Earlier quoted context omitted.
Would you mind briefly explaining the concept of "tech debt" to a layperson?
Two ways, I think they're easy to understand but I have no experience in teaching: Technical debt is like not cleaning your house to save a bit of time everyday. When you actually have to clean it, it's going to take longer than the time you saved. And until it's not clean, everything you do will be a bit worse because the house isn't clean. "Remember when you were a student and didn't do the dishes, and then when yo…
US companies hit by 'colossal' cyber-attack
471–480 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#472What are those VSA tools used for in practice? Can anyone in IT who uses them tell us. I don't mean what is sold as I mean what it is used in reality, actual operations performed.
These are what they’re sold as and literally what they’re used for daily to manage and monitor thousands upon thousands of endpoints of all flavors. In a traditional on-prem Windows corporate environment these functions would have been offered by the on-prem Microsoft stack like domain services, group policy, WSUS, SCCM, SCOM, RDP, etc., and the overhead was enormous. In a diverse and dispersed environment, these toolsets have adapted accordingly - multi-platform, over-the-air, asset light. Now even internal enterprise IT shops use flavors of RMMs that MSPs would use for SMBs. MSPs can simply apply these systems to more SMBs via economies of scale, whereas an SMB could rarely afford the overhead of maintaining the tooling let alone the circus that is device management. So if you break an RMM platform used by an MSP the impact can be quite broad, and include larger enterprise IT operations. It’s easy to say “don’t use RMM tools, or switch to Macs”, but this kind of simplistic reaction belies an understanding of the environment and the need.
Re: US companies hit by 'colossal' cyber-attack
#473I kinda feel at this stage we should go back to air gapped intranets and working from the office again. SAAS just isn't worth it, and the other things like stack overflow you can do from your phone.
Re: US companies hit by 'colossal' cyber-attack
#474Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…
> But giving the keys to the castle to some mid-tier company is just a recipe for disaster It sucks, because I know my company is quite small but we take security extremely seriously (we have 9 people, 4 are security engineers, and the other 5 have varying degrees of experience in security). I think people might worry that, because of our size, we won't be as secure as a larger company. But the irony is that larger c…
You can be compliant and buy insurance or you can be secure. Pick one.
Re: US companies hit by 'colossal' cyber-attack
#475Earlier quoted context omitted.
Governments can stop a lot of those breaches if they applied financial and criminal (i.e. imprisonment) penalties to executives for failing to secure their systems. If every CEO and CFO's first priority is "How do I not go to prison?" and the second priority is "How do I enrich shareholders?", then security _will_ be fixed. Simple as that.
Of course, a supply-chain software company must have strong security and bear full responsibility for not having one. However, in general I wouldn't be so fast to blame victims. Strong security isn't cheap nowadays and adds to cost of doing business. To make things worse, cyber-attacks become increasingly more sophisticated, so the "security tax" will only grow and fewer organizations will be able to afford it. That'…
Re: US companies hit by 'colossal' cyber-attack
#476This really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand. I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware…
There is also allegedly a reciprocal agreement to allow extradition and prosecution for cyber attacks. So we'll see if that comes to pass or if it's just a little fake glad handing until you actually try to take them up on it.
Re: US companies hit by 'colossal' cyber-attack
#477This really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand. I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware…
Re: US companies hit by 'colossal' cyber-attack
#478> Mr Biden said he gave Mr Putin a list of 16 critical infrastructure sectors, from energy to water, that should not be subject to hacking. This sounds like a concession of major weakness on the part of the US. I guess we already knew that Russia has outmatched US’s cyber capabilities, but I was surprised to see it acknowledged by Biden in this way. And if Russia ignores this edict, it means they’re doing so in the f…
Re: US companies hit by 'colossal' cyber-attack
#479Earlier quoted context omitted.
I wasn't trying to say otherwise - it's a huge advantage to be this size, with regards to security. It would have taken me years at Dropbox to accomplish things that take a weekend now.
I wouldn't trust a company that implements security critical projects on the weekend...
To do the same is trivial at a small company. What would take years and lots of effort becomes something you can do in spare time.
Of course, we put considerably time into security, it's not just something that one does once in a while with spare time. The point is that we can go much much faster.
Re: US companies hit by 'colossal' cyber-attack
#480Earlier quoted context omitted.
If we, the west, let Russia take Crimea and China take Hong Kong with minimal fuss, I don't see why a few cyber attacks would get more attention.
Take over? I thought Hong Kong was given back?