Live data from Hacker News

Palo Alto Networks PAN-OS Zero-Day Exploitation

volexity.com

61–66 of 66 posts

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#61

Earlier quoted context omitted.

> a business needs to know what kind of data is passing through its networks a business... without context this appears to be a "free" card for any amount of micromanagement or intra-company snooping.. locks on the cabinets with the cheap coffee in it.. that level of petty.. sure, there are larger objectives but the way this is said, there appear to be no checks and balances.. it could be like a fish-in-a-barrel snoo…

Companies have a legal and fiduciary duty wrt everything that goes on with their equipment and services. Examples: I was the regional IT director at an extremely large, French owned, financial organization that had a child pornography ring operating among a couple of employees and several outside entities. The investigation and apprehension involved the FBI. At the same company: FINRA investigation into illegal insid…

"you don't know" and "all employees require no-consent supervision" and Fusion Centers .. yes, you are right, we disagree

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#62
post #52
post #28

Earlier quoted context omitted.

One company had a related (but less defensible) decision, coming down from the top, which broke CI runners and other things, and the poor overworked Git&CI infra lead was trying to work around it. They asked me to be a Git reviewer for their big workaround, and I found around a dozen new vulnerabilities and future build-breaking defects that the workaround introduced. I also told them that it's unreasonable for this…

I get that this sort of MITM often breaks CI pipes, but working with this shouldn't be anything more than a chunk of work involving stuff you ought to be doing already, including: 1. put all assets into infrastructure you control, allow pulling only from that infrastructure, no exceptions. 2. understand your containers enough to be able to modify and manage their trusted CA / TLS chains. You really ought to be in a p…

Agreed, and that wasn't the problem.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#64
post #53

Earlier quoted context omitted.

These tools typically claim to block or catch stupidly high number of threats per unit time. And they usually bucket the drive-by stuff as a threat to achieve this narrative. I agree it’s hogwash. So you’re essentially admitting that these TLS boxes are more about controlling employees and “data loss prevention” than actually preventing real threats and doing honest security. Got it. https://honest.security

>I agree it’s hogwash. I think the parent commenter was pointing out that "MITM TLS box" has nothing to do with sshd scans. Not that MITM TLS boxes have no use. Oh, and #4 on that "tenets of honest security" is an opinion not shared by all. In the modern era of guest wifi and ubiquitous personal mobile devices, personal use on a work machine is not necessary or advisable. That said, in most places it is common to *no…

You know what I mean, the TLS middleware is part of your IDS suite. Anyway.

Personal use was not the norm. Locking machines down was. VPNs, corporate network perimeters, blocking copy paste (my god), TLS middleware boxes. It all sucks. And inspecting internet traffic is a breach of human rights among adults.

Then we grew out of it. Now we have identity perimeters. Strong identity and yubi keys, webauthn, SSO. Honest.security reflects how people operate today. Modern IT stacks operated by ethical teams don’t do traffic inspection.

We agree, TLS inspection is about control, not security. And that’s why it’s unethical.

“No personal use” also just doesn't work, ideologically. Gotta access your bank for payroll, financial stuff for 401k, RSUs. HR portal has to be accessible on the personal side too for taxes healthcare and emergencies. Been there done that move on.

I will concede that there are isolated highly security sensitive situations where full device control is needed like maybe for the employees or machines with access to a CA or production deployment keys or classified information with human loss of life at stake. But the no personal use mantra is not a blanket philosophy that’s healthy or good for modern society and isn’t relevant in 99.99% of use cases.

You can even look at MDMs which have shifted from full device control to hybrid support.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#65
post #58

Earlier quoted context omitted.

Telemetry is pretty much the norm for XDR. The problem is all this stuff is cloud and not on-prem. Wazuh is great for on-prem, but the profiliferation of SaaS, etc., makes it extremely difficult to keep a handle on everything.

My feeling is that Wazuh is of little use to anyone besides those aiming to please security auditors, for whom it provides file integrity monitoring and other 20th century best practices that predate our modern world of virtualized short-lived servers.

I primarily use it as a tool to aggregate logs, alerts, and to proactively audit configurations.

It's great at finding people who can't remember passwords or misbehaving services or software.

Re: Palo Alto Networks PAN-OS Zero-Day Exploitation

#66
post #26

I've been trying to get a copy of panos for fuzzing/research myself but unless I set up a reputable llc that seems impossible. They've ignored every request for purchase I've made. If anyone has tips on how to get started with this do let me know. It seems not allowing researchers even black-box access is their strategy to secure the platform.

If you're trying to buy from them directly you aren't going to get anywhere. Palo Alto is a channel company; you need to find a channel partner that considers a one-off sale worth their time. Palo Alto does do direct deals, but not small ones. There's an easier way to get a firewall spun up, though. https://aws.amazon.com/marketplace/pp/prodview-nkug66dl4df4i looks like the current version. I'm still running https://…

Thanks, I think the cloud approach is the only way, I wanted to do it locally. For personal use, cloud providers are very hostile, especially if your use case is to do things that aren't normally done.
Post reply on HN