Live data from Hacker News

Why firewalls won’t matter in a few years

etherealmind.com

71–80 of 139 posts

Re: Why firewalls won’t matter in a few years

#71

Passwords are unsafe Passwords are unsafe for the same reason that roads are unsafe: human beings. Things work well enough for most people, most of the time. However, during certain situations, most people aren't trained correctly and often do the wrong thing. What's more, there's even an accepted culture of doing the wrong thing.

I'll add that passwords are used because they're the best default given all the constraints and risks:

https://www.lightbluetouchpaper.org/2012/05/22/the-quest-to-...

They fail when their correct use depends on human beings. Just like you said.

Re: Why firewalls won’t matter in a few years

#72

"You can’t use firewalls to secure East/West data flows in the network." What does that mean?

It means he doesn't know about those PCI card firewalls specifically designed to enforce security policies on traffic flows within the network (or enclave). They're an uncommon thing in industry because most industry thinks outward-facing firewall = secure. Others that know better didn't want to spend money on a security device attached to every server they own. So, the companies in the 90's offering highly secure versions got acquired after little sales, the current ones are obscure, and all he got to see were the more limited crap the industry adopted en mass.

A sad, recurring theme in INFOSEC industry. They're figuring out a lot of the old stuff, though, slowly but surely. Especially in cutting edge datacenters doing things like OpenFlow.

Re: Why firewalls won’t matter in a few years

#73

Firewalls are just some stupid crap industry made up and went with. We've known since the Orange Book days that security had to be done holistically involving every endpoint and network. Their standard for security was a strong TCB on endpoint with trusted path (see EROS or Dresden's Nitpicker); a network card with onboard security kernel, firewall, and crypto (see GNTP + GEMSOS); connections between networks through…

If you opened by saying "Firewall MARKETING is just some stupid crap ...", people might hear your message better.

Yes there's huge complacency about security. But the problem is people, not firewalls.

Holistic security is important and a huge opportunity created by this mass hypnosis. There's never been a better time to raise money. Happy to discuss, contact info on my profile.

Re: Why firewalls won’t matter in a few years

#74

Earlier quoted context omitted.

Best way is to not send credentials in plain text. I wish SRP had taken off and become standard.

This doesn't send credentials in plain text.

What is being sent to the server then?

And by plain-text, I mean the server receives information that could then be used to authenticate later.

For instance, if you send the sha of a password, and then store the sha of the sha, you're still sending the password in plaintext, it's just that it's not the password the user entered.

Re: Why firewalls won’t matter in a few years

#75

Earlier quoted context omitted.

This doesn't send credentials in plain text.

What is being sent to the server then? And by plain-text, I mean the server receives information that could then be used to authenticate later. For instance, if you send the sha of a password, and then store the sha of the sha, you're still sending the password in plaintext, it's just that it's not the password the user entered.

...Which is why I said "over a secure connection".

This method is no less secure than the standard "client sends server password over HTTPS" scheme.

Re: Why firewalls won’t matter in a few years

#76

Firewalls are just some stupid crap industry made up and went with. We've known since the Orange Book days that security had to be done holistically involving every endpoint and network. Their standard for security was a strong TCB on endpoint with trusted path (see EROS or Dresden's Nitpicker); a network card with onboard security kernel, firewall, and crypto (see GNTP + GEMSOS); connections between networks through…

If you opened by saying "Firewall MARKETING is just some stupid crap ...", people might hear your message better. Yes there's huge complacency about security. But the problem is people, not firewalls. Holistic security is important and a huge opportunity created by this mass hypnosis. There's never been a better time to raise money. Happy to discuss, contact info on my profile.

Fair enough as that's a huge part of the problem. Yet, if firewalls should be trusted, they need to meet these basic critera:

1. Attention paid to firmware security and its ability to load kernel.

2. Firewall TCB is strong in that it can prevent or contain compromises.

3. Each component is isolated with restricted interactions subject to believable security arguments, static analysis, or formal verification.

4. Every piece of every packet is inspected for foul play.

5. Covert storage and timing channel mitigation is in place.

6. Supports application-layer security for whatever it's being used for.

Can you name a single firewall that meets all these criteria? That's how guard's were designed in the past before firewalls got invented to ignore most of that. So, firewalls (in theory and practice) are technically incapable of doing their job unless the coders were nearly perfect. Then, they're marketed as doing much more than they can. So, why people demand firewalls instead of companies getting the cost of guards down is beyond me.

Here's an example of a real firewall that is more like a guard in practice:

http://www.sentinelsecurity.us/HYDRA/hydra.html

A nice architecture combining highly assured firewalls and SNS Server guard (15-20 years without compromise) with COTS enhancements for quite a security argument:

http://www.dtic.mil/dtic/tr/fulltext/u2/a425566.pdf

Once I see the real thing, esp seeing NSA pentesters achieve nothing, it's hard for me to make excuses for security engineers making the same mistakes for years despite being shown what works. I've sent about every firewall vendor validation reports of what made it and why. They don't care and that's why firewalls are some stupid crap industry trusts but shouldn't.

Re: Why firewalls won’t matter in a few years

#77

Firewalls are just some stupid crap industry made up and went with. We've known since the Orange Book days that security had to be done holistically involving every endpoint and network. Their standard for security was a strong TCB on endpoint with trusted path (see EROS or Dresden's Nitpicker); a network card with onboard security kernel, firewall, and crypto (see GNTP + GEMSOS); connections between networks through…

"Firewalls are just some stupid crap industry made up and went with." -- I can't even begin to unravel how short sighted that comment actually is.

I'm not sure you really understand the state of the firewall industry at this point in time if I'm allowed to be blunt. While I do think that traditional firewalling (L3/L4) has lost it's overall efficacy there are solutions on the market that address application control, identity, A/V, IPS, spyware and malware solutions in a single solution (not UTM) and that are stream based (single pass - again not UTM).

Firewalls at the enterprise level are FULLY required for business to operate in a relatively secure manner today. Controlling the applications ingress and egress is not an option - it's a requirement. Greg (Etherealmind) has been very well known to be, well, a bit opportunistic in his early assessments. He mentions NSX in the East/West flows in the SDN environments, however what he fails to mention is that many customers implementing NSX have also been implementing purposebuilt firewalls in NSX via the exposed placement of security services tied to the NSX and NetX APIs (http://www.networkworld.com/article/2169448/virtualization/v...).

Working for a security company in this space let's refute the majority of his numbered components..

1) The majority of the customer verticals I deal with buying 10Gb+ firewalls buy A LOT of them. These are environments doing millions to, literally, billions of dollars of revenue per hour. A completely licensed, supported firewall rated at, say 20Gb can be had for under $300k and maintained annually for less.

2) 6.7 nanoseconds is a myth - unless you're in financials and the HPC space. There are so many conga line security products today, and ill conceived network architectures and a thousand other things where 6.7 nanosecond expectation is a unicorn. We typically get to the microsecond levels and customers (even financials) are often fine with those numbers in critical environments.

3) Yes you can. There are a lot of customers using NSX and OpenStack using fully supported, fully modern security solutions in production today. I've been involved in said projects - the best part about those environments is it's actually easier to deploy because it's software and more and more platforms have fully exposed APIs and are built for automation and abstraction.

4) BS. Application security? For real? Most of the Global 2000 are NOT software companies. That means they're software development is not their forte. Which means that most will continue to have SQLi (and other trivial) problems well into the next decade.

5) Let's just say for a minute that the perimeter is collapsed - which I hope that at this point it is for the majority of organizations who take network security seriously. That doesn't change the fact that overlays can't have security insertion points and that there can't be microsegmentation. Because there already is today.

6, 7 and 8... They make the least sense of any of the arguments because they are so pointed and least relevant to all scenarios.

Sure - fixing the endpoint and the software involved is an awesome approach to security. But traditional firewalls never fixed that in the first place, all they controlled was access. However today's firewalls go well beyond that and provide much more granular application and user control as well as threat services on top to boot.

But I'm sorry - if firewalls provided no business value there would not be companies building and selling 10 & 100Gb firewalls for hundreds of thousands to millions of dollars to protect, segment, identify and inspect - well beyond what this is lumping all "firewalls" into.

Re: Why firewalls won’t matter in a few years

#78
post #42

I also wonder how the move to IPv6 will also affect the current paradigm. Internet facing firewalls were typically also NAT machines to save IPv4 address space but all of that is gone in IPv6 meaning your global address is now exposed and a hacker can persistently try to compromise your machine if you don't firewall.

[deleted]

Re: Why firewalls won’t matter in a few years

#79

Earlier quoted context omitted.

Could you expand on your last para please - it seems to promise there is a solution to software security already available ... E-language seems a bit out dated from the intro I can find, What's an IO offload engine? What do you means about unified model (capability based / distributed implies E-language again?) Is this using strong data types to base security capabilities on? And how does hardware for in here I ask f…

I covered a lot of ground in this counterpoint to Dan Geer on why our security sucks: https://www.schneier.com/blog/archives/2014/04/dan_geer_on_h... Read it, its two links, and whatever they link to for plenty of inspiration. If you want, I'll email you a list of my designs and essays on there. I use his blog to reach as many people as possible. I can't make money on high assurance without selling out to the enemy s…

That would be kind - please. I shall delve, kids holiday permitting !

Re: Why firewalls won’t matter in a few years

#80
post #62

Years ago at a large car manufacturer I had an argument with the "Data Security" team about firewall settings. They had some crazy dumb ideas of what had to be on the firewall and it was constantly causing us pain. I went to visit this person in charge and argue my case. He was in another building outside of the "Secure Datacenter".. He argued with me for about 45 mins about how nothing leaves that data center and th…

I've seen multiple security audits that didn't see fit to mention such ethernet ports as a problem. I don't know why; it's possible management told them it was "out of scope".
Post reply on HN