Live data from Hacker News

Ceremonial security and cargo cults

philvenables.com

31–40 of 49 posts

Re: Ceremonial security and cargo cults

#31

Earlier quoted context omitted.

I largely agree with you, but the problem ends up being when you have some braindead person in your GRC role who persistently fails to grok the scale of the operation...or doggedly insist that you prove negatives. Example: Some idiot person we have in IT insists that a control for proving lack of user admin access should be to screenshot the userlist w/ group permissions of every single server in our operation. Idiot…

The “proof via a series of tedious screenshots” method of audit is absolutely infuriating. Please bring on the 10x auditors…

When you don't know what you're doing, dazzle them with bullshit.

Best part of the story above is that in our system there are no human users that can access a live system. And proof of that is insufficient because the IT person isn't familiar with the practice.

Re: Ceremonial security and cargo cults

#32
post #9

My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…

> Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security.

There is one company I know of that added a two step login to their azure active directory where logins expire every twenty four hours. It made no sense to me why they did things this way. As far as I knew, even Microsoft wasn't this restrictive with logins.

Until I saw last week that people are willing to let tools like https://news.ycombinator.com/item?id=34416386 basically hijack their session tokens. If they can use this for good, imagine what other add-ons can use this for evil...

So I think the idea is if someone steals your credentials, they will only work for twenty four hours and they would fail because hopefully they don't have your two step authenticator? I still don't like the idea but at least I see why they'd do this...

Edit: maybe someone else here has a better idea why it is a good idea to require password and two step authentication every twenty four hours?

Re: Ceremonial security and cargo cults

#33
post #32
post #9

My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…

> Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. There is one company I know of that added a two step login to their azure active directory where logins expire every twenty four hours. It made no sense to me why they did things this way. As far a…

> maybe someone else here has a better idea why it is a good idea to require password and two step authentication every twenty four hours?

Not saying it's directly the answer here, but some distributed systems lack proper session blocking or revocation, as a session is a signed JWT or similar standalone token.

If the security decision makers favour a 24 hour guaranteed lockout, rather than risking someone whose access has been suspended having an old session still live, this could make sense from being able to know and show access is always "gone" in 24 hours of blocking their ability to get a new token.

Re: Ceremonial security and cargo cults

#35
I'm currently working at a mid-size startup that is undergoing ISO27001 certification. A lot of the complaints we are getting from employees are similar to the contents of this article.

Part of my job is training our staff on the new requirements. They question everything from why each individual has to badge in one by one to why doors can no longer be propped open. Why can they no longer access company resources with personal gear? Why can't they install whatever they want on their company gear? It goes on and on.

My answer is always the same, in order to be certified we need to show that we have demonstrable, verifiable control over this (for example entry logging).

Re: Ceremonial security and cargo cults

#36

I'm currently working at a mid-size startup that is undergoing ISO27001 certification. A lot of the complaints we are getting from employees are similar to the contents of this article. Part of my job is training our staff on the new requirements. They question everything from why each individual has to badge in one by one to why doors can no longer be propped open. Why can they no longer access company resources wit…

Away from standards like that, we also sometimes have requirements from clients' compliance people, and "what they don't know won't hurt them" (which some would love to get away with) doesn't, can't, wash. We will directly loose work, or the chance to bid for it, if we don't comply or can't demonstrate compliance. People moan less about some inconveniences if it is explained as "because jobs or bonuses may be at risk of we don't comply".

Re: Ceremonial security and cargo cults

#37
post #6

I believe that such dogmatic "thinking" (if one can call it that) exists and propagates only because people are being discouraged from thinking critically. They are instead encouraged to find "best practices" and "solutions" from others (often giving them $$$), which they can blindly follow, instead of evaluating their unique circumstances and thinking independently about their own needs. The constant use of "securit…

No offense, but I think you're exactly wrong. People need to trust the science, so to speak, and leave the thinking to domain experts who can dictate the best course of action for everyone. On their own, too many people are prone to following misinformation, and can't even be trusted to read both sides of any given argument critically. If the last few years hasn't taught us this lesson, what has it taught us?

Trust is earned, not given.

The word "Science" came from a type of knowledge/knowledge-seeking that has been very successful from the age of Newton to present day.

But Science's success has become it's curse. Lots of fields now call themselves "Sciences" even if they're not employing the kinds of standards and methodologies that lead to the early successes. People with ulterior motives (economic, ideological, political, social or religious) have for a long time claimed to represent Science.

Lately, "Science" has warped into "the Science", meaning a world view promoted by a set of authorities that can be highly partisan. In many cases, the kind of mechanisms that ensured (eventual) falsification of bad ideas have been abandoned. Instead, "the Science" now must now often comply with what is what we WANT to believe, rather than with evidence.

Understanding real Science is still as useful as ever. Not only does an actual scientific education give access to undertanding directly, it also helps us see through those who claim to represent "the Science", but who are not respecting the Scientific Method. People without a proper scientific education will, today, be helpless in distinguishing between real Science, cargo cult Science and outright fraud.

I would argue the same goes for IT security. At least a few decision makers in an organization needs to have a fairly good understanding of it if the organization of the topic to know how to deal with it, either internally or through service or software vendors.

Re: Ceremonial security and cargo cults

#38
post #6

I believe that such dogmatic "thinking" (if one can call it that) exists and propagates only because people are being discouraged from thinking critically. They are instead encouraged to find "best practices" and "solutions" from others (often giving them $$$), which they can blindly follow, instead of evaluating their unique circumstances and thinking independently about their own needs. The constant use of "securit…

No offense, but I think you're exactly wrong. People need to trust the science, so to speak, and leave the thinking to domain experts who can dictate the best course of action for everyone. On their own, too many people are prone to following misinformation, and can't even be trusted to read both sides of any given argument critically. If the last few years hasn't taught us this lesson, what has it taught us?

I am invoking Poe's Law on this one.

Re: Ceremonial security and cargo cults

#39

Cargo culting is unavoidable. We build everything "on the shoulder of giants". We do not have the infinite time and energy to analyse every problem from beginning to end and develop a perfectly fitting solution for it. For the most part we must copy behavior observed in successful entities. We also do not have the energy and effort to perfectly analyze the observed behavior so some data is lost in the copy. You end u…

> We build everything "on the shoulder of giants"

There may be huge variances in the degree that we do that, though, and to the degree that we're able to prevent really bad ideas to spread. Some organizations are seeing really bad (but good looking) ideas spread like cancers, until the organization is completely perverted.

> Ceremonies mostly get discarded by evolutionary pressure in the long term.

This is perhaps the main strength of capitalism. There needs to be an actual mechanism for bad ideas to die off. Many large organizations (especially "too large to fail" or publicly owned) lack good mechanisms to limit the growth of organizational entropy.

Re: Ceremonial security and cargo cults

#40
post #32
post #9

My current title at work includes the words "software" and "engineer", and thus I have a natural mutual predator-prey relationship with infosec and compliance/IA. Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. Compliance is an easy way to force e…

> Which brings me to the point: Compliance isn't just there to cargocult and boxtick. It's there because, left to their own devices, most organisations/sub-organisations will end up, at pinnacle-best, half-assing security. There is one company I know of that added a two step login to their azure active directory where logins expire every twenty four hours. It made no sense to me why they did things this way. As far a…

24 hour session limits are what's asked from our site reliability (cybersecurity) insurance carrier.
Post reply on HN