Live data from Hacker News

SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

reuters.com

151–160 of 294 posts

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#151

Earlier quoted context omitted.

Detection is inadequate, because detecting the open barn door after the horse left is not helpful. > Sprinklers That is "we can prevent the server room from being destroyed" thinking, rather than "how do we survive the server room being destroyed" I'm proposing.

It may be helpful if you have more then 1 horse. And you are wrong in labeling it "prevention". It is a feedback mechanism. Fast feedback is essential in almost ANY scenario. Most of the things can be fixed if detected early on. The first thing is knowing. If you don't know something, you can't act on it. To take your battleship analogy, if I remove all torpedo sensors from the ship, how long will it last given it is…

> Most

That's still focusing on making components that will not fail, rather than a system that can tolerate failure.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#152
post #118

Earlier quoted context omitted.

That's pretty much the concept of defense-in-depth, and breaches like Solar Winds of others like this kind of threat actors, are so sophisticated that they do work around every single aspect of this.

> are so sophisticated Their password was "SolarWinds123". Everyone who gets pwnd tells a story about sophisticated state actors to make it sound like some unstoppable force has hit their impenetrable defences.

Yeah and often, what makes state actors so threatening is not their untold leetness but the impunity with which they can operate. Common cybercriminals usually know better than to go after certain targets, but state actors can do whatever they please and will not face legal repercussions.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#153

Earlier quoted context omitted.

Youre suggesting detection is only possible much after the fact, when it is possible to also do before an adversary has been able to achieve anything significant on the target. But credit where credit is due, detection is not the answer but rather early detection. Sprinklers comment was made in jest.

I bought a book some years back about how to defeat burglar alarm systems, as I wanted to make my home more resistant to burglars. The book described a sophisticated system that would detect burglar entry and then automatically phone the cops. The defeat was to chop the phone line where it entered the house, because the telephone company puts their box on the exterior of the house. (The book was printed before cell p…

You can expect single detection system to fail, so you need to make it redundant. For example impossibly loud siren.

Like you said before, any solution is a mix of 2 paradigms.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#155

Earlier quoted context omitted.

It may be helpful if you have more then 1 horse. And you are wrong in labeling it "prevention". It is a feedback mechanism. Fast feedback is essential in almost ANY scenario. Most of the things can be fixed if detected early on. The first thing is knowing. If you don't know something, you can't act on it. To take your battleship analogy, if I remove all torpedo sensors from the ship, how long will it last given it is…

> Most That's still focusing on making components that will not fail, rather than a system that can tolerate failure.

Why do we have pain receptors then ? Nature sux as designer ?

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#156

Earlier quoted context omitted.

Youre suggesting detection is only possible much after the fact, when it is possible to also do before an adversary has been able to achieve anything significant on the target. But credit where credit is due, detection is not the answer but rather early detection. Sprinklers comment was made in jest.

I bought a book some years back about how to defeat burglar alarm systems, as I wanted to make my home more resistant to burglars. The book described a sophisticated system that would detect burglar entry and then automatically phone the cops. The defeat was to chop the phone line where it entered the house, because the telephone company puts their box on the exterior of the house. (The book was printed before cell p…

If we're looking at how to do detection right in IT systems, the physical world example you give doesn't really apply all that well. First the environment is different and second threat detection in IT infra is a multi-stage process involving probabilities on each stage. You can't cut the wire and disable them all from one spot. (or you can if you slice the cable, but then you cut your access too - and a bunch of other collateral...)

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#157

I've found my experience designing gearboxes for Boeing has applicability to software design. For example, the fundamental idea with airplane design is not to design components that cannot fail, as that is impossible. The idea is to design the system to be tolerant of failure . Every part in the system is not "how can we make this part never fail" but "assume it failed. How does the airplane survive?" This is a funda…

Some questions a security professional should ask: 1. What happens when the root password is guessed by a malicious person? 2. What happens when a trusted employee is really an enemy agent? 3. What happens when we download and install a malicious update from a trusted vendor? 4. What happens when the server room burns down? 5. What happens when a malicious USB stick is plugged into our secure network? 6. What happens…

These hypothetical scenarios are not anchored with the language that most businesses will understand: cost.

Without providing the context of how expensive or cheap it will be to adhere to each of these best practices, it will be hard to convince those with decision-making authority to do the right thing, unless they are in a highly regulated environment to begin with.

An aircraft on the other hand is already very expensive to make, precisely because it involves transporting resources that are impossible to replace: human life.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#158

Earlier quoted context omitted.

However, with each new thing resources needed to implement and operate go up to the point when it is not feasible - money, people, time ...

It's always a tradeoff between how much to spend on security vs how much a breach is going to cost you. But if you are going to spend it on security, spend it on things that are more likely to work, rather than on impossible things.

From a risk perspective you're advocating bundling all of your eggs in one basket - perfect fault-tolerance & prevention - whilst that is actually a system nobody has built in the history of computing.

Neither detection or prevention can be perfect like nothing human-designed, but rather detection should be used to hedge yourself in situations where prevention fails.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#159

Earlier quoted context omitted.

A literal turn-key switch on the case would work. Turn the key one way to enable firmware updates. Turn it the other to disable them. This should also be easy to replace and come as a standard sized device. As an alternative, a 'security card' slot; similarly easily replaced or with an internal switch depressed re-'paired' to a new key.

Just a one cent slide switch will do the job. Even a jumper will do the job.

Ceremony is part of the need for a key or a card. This needs to have weight to average, even sub-average, end users.

It must be out of the ordinary. The ceremony must have weight and differentiation from typical activities. True going inside and moving a jumper is fine for those willing to open the case, but it must work on Gradnma's Dell; while under warranty, without voiding the warranty.

Re: SolarWinds hack was 'largest and most sophisticated attack' ever: MSFT president

#160

Earlier quoted context omitted.

Some questions a security professional should ask: 1. What happens when the root password is guessed by a malicious person? 2. What happens when a trusted employee is really an enemy agent? 3. What happens when we download and install a malicious update from a trusted vendor? 4. What happens when the server room burns down? 5. What happens when a malicious USB stick is plugged into our secure network? 6. What happens…

Just to be blunt, here are wrong answers: 1. make the root password unguessable and change it often 2. background check employees 3. audit trusted vendor's security procedures 4. install sprinklers (!) 5. jam all USB ports with glue 6. train CEO on laptop security protocol

> install sprinklers (!)

Sure you install sprinklers in a data center to sprinkle water on servers and other electric devices in a context where there might or might not be broken or other wise un-isolated wires due to the fire...

What you can use instead is to flood the room with CO2 to suffocate the fire.

The problem with that is that it's also deadly to humans.

Still e.g. for rooms with long term data storage it's not uncommon to have measurements like that.

Besides that there are docent of other reasons why a data center might go down (temporary).

So the better answer is make sure you system is distributed over multiple data center, i.e. eliminated any single point of failure.

Post reply on HN