6 ms·
The biggest defense on a societal level is a pervasive use of MFA for all applications, a good patching policy and backups.
by 1cvmask 5y ago
The biggest defense on a societal level is a pervasive use of MFA for all applications, a good patching policy and backups.
- crims0n 5y agoMFA and patching doesn’t help much when your perimeter gets knocked over by a zero day. There is quite a bit more that goes into security than these surface level recommendations. It’s why cybersecurity is such a hot field right now, with a massive talent shortage.
- giantg2 5y agoThere's a talent shortage because most companies don't want to make security a priority. The executives just go "eh, we have insurance for that" beyond some base threshold of security focus. The companies don't want to train either. I see way more dev postings that security ones. I'm an application security champion (in addition to being a dev) at my company and I'm looking for a new job. I see very little for security and almost none that are entry level. The ones I do see don't pay as well as the dev jobs either.
- jvanderbot 5y agoNot disagreeing, but Op's 'biggest' and 'societal' is not necessarily in disagreement with what you said, and leaves lots of room for necessary measures above and beyond.
- bitexploder 5y agoPeople get compromised with MFA all the time. It’s like 1/10th of a societal level solution. The real biggest part is also the hardest and that is education. Password managers, spotting phishing, spotting scam calls, using MFA, updating your software regularly, patching your ancient home router, etc. It takes a lot and these are all likely vectors you will get popped as a regular user in home equipment. There is no cure all and even as someone with 15 years of experience in the most technical parts of information security I have no simple solutions. Don’t use computers lol.
- giantg2 5y agoMost routers today have automatic patching schedules, so at least that one is getting better.
- jvanderbot 5y agoyes they do get compromised, but that doesn't mean you shouldn't use it. It also doesn't mean that's all you should use. If all of society used 2fa, we'd be much better, which is all OP was saying. Also, 1/10 can still be the biggest factor. but this is getting pedantic
- bitexploder 5y agoI don't think it is pedantic at all. I have been in the most technical parts of the infosec industry for 15+ years. The usability of security features and user education is the iceberg. Getting them to use MFA and such are the tip.
- 2snakes 5y agoI think you're so deep you don't see the forest for the trees. I doubt you are right about people getting compromised with MFA all the time. Especially with hard tokens. If you can substantiate that claim, I might learn something.
- bitexploder 5y agoI see it all the time in incident response summaries. It’s happened to our own customers many times. Standard “enter a few numbers” MFA is easy. Phishers collect it just like they get passwords. It raises the bar slightly. Hardware based MFA is a different situation. So it has to be qualified. But normal people logging intoxicated their bank accounts don’t have hardware MFA tokens. Most security professionals don’t even use them everywhere. We run phishing simulations and red teams dozens of times a year for F500 and high tech firms. MFA tokens are never what saves someone. Ever. We always get in. Often with phishing or smishing. I talk with many other folks that do red teams and phishing engagements.it’s of course anecdotal, but it’s a rather large and high impact customer set across people I know and our own customers. It will save some people some of the time. But not like people think. If my own deep experience and what I have seen in the field doesn’t convince you, that’s fine. I’m just sharing what I know to help people understand.
- jason-phillips 5y agoThose are good points, but there's quite a bit more to it than that. Off the top off my head, hunting within your network and reducing attackers' dwell time is another strong recommendation. Proxying internal network traffic with SSL-decrypt and rules-based analysis is another. Defining boundaries and firewalling off infrastructure to limit the blast radius is another. Scanning project code, dependencies and containers, and so on. It really requires a holistic approach and commitment. There is no one right answer here but it's something we all need to take seriously, imo. Disclosure: Have worked for several cyber-security startups with former .gov and .mil professionals while assisting many sensitive federal agencies myself.
- AyyWS 5y agoDoes SSL-Decryptand and rules-based analysis work? These are the times I've interacted with them: 1. Disabling SSL-Decrypt because it blocks HTTPS from PowerShell, bash, git, android studio and other comandline tools where I couldn't figure out how to trust our internal cert. I figured it out for Postman, but mostly I just couldn't figure it out. 2. Disabling or exempting rules that blocked our pharmacy app from going to webpages or perform SQL Queries that included legal drug names that were also illegal drug names. I think it's tough for non-security professionals who feel burdened and never get to see the benefits.
- jason-phillips 5y agoDefine "work". It's a layer in your overall plan. You should be able to apply it selectively and tweak as appropriate. If an internal resource is exfiltrating information somehow, the goal is to uncover that activity.
- rocqua 5y agoI'd expect in case of actual war, prepare for commercial network connectivity to fail. Satellites? Shot down. Fiber? ISP and higher-level routers are owned or simply DDOSed Cellular? what parts of the edge are owned is down, the core networks get targeted heavily. At best this will be spotty. The big internet-interconnects? Targets for cruise missiles and any other viable attacks. BGP? Fully poisoned and needs to be cleaned up before anything works. I'd expect the DoD to have their own networks up that are much more resilient. But our current highly interconnected, triered, and multi-faceted internet is going down the moment war between the great nations breaks out. It is simply too easy, and too valuable for the enemy not to do this.
- jnurmine 5y agoUnless EMPs also wipe out consumer electronics, there will likely be only islands of connectivity. I'm thinking folks with WIFI gadgets and COTS networking gear could very well build local connectivity, but those islands would be unable to talk to each other. The WIFI gadgets would have to mesh up over distances which are likely to exceed their range. Jamming and a generally dirty RF environment is likely in a war of such magnitude, so perhaps distributed laser links would work best, if one could create line of sight between the link nodes.
- KineticLensman 5y agoAlso cutting underwater cables. In the news in the last few days as a potential act of war [0], and the real-world effects have already been , e.g. [1] [0] https://www.forces.net/news/chief-defence-staff-russia-cutting-underwater-cables-could-be-act-war https://www.forces.net/news/chief-defence-staff-russia-cutti... [1] https://en.wikipedia.org/wiki/2008_submarine_cable_disruption https://en.wikipedia.org/wiki/2008_submarine_cable_disruptio...