Live data from Hacker News

The Insecurity of Secret IT Systems

schneier.com

1–10 of 26 posts

Re: The Insecurity of Secret IT Systems

#2
I know that NSA/Snowden continues to be at the top of the news, but it's still worth pointing out again that NSA's internal system is probably one of the most secret of internal IT systems and through Snowden's work, we've found out: 1) NSA employees are easily phished and 2) They probably don't have the same level of deterministic dev ops deployments that modern tech companies depend on, given that it was Snowden's job to install an "anti-leak" system and apparently no one double-checked to make sure he had installed it. Hell, who knows if even that secret anti-leak system would actually do anything besides add more cruft to their internal operations? http://arstechnica.com/tech-policy/2013/10/snowdens-nsa-post...

Re: The Insecurity of Secret IT Systems

#3
post #2

I know that NSA/Snowden continues to be at the top of the news, but it's still worth pointing out again that NSA's internal system is probably one of the most secret of internal IT systems and through Snowden's work, we've found out: 1) NSA employees are easily phished and 2) They probably don't have the same level of deterministic dev ops deployments that modern tech companies depend on, given that it was Snowden's…

I'd not realised that it was the person whose job it was to install the anti-leak system who leaked everything. I guess that's an obvious outcome..

Re: The Insecurity of Secret IT Systems

#4
post #2

I know that NSA/Snowden continues to be at the top of the news, but it's still worth pointing out again that NSA's internal system is probably one of the most secret of internal IT systems and through Snowden's work, we've found out: 1) NSA employees are easily phished and 2) They probably don't have the same level of deterministic dev ops deployments that modern tech companies depend on, given that it was Snowden's…

Snowden denies phishing from other NSA employees. And that article you link does not say what you imply it does. It does not say it was Snowden's job to install an anti-leak system. The article just says that one was supposed to be installed, and it wasn't for bandwidth reasons.

Re: The Insecurity of Secret IT Systems

#5
How is a an airport xray scanner maker supposed to participate in that iterative process for improving security if they aren't in a mass market? No security researchers took interest for a long time till Rios purchased a scanner. "It runs an outdated windows 98 operating system" just shows how little anyone cares, even if Rios would like it to show how awesome he is as a researcher or how awful windows 98 is as an OS.

Also unrelated, how to factor a large prime to break RSA 1024 quickly is a secret too.

Re: The Insecurity of Secret IT Systems

#6
His point applies equally to general software quality. Even in the workplace, I always see the bad programmers try to sling shitty code with private repos or direct pushes with no peer review. The good ones always operate in the open and appreciate peer reviews.

Re: The Insecurity of Secret IT Systems

#7

How is a an airport xray scanner maker supposed to participate in that iterative process for improving security if they aren't in a mass market? No security researchers took interest for a long time till Rios purchased a scanner. "It runs an outdated windows 98 operating system" just shows how little anyone cares, even if Rios would like it to show how awesome he is as a researcher or how awful windows 98 is as an OS…

> How is a an airport xray scanner maker supposed to participate in that iterative process for improving security if they aren't in a mass market?

Invite pentesters. Hold competitions for people to try and break it in an isolated part / mockup of an airport. Donate one to your local hackerspace and ask them to have fun with it.

Possibilities are endless; the only things needed is understanding the points in Schneier's essay and a little courage to do the right thing.

Re: The Insecurity of Secret IT Systems

#8
post #3
post #2

I know that NSA/Snowden continues to be at the top of the news, but it's still worth pointing out again that NSA's internal system is probably one of the most secret of internal IT systems and through Snowden's work, we've found out: 1) NSA employees are easily phished and 2) They probably don't have the same level of deterministic dev ops deployments that modern tech companies depend on, given that it was Snowden's…

I'd not realised that it was the person whose job it was to install the anti-leak system who leaked everything. I guess that's an obvious outcome..

This gives the new meaning to "copying production database to test environment"... ;).

Re: The Insecurity of Secret IT Systems

#9

How is a an airport xray scanner maker supposed to participate in that iterative process for improving security if they aren't in a mass market? No security researchers took interest for a long time till Rios purchased a scanner. "It runs an outdated windows 98 operating system" just shows how little anyone cares, even if Rios would like it to show how awesome he is as a researcher or how awful windows 98 is as an OS…

are you sure?

secret means many things, but not the meaning of 'how to factor a large prime to break RSA 1024 quickly is a secret too'

degree of labor hours to reach knowledge is not the same as secret

Re: The Insecurity of Secret IT Systems

#10
Regarding voting systems, all we ever needed was open source software.

Voters were incorrectly recording their paper ballots. A PC with a punch card machine attached and running open source software could have correctly punched these cards.

And we also could have had another system that read the cards right there in the polling place that the voter could use to confirm their ballot was correctly encoded. Or an phone app that could read a photo of it.

We could have gotten that software for free. It could have run on ancient PCs. It could have solved the actual problem that we had.

But the lobbyists got there first, influencing politicians into buying unneeded and overpriced solutions, just like they do in every other area of government.

Post reply on HN