>> Actual resting data protection would allow a "I don't care if I'm hacked," posture. That's quite interesting. Where can I read more about that ?
I think something along these lines is called “zero trust” and especially Google has been aggressively implementing it. But I could not find have any high quality articles on the concept. https://www.csoonline.com/article/3247848/what-is-zero-trust...
Zero trust protects the servers, not the network, and not the data.
Protecting the data means encrypting it (which Google also does) such that the client needs a key to decode it.
But if the client is hacked, the hacker can get their keys! so encrypting the data isn't a magical cure-all.
I worked for an MSP that used Kaseya VSA. First used the SaaS version. Their "SSO" is not claims-based but an agent that may just run on a DC and copy NTLM hashes to the SaaS instance. Had an admin account compromised. Asked for logs from Kaseya. Attacker traffic came from a Tor exit node. They did zero ingress filtering. Much of their codebase is Classic ASP riddled with comments like "'fixed SQL injection." Beyond…
This sounds like something Computer Associates would buy and keep alive for another decade.
A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…
>These people can tell you so much about the theory of security by heart that it will make you dizzy but then won't actually understand the underlying problems. I've thought greatest failure of many professionals in this field is in the "protect the network" perspective rather than "protect the data". While many of them fess up to "we can make it difficult but not impossible" to breach the network, that is not evince…
If hacker hack your systems, they get the decryption keys too. They just might need to hit two separate targets with two attacks or a attack that both are vulnerable to.
>These people can tell you so much about the theory of security by heart that it will make you dizzy but then won't actually understand the underlying problems. I've thought greatest failure of many professionals in this field is in the "protect the network" perspective rather than "protect the data". While many of them fess up to "we can make it difficult but not impossible" to breach the network, that is not evince…
I always thought that when thinking security a compromised system HAS to be rebuilt. I have never seen that happen in an enterprise though. They never ever rebuild compromised systems they just try to improve perimeter protection.
Rebuilding the entire IT deployment is prohibitively expensive.
Imagine if the solution to Covid was "the virus can spread to anyone, we need to replace all humans"
I have never understood this; the whole Enterprise™ security business talks about all these things where half the time I literally don't even know what they're on about. They all seem to take it very serious; great! And at the same time they miss basic stuff like, I don't know, subscribing to Apache struct release mailing list. Or not keeping employee credentials around on public servers used to file credit disputes.…
Seems like kind of a corporate/organizational culture thing. Imperfectly distributed knowledge, hierarchical decision-making in groups with misaligned incentives, the limitations of communication and the capacities of individuals... These and more make it hard to operate a large enterprise intelligently and cohesively, and oversights will happen. Corporations can certainly seem to act dumb or just learn slowly as a w…
Humans can't get this stuff right every time either.
It's not like Colin Percival or Theo de Raadt , perfect as they are, could just audit and secure all of the Fortune 500.
ISC² has done so much damage to the industry via enabling the fallacy of appeal to false authority it is mind-blowing. The cissp is such a terrible proof of whether someone knows anything, everyone knows it, but for some reason people keep falling for it.
I view it as a shared level of baseline knowledge that helps with conversation. If I see someone has it, it at least tells me they understand the words I’m using and have a basic knowledge of the concepts we are discussing (or should, at least). It also tells me they are good at taking tests. It doesn’t tell me whether they understand how it all works together, or if they understand the organization’s environment, or…
Sounds like it's a test in Security Fluency, not Solution Providing.
I keep reading over and over again indignant comments about "cost centers" on Hacker News and I think it's not a good term to use because I looked up the definitions and the only logical consensus I could find is that everything which isn't shareholder profit is a cost center. It's just rhetoric.
I don't think it is - I think it's cultural and organisational. The CFO and Finance in general see businesses as capital flows, they don't see value being added - just opportunities for leverage and cash management. The description of a cost center is a labelling denoting a target for removal and reduction - the destruction of value that occurs (typically 12 -24 months after the exercise) is seen as disconnected and…
But everything is a cost center , even product development and sales. A salesperson is a cost center except for the singular moments when they sign a deal.
I keep reading over and over again indignant comments about "cost centers" on Hacker News and I think it's not a good term to use because I looked up the definitions and the only logical consensus I could find is that everything which isn't shareholder profit is a cost center. It's just rhetoric.
I always recommend that engineers who aspire to manage at the executive or "C" level take some classes or read up on how business school teaches business leaders to analyze the health of their company. Those are the classes where 'gross profit margin', 'marginal costs', and 'operational efficiency' are discussed and explained. If you are looking at US curriculum, my experience is that you will see the discussion in t…
The problem here is that when, P&L in IT/Security is L, the answer is always "reduce costs", not "get more credit for enabling and protecting the revenue of other cost centers". IT undercharges for the value they are expected to provide. Often times (hello GDPR and ad tech /spyware) skimping on IT is way to cover up the fact that the business is fundamentally not sustainable or sustained only by breaking the law or negative externalies.
Much easier to do it Ina small company, very hard to get it right in a company "100x your size".
I wasn't trying to say otherwise - it's a huge advantage to be this size, with regards to security. It would have taken me years at Dropbox to accomplish things that take a weekend now.
I wouldn't trust a company that implements security critical projects on the weekend...
Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…
Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…
The fix, known all over industry, it insurance coverage that pays out for externality incidents. Then actuaries figure out what real security is.