Live data from Hacker News

Cybersecurity Is Broken

crankysec.com

41–50 of 83 posts

Re: Cybersecurity Is Broken

#41
Back in my aerospace days I worked on an obscure secure operating system, which, unfortunately, was built for the PDP-11 just as the PDP-11 neared end of life. This was when NSA was getting interested in computer security. NSA tried applying the same criteria to computer security they applied to safes and filing cabinets for classified documents. A red team tried to break in. If they succeeded, the vendor got a list of the problems found, and one more chance for an evaluation. On the second time around, if a break in succeeded, the product was rejected.

Vendors screamed. Loudly. Loudly enough that the evaluation process was moved out of NSA and weakened. It was outsourced to approved commercial labs, and the vendor could keep trying over and over until they passed the test, or wore down the red team. Standards were weakened. There were vendor demand that the highest security levels (including verification down to the hardware level) not even be listed, because they made vendors look bad.

A few systems did pass the NSA tests, but they were obscure and mostly from minor vendors. Honeywell and Prime managed to get systems approved. (It was, for a long time, a joke that the Pentagon's MULTICS system had the budgets of all three services, isolated well enough that they couldn't see each other's budget, but the office of the Secretary of Defense could see all of them.)

What really killed this was that in 1980, DoD was the dominant buyer of computers, and by 1990, the industry was way beyond that.

Re: Cybersecurity Is Broken

#42
post #41

Back in my aerospace days I worked on an obscure secure operating system, which, unfortunately, was built for the PDP-11 just as the PDP-11 neared end of life. This was when NSA was getting interested in computer security. NSA tried applying the same criteria to computer security they applied to safes and filing cabinets for classified documents. A red team tried to break in. If they succeeded, the vendor got a list…

^^^ this guy is an absolute legend (and his work was the bane of my existence as an Engineer, which made me switch to the business side /s).

This the guy who created the Nagles Algorithm for TCP optimization.

https://en.m.wikipedia.org/wiki/Nagle%27s_algorithm

Re: Cybersecurity Is Broken

#43
post #38

> You do what the payment card industry has been doing for decades What? Mandate a bunch of paper-thin worthless rules that tie up security & engineering teams and don’t actually add measurable security improvements? I’d be very interested in seeing the data that shows PCI-DSS has had any impact. I spent a previous life breaking into PCI compliant companies, and it didn’t offer the tiniest speed bump. This is a horri…

While it feels dirty, I blame companies more than PCI.

Just like the failures of traditional Enterprise Architecture, the Prescriptivist, universal top down method eats lots of resources without delivering much value to the company.

While governance and policy are important, most are written to CYA more than to solve the initial problems.

As an example, as a consultant I once found a serious vulnerability with a serialization library on a very large companies stack.

Because it wasn't web facing, it couldn't be prioritized as policy didn't allow increasing its weight.

They were compromised a few quarters later... but it was their policy that they wrote that caused that.

Almost universally, restrictions and barriers have almost nothing to do with PCI requirements, but due to how the company implemented it.

A lot of that is due to the consulting and certification industrial complex and the focus on productized offerings. Just as chatGPT is intentionally verbose because it appears more authoritative, companies adopt governance that is way more detailed than appropriate.

Obviously any compliance will have some detailed and firm requirements, but the core concepts are replaced with blindly implemented checklists when values and principles are what should drive most decisions in specific systems.

The requirements to be PCI compliant often follow that concept far more closely than what companies actually adopt.

PCI DSS isn't that far off from generic best practices, optimization for superficial Self-assessment questionnaires and audits that we know don't catch much over those best practices is the problem.

Re: Cybersecurity Is Broken

#44
it doesn’t help all governments sponsor and partake in the 0-day trade which undermines efforts of their citizens private sector blue teams. In addition to paying ethical hackers sometimes 1-2% of what they pay 0-day brokers for the same vulnerability.

It’s definitely broken, and as long as the same entities demanding “improved cybersecurity” from its citizens also continue to undermine their efforts nothing will change.

It’s to wrapped up in the military industrial complex, no one’s trying to fix and stop wars when there’s money to be made.

Re: Cybersecurity Is Broken

#46
post #14

It's time to introduce PE licensing for the title of "software engineer". Like civil engineers, software engineers should be personally, civilly and criminally liable for the systems they sign off on. Reserve other titles, likE "software developer", for those who work under the engineer and do not assume liability. Other measures, like data protection laws, will still be necessary. But introducing certification and l…

I’ve had the same thoughts and I’m glad I’m not alone. We like the money and prestige from wearing these titles but not the responsibility that others who call themselves engineers shoulder.

I can protest to my boss about security issues and data privacy or even try refusing to proceed with a project or release but that’s a minor inconvenience to him. Easy enough to fire me and get somebody else who doesn’t care.

We complain that we are powerless but investors and executives aren’t going to give us any power willingly. That will have to come from legislators and if we want it we’ll have to take some responsibility too.

Re: Cybersecurity Is Broken

#47
post #41

Back in my aerospace days I worked on an obscure secure operating system, which, unfortunately, was built for the PDP-11 just as the PDP-11 neared end of life. This was when NSA was getting interested in computer security. NSA tried applying the same criteria to computer security they applied to safes and filing cabinets for classified documents. A red team tried to break in. If they succeeded, the vendor got a list…

And still, despite the weakening, hardly anybody passed even the watered down requirements. Large vendors like Microsoft complained that the bidding process was unfair because they were not even allowed to compete just because they could not meet the minimum security requirements. So, the requirements were reduced until the requirements could meet the the abilities of the vendors.

For operating systems in the early 2000s, this constituted a Common Criteria EAL4 certification according to the Controlled Access Protection Profile (CAPP) [1] which is only appropriate for: "an assumed non-hostile and well-managed user community requiring protection against threats of inadvertent or casual attempts to breach the system security". EAL4 certifications have since been viewed as too onerous for vendors so they progressively dropped it to 2 stacked EAL2, since clearly 2 * EAL2 = EAL4 (I am only half-joking). To where we are now where the requirement is only the lowest level of certification, EAL1, which does not even demand a security analysis. The vendor is only required to Google: Name + Vulnerability (I am not joking this time [2][3]) and show that any vulnerabilities that showed up were patched.

And people wonder why everything is easily hacked. Should be pretty obvious once you see the standards we hold them to.

[1] https://www.commoncriteriaportal.org/files/ppfiles/pp_os_ca_... Page 9

[2] https://www.niap-ccevs.org/MMO/Product/st_vid11349-vr.pdf Page 20 to see the searches used to validate iOS

[3] https://download.microsoft.com/download/6/9/1/69101f35-1373-... Page 14 to see the searches used to validate Windows

Re: Cybersecurity Is Broken

#48
post #10

> You see, cybersecurity is broken because of the lack of consequences. It's really that simple. To put a slightly more explicit phrasing around the blog's message: Consequences fall on the wrong people . The ones screwing up chasing profit are not the ones feeling the pain. The damage falls on the innocent people the companies were trying to use as resources. This can be broadly classed as an economic externality, m…

Consequences are happening. People just don't see them because this happens well above the IC pay grade and takes some time to percolate down and no one wants to publicly announce you shitcanned 5-10 people in middle management and security leadership because you enter thorny employee litigation territory. That said, I agree with the author about mismatched expectations, though I can safely say that $500k year is VER…

> I don't care that you feel restricted

Yeah well, this is why we don't like security engineers. You absolutely should care that the policies you push for are making workers feel restricted.

For your job to even exist, engineers must be able to produce just remember that.

Re: Cybersecurity Is Broken

#49

Earlier quoted context omitted.

I am as much of a rust shill as you'll ever meet, but I agree that there is something beautiful and alluring and simple and engaging about C that few other languages match. It's basically an advanced macro assembler for an abstract machine, so there's all of the allure of using 6502 or 68000 assembly language but with none of the portability problems, and a vast ecosystem of libraries and amazing books to back it up.

I've enjoyed writing a few projects in x86-64 assembly as well, for what it's worth. Even though I'm sure that any C compiler would generate better assembly than my handwritten one. Flat assembler is great, by the way.

Any C compiler can generate better assembly for a function. But there's often some whole program optimizations that you can make, which the C compiler isn't allowed to do (because of the ABI/linker).

For example, a Forth interpreter can thread its way through "words" (its subroutines) with the top-of-stack element in a dedicated register. This simplifies many of the core words; for example, "DUP" becomes a single x86 push instruction, instead of having to load the value from the stack first. And the "NEXT" snippet which drives the threaded execution can be inlined in every core word. And so on.

You can write a Forth interpreter loop in C (I have), and it can be clever. But a C compiler can't optimize it to the hilt. Of course it may not be necessary, and the actual solution is to design your interpreted language such that it benefits from decades of C compiler optimizations, but nevertheless, there are many things that can be radically streamlined if you sympathize with the hardware platform.

Re: Cybersecurity Is Broken

#50
post #47
post #41

Back in my aerospace days I worked on an obscure secure operating system, which, unfortunately, was built for the PDP-11 just as the PDP-11 neared end of life. This was when NSA was getting interested in computer security. NSA tried applying the same criteria to computer security they applied to safes and filing cabinets for classified documents. A red team tried to break in. If they succeeded, the vendor got a list…

And still, despite the weakening, hardly anybody passed even the watered down requirements. Large vendors like Microsoft complained that the bidding process was unfair because they were not even allowed to compete just because they could not meet the minimum security requirements. So, the requirements were reduced until the requirements could meet the the abilities of the vendors. For operating systems in the early 2…

Tbh, Common Critera is basically security theatre. I've went thru the process and it's very checkbox driven and not truly design driven.

There is a mutual issue of both Procurement being an onerous shitshow and vendors being lazy about validating and ensuring security.

I have some thoughts about this but that would basically be a book (or an angry presentation at RSAC, Black Hat, DefCon, and Gartner Federal)

Some of the federal PoCs I've been a part of recentlyish (past decade) have returned to the red-teaming methodology that OP mentioned, but it's very Agency dependent.

Post reply on HN