it. i.e. if they have to pay based upon an attack - they want to ensure the lowest risk.

If people understood those that were building the Cyber liability policies within the big firms, they'd realize few have a clue. Having worked with the big 5 for years now on this, many are so far behind on reality it hurts.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#26
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

I'm in that same boat with both exploit and performance concerns. I'm trying ClamAV right now. For auditing and hardening I used Lynis. Any other tools you recommend? I need an external scanning tool.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#27
post #24
post #20

Earlier quoted context omitted.

Most certifications, and in particular, ISO 27001 asks if you have anti-malware running. Now, the thing about ISO and many of the other certifications, if you can demonstrate some mitigating control, say aggressive network monitoring, or pre-scanning files before they get loaded onto your target system, then you can pass. For example, http://www.iso27001security.com/html/27002.html on 12.2 mentions this, along with a…

Will ask whether your EC2 instances have anti-malware on them?

Yes, for all systems in scope. If you are putting code and/or files there, they will ask.

But as I note in other threads, you have a good chance of demonstrating some compensating controls.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#28
post #21

Earlier quoted context omitted.

So, what would be the compensating control for infecting yourself with malware?

For a system in the scope of the audit, if you can demonstrate that the files coming in are checked for malware before they get on your critical systems, this is one example of a compensating control. Further, if you can demonstrate in auditable fashion that there are no browsers or other network connections or other typical vectors for infection, that can be a compensating control. [Edit] Or if you can demonstrate t…

So, in a typical SAAS cloud application environment, is ISO 27001 just off the table for anyone serious about security? As (in effect) the CSO for a bunch of decently-sized startups, I would have a hard time approving the deployment of any kind of antimalware tool, because the risk simply isn't worth the reward. Even when deployed on isolated systems and not every end system and server, they're still intrinsically dangerous systems: they're essentially most of the attack surface of a browser.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#29
post #8
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

Use their same language back at them and talk about your "compensating controls". That's auditor lingo for I know A is the standard control but by doing B and/or C instead I have adequately addressed the risk.

This is insightful.

Ran into this sort of thing at a .gov during audits for systems accreditation in 200x. I made the mistake of using 'mitigation' in my documentation and opened up a can of worms with the contracted auditing firm. They should have provided a glossary of weasel words.

Took twice as long to get the system accredited because of a common sense initial approach.

Post reply on HN