I mean, it's 100% going to happen again, and it was plainly obvious it was going to happen to begin with. We did a Black Hat talk about this (checks notes) 14 years ago, after being paid by a client to audit something like 12 different agent-based management systems: https://web.archive.org/web/20061215050427/http://www.matasa... Agent-based endpoint management is super convenient and is mainstream in modern IT manag…
SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
141–150 of 294 posts
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#142Earlier quoted context omitted.
Some questions a security professional should ask: 1. What happens when the root password is guessed by a malicious person? 2. What happens when a trusted employee is really an enemy agent? 3. What happens when we download and install a malicious update from a trusted vendor? 4. What happens when the server room burns down? 5. What happens when a malicious USB stick is plugged into our secure network? 6. What happens…
Just to be blunt, here are wrong answers: 1. make the root password unguessable and change it often 2. background check employees 3. audit trusted vendor's security procedures 4. install sprinklers (!) 5. jam all USB ports with glue 6. train CEO on laptop security protocol
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#143Earlier quoted context omitted.
Detection is inadequate, because detecting the open barn door after the horse left is not helpful. > Sprinklers That is "we can prevent the server room from being destroyed" thinking, rather than "how do we survive the server room being destroyed" I'm proposing.
Youre suggesting detection is only possible much after the fact, when it is possible to also do before an adversary has been able to achieve anything significant on the target. But credit where credit is due, detection is not the answer but rather early detection. Sprinklers comment was made in jest.
The defeat was to chop the phone line where it entered the house, because the telephone company puts their box on the exterior of the house. (The book was printed before cell phones.) The sophisticated $$$$ detection system, defeated by the simple swing of an axe.
Relying on detection requires a perfect detection system, which is impossible.
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#144Earlier quoted context omitted.
No, they don't. Their safety record is incredibly good, especially considering you're zipping along at 500 mph in an aluminum balloon at 30,000 feet with flaming engines and surrounded by jet fuel. They really are a triumph of engineering.
yes, but also with 100+ years of engineering, for far fewer companies/nations, and with trillions (more?) thrown at the discipline. Software engineering is, what, 50 years old, tops?
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#145Earlier quoted context omitted.
Just to be blunt, here are wrong answers: 1. make the root password unguessable and change it often 2. background check employees 3. audit trusted vendor's security procedures 4. install sprinklers (!) 5. jam all USB ports with glue 6. train CEO on laptop security protocol
what are some right answers?
1. don't store everything on the machine(s) accessible via that root password
2. don't allow any employee unfettered access to everything
3. don't allow one piece of software to have access to everything
4. do not store backups in the server room, or even in the same building
5. buy computers that do not have USB support in any form
6. full disk encryption on laptop. Minimize sensitive data on laptop. Use smallest capacity disk drives on laptop. Don't allow any laptops to have access to secure network. Issue hardwired desktops to employees. No wifi to secure network.
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#146Earlier quoted context omitted.
yes, but also with 100+ years of engineering, for far fewer companies/nations, and with trillions (more?) thrown at the discipline. Software engineering is, what, 50 years old, tops?
Unfortunately, sophisticated threat actors are still very hard to defend against in aviation like in software.
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#147Earlier quoted context omitted.
Just to be blunt, here are wrong answers: 1. make the root password unguessable and change it often 2. background check employees 3. audit trusted vendor's security procedures 4. install sprinklers (!) 5. jam all USB ports with glue 6. train CEO on laptop security protocol
what are some right answers?
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#148Earlier quoted context omitted.
what are some right answers?
I'm not a security professional, but I'll spend a couple minutes and make a stab at it: 1. don't store everything on the machine(s) accessible via that root password 2. don't allow any employee unfettered access to everything 3. don't allow one piece of software to have access to everything 4. do not store backups in the server room, or even in the same building 5. buy computers that do not have USB support in any fo…
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#149Earlier quoted context omitted.
How to defend against these: 1) detection 2) detection 3) detection 4) sprinklers 5) detection 6) detection unfortunately, most orgs outsource their internal detection or have no capability at all.
Detection is inadequate, because detecting the open barn door after the horse left is not helpful. > Sprinklers That is "we can prevent the server room from being destroyed" thinking, rather than "how do we survive the server room being destroyed" I'm proposing.
And you are wrong in labeling it "prevention". It is a feedback mechanism. Fast feedback is essential in almost ANY scenario. Most of the things can be fixed if detected early on.
The first thing is knowing. If you don't know something, you can't act on it. To take your battleship analogy, if I remove all torpedo sensors from the ship, how long will it last given it is compartmentized and whatnot.
Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president
#150Earlier quoted context omitted.
I'm not a security professional, but I'll spend a couple minutes and make a stab at it: 1. don't store everything on the machine(s) accessible via that root password 2. don't allow any employee unfettered access to everything 3. don't allow one piece of software to have access to everything 4. do not store backups in the server room, or even in the same building 5. buy computers that do not have USB support in any fo…
However, with each new thing resources needed to implement and operate go up to the point when it is not feasible - money, people, time ...