Earlier quoted context omitted.
When driving by Bad Aibling I always wondered why the BND (intelligence agency) invests so heavily in satellite communication eavesdropping. I naively assumed that this kind of communication would be encrypted. Also a fun fact: For a long time it was only semi-officially known that the BND owned and operated the site. Officially it was called "Long distance telecommunications station of the Bundeswehr" and operated b…
At least since the mid-1990s Echelon revelations in the EU parliament anybody who cares knows that Bad Aibling (and similar stations all across Europe like Bude/Morwenstow in the UK) had been operated by the NSA in collaboration with US Army intelligence (if the official name of “18th United States Army Security Agency Field Station” didn’t clue you in. Officially it has been transferred to the BND; experience sugges…
Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
121–130 of 145 posts
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#122Earlier quoted context omitted.
Wait til you hear about how many companies willfully perform all their work in g-suite and office 365/teams
Indeed. And they are trying to find sneaky ways to get you to back up more and more data there. They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties…
> who knows if that is true? There's no oversight
The oversight is that those companies rely heavily on being trustworthy, and proving untrustworthy would be disastrous for their business models. Companies don't have to care right now because they have reason to believe Google, MS, et. al. aren't sniffing that data. If they came to believe they were?
Google alone is making $43 billion on Cloud and would prefer not to jeopardize that revenue stream.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#123Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#124Earlier quoted context omitted.
Indeed. And they are trying to find sneaky ways to get you to back up more and more data there. They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties…
I believe the point of the above comment is "The trust model already trusts the recipient, so nobody cares that the recipient is seeing query params because they trust the recipient to ignore them." > who knows if that is true? There's no oversight The oversight is that those companies rely heavily on being trustworthy, and proving untrustworthy would be disastrous for their business models. Companies don't have to c…
That's what I don't get - security and compliance people are paranoid.
This is the kind of thing they shouldn't be requiring evidence to care about, given the rest of their job is about the "what-ifs". Just seems crazy to me.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#125Who needs hackers when companies broadcast their secrets to half the planet?
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#126Earlier quoted context omitted.
Indeed. And they are trying to find sneaky ways to get you to back up more and more data there. They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties…
I believe the point of the above comment is "The trust model already trusts the recipient, so nobody cares that the recipient is seeing query params because they trust the recipient to ignore them." > who knows if that is true? There's no oversight The oversight is that those companies rely heavily on being trustworthy, and proving untrustworthy would be disastrous for their business models. Companies don't have to c…
The reason why this does not result in a significant loss of usage is because trustworthiness-usage is not a linear function or a even a continuous function -- it is a step function. To cause less usage, the loss-of-trust force has to be higher than the networking effect force. Otherwise, behavior does not change.
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#127Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#128Earlier quoted context omitted.
Likely no consequences to the decision-makers for data exfiltration or other shenanigans happening, so there's nothing motivating a behavior change. The reason security is so bad everywhere is that nobody gets fired when there's a breach. It's just blamed on the hackers and everyone just goes on with life singing "We take security very seriously--this happened because of someone else!"
Who do you imagine will get fired? The CISO who's been recommending various security imporvements and been trying to get them implemented, but been unable to do so due to a lack of C level interest in IT. Or the C level's who lack interest in IT security until it bites them in the investor? At least here in the EU we're moving toward personal responsibility for C level's who don't take IT and OT security serious in c…
I wont pretend that accountability in the physical engineering world is all smiles and rainbows but at least there are actual laws dictating responsibilities, certification and other real consequences for civil engineers. When a Professional Engineer in Canada signs-off (seal) on work they are legally assuming responsibility which means the practitioner could be held accountable in the event of professional misconduct or incompetence regarding the engineering work. There is no reason but corporate greed and corruption why there isn't similar legislation in North America for cybersecurity or software engineering where you have professional bodies certify people to be legally obligated to sign-off on work (and refuse work that isn't up to standards).
But this would require introducing actual legislation which god-forbid how could we do such a thing to the poor market! It would stifle their innovation at leaking everyone's data.
There's no reason we couldn't extend the same existing system of licensure [1] that professional engineers require.
Sure maybe its overkill for someone stringing together a python app, but if you're engineering the handling of any actual personal information then this work ought to be overseen by qualified, licensed and accountable professionals who are backed by actual laws.
[1]https://en.wikipedia.org/w/index.php?title=Regulation_and_li...
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#129Earlier quoted context omitted.
Wait til you hear about how many companies willfully perform all their work in g-suite and office 365/teams
Indeed. And they are trying to find sneaky ways to get you to back up more and more data there. They do have privacy policies which say they won't sell that data, or use it for advertising or anything other than delivering the service. But - who knows if that is true? There's no oversight. And if they get caught breaking that privacy policy, who has the appetite these days to do anything meaningful in terms penalties…
Re: Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
#130Earlier quoted context omitted.
> nobody gets fired when there's a breach this must mean the consequences of such a breach has either not produced any visible damage, or the entity being damaged is uncaring (or have no power to care).
If you fire people for stuff they didn’t maliciously introduced you will end up with no people to work with. Imagine jailing doctors for every patient that died you would be out of doctors quite soon.