Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

251–260 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#251
post #80
post #48

Earlier quoted context omitted.

404 for every link to the standards. Awesome!

You have to buy them... http://www.comm-2000.com/ProductDetail.aspx?UniqueKey=31733

Yeah, I picked that up from reading the press release[1] that OP had originally included in the comment. What I was surprised to discover was the 404 error page when I clicked the individual links for the different standards. My expectation is that I would have been directed to a site to purchase them.

[1]: http://ulstandards.ul.com/downloads/news-announcing-ul-2900-...

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#252
post #224

Earlier quoted context omitted.

That's why we need the regulation in order to make them give a fuck.

What I'm ultimately arguing here is that: even after the regulators step in and make make them give a fuck, I mean really give a fuck, and they are forced to fix the low hanging fruits, these botnets or other similar machinations, will still exist. In fact, if we assume the regulations work and actually make things harder to exploit, we can add in the knowledge that the price for using and creating IoT botnets will g…

I completely and totally disagree. You're basically saying that, because it will become harder in the future, we shouldn't even try.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#253
post #252

Earlier quoted context omitted.

What I'm ultimately arguing here is that: even after the regulators step in and make make them give a fuck, I mean really give a fuck, and they are forced to fix the low hanging fruits, these botnets or other similar machinations, will still exist. In fact, if we assume the regulations work and actually make things harder to exploit, we can add in the knowledge that the price for using and creating IoT botnets will g…

I completely and totally disagree. You're basically saying that, because it will become harder in the future, we shouldn't even try.

Well I think we can agree to disagree on regulation as the method of fixing the issue. Of course we should do something. I'll admit I'm not sure what though and have no better proposal. I just believe regulation is too blunt an instrument.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#254
post #188

Earlier quoted context omitted.

I'd buy infosec insurance, if such a device existed. Premiums go down the more secure your site, the security work itself being a standardized checklist. Forces the snake-oil salesmen out because they'd have to pay out in the event of a breach. Like you, I have no idea what I'm talking about, but as OP demonstrated you can do everything right and get unlucky, or do nothing right and get lucky. Sounds perfect for some…

> Premiums go down the more secure your site That shit will bring out the snake-oil men harder than anything. It means those peeps will do all they can to get the auditors to think you are more secure. Instead, have a requirement of some compliance, with penalties for breaking compliance.

Honus is on the auditors to know what works and what doesn't. Auditors tell you "these are the things you must do to be compliant". Then the oilmen have to sell to people who lose money if they're wrong.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#255
post #125

Earlier quoted context omitted.

"How many pennies would've been needed to insert a simple page forcing you to change user/password combo and to choose a reasonably strong password after first boot ?" These are written by outsourced developers who don't know anything about security. They wouldn't even think to develop something as simple as that. You are obviously unaware of how this works, companies would have to hire consultants/penetration tester…

Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery. In your app you already have a setup wizard, right ? Add one more page to the end "Hey, we're almost done! We just need to make sure your device is secure. Please choose a username and (strong) password." Edit: Because if you have a logi…

> I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery.

This is utterly ignorant of the facts, Mirai took advantage of weak passwords to spread, but was not dependent upon them.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#256
post #15

Maybe we need liability for software vendors? With exemption for those who provide full source code.

X writes secure code, Y writes secure code, Z integrates both parts in a secure way. X creates a secure update. X releases an update which makes a race condition with Y leading to elevated privileges possible in Z's product. Who's liable for the issue now?

A hard problem - but what if that race condition kills someone? This used to be theoretical problem - there were not so many systems that could fail in so catastrophic ways - but we are now putting software into everything.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#257
post #252

Earlier quoted context omitted.

I completely and totally disagree. You're basically saying that, because it will become harder in the future, we shouldn't even try.

Well I think we can agree to disagree on regulation as the method of fixing the issue. Of course we should do something . I'll admit I'm not sure what though and have no better proposal. I just believe regulation is too blunt an instrument.

I don't see how anything but regulation would do it. The companies clearly don't give a shit, and they won't, as they can't really be held accountable.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#258
post #188

Earlier quoted context omitted.

> Premiums go down the more secure your site That shit will bring out the snake-oil men harder than anything. It means those peeps will do all they can to get the auditors to think you are more secure. Instead, have a requirement of some compliance, with penalties for breaking compliance.

Honus is on the auditors to know what works and what doesn't. Auditors tell you "these are the things you must do to be compliant". Then the oilmen have to sell to people who lose money if they're wrong.

Ticking boxes helps with security, but it tends to be easy to tick the box and yet mitigate much of the actual benefits. When this is cheaper, some companies will chose it, and snake-oil-salesmen will help them do that.

You need some kind of incentive that derives directly from the end goal (less breaches), rather than some derivative (better standards compliance). Auditors certainly have their place, but we need more than them.

edit: Also, you probably meant 'onus' rather than 'honus'.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#259
post #144

Earlier quoted context omitted.

> However, if it is a very wide spread problem then they will eventually install a light on your dash to notify you to change your oil. My wife's car currently does this. Since this is the first car she's ever owned, it's good because I don't think she would have known. We also have check engine lights and indicators for when a turn signal light bulb stops working. New cars even keep track of things like tire pressur…

> And likewise, if someone sabotages your car or has a remote exploit for your computer, I find it hard to dish out blame. > Not knowing better or being too busy is not an excuse to be a party to a DDoS attack. I feel you contradicted yourself here. In one way you excuse it, but you also claim users should know better. When it comes to having a strong password, I feel this is where it's acceptable to place blame. Whe…

Sorry for the late reply. I think I did contradict myself there. And I don't see any way I could fix that contradiction.

There might be a meaningful difference to me between a remote kernel hole versus using a default password, but for most people there is no difference there.

So you've changed my mind, to an extent. I don't think that we should "blame" them, but at the same time, if you entrust a large part of your life into computers and are not aware of the risks you're putting yourself in, I do think you deserve some blame for believing the advertising pitch without researching on your own-- and that kind of blame is relevant for everything, from cars to tablets to vacuum cleaners. I think doing your due diligence is relevant to any topic, and people who don't put it in will reap what they sow. But that blame is more superficial-- you shouldn't have to become a mechanic to buy your car and you don't have to be a programmer to buy an IP camera.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#260
So many devices are now connected to the Internet and potentially vulnerable. The basics definitely matter – changing default passwords, ensuring our internet is hosted on DDoS protection servers, etc. But who was going to warn the traffic engineer that their security camera is vulnerable or the new parents whose IP-connected baby monitor gets scanned by foreign hackers. We just want things to work and don’t realize that we’re at risk – even if our device is the target and not ourselves.

Have you checked out this Mirai vulnerability scanner? Something everyone should do – whether a random home user or a large enterprise (and how many have CISOs?). It scans your IP and can pinpoint vulnerable devices: https://www.incapsula.com/mirai-scanner.html

Post reply on HN