Would you let users vouch for unknown software's safety with an upvote? Google does
- Reference: 1614844510
- News link: https://www.theregister.co.uk/2021/03/04/google_malware_upvote/
- Source link:
The ad and search giant’s rationale is that blocking all unknown software works but may limit productivity, while blocking only known unsafe software requires a lot of vetting.
[1]
“The obvious difficulty is that the more freedom you want to allow over the software your workforce can install outside your pre-vetted software, the more unmanageable the policy becomes,” [2]wrote Max Saltonstall, a developer advocate at Google Cloud.
Google’s answer is code called Upvote that it’s just [3]posted to GitHub .
[4]
“Upvote consists of both a web-based frontend for user voting and a policy server that works with the Santa system for Mac OS and the Carbon Black Protection (formerly Bit9) system for Windows,” Saltonstall wrote.
Google reveals how its Borg clusters have evolved yet still only use about 60 percent of resources (Alibaba might do better) [5]READ MORE
“When a user (a Mac user, in this example) tries to run an unknown binary Santa—running in ’lockdown’ mode, allowing only allowed software to run—blocks the binary and Upvote allows the user to vote to allow it, surfacing a VirusTotal analysis so that they can make an informed decision.”
“If others also vote to allow it and the total number of votes reaches a certain threshold, the voters—and only these voters—can then run the software.”
“This threshold is the first of two thresholds—a ‘local’ one and a ‘global’ one—that Upvote enforces. Voting continues even after the local threshold has been reached and anyone else who wants to run the software will still need to vote to allow it before they can run it. The voting stops only when the higher global threshold is reached, and only then is the software allowed for all users. You set the levels for these thresholds.”
Even a single downvote, however, disables voting “until an admin reviews the binary and either unflags it or downvotes it further to deny it as malware.”
Admins can also approve software in advance, so that users can run it without voting.
Saltonstall admits that this approach is risky because users could be wrong in their assessment than code is not naughty.
But he thinks the threshold scheme limits the impact of mistaken assessments. “Any potential infection is restricted by default to the subset of computers whose users have voted,” he wrote. “The fleet as a whole is protected until the global threshold—which you’d naturally want to set as a very high bar—is reached.”
Google is still working on Upvote and Santa for its own use but has created GitHub repos of both. Upvote’s repo has not had much recent love. Santa’s [6]seen action in February.
Over to you now, dear reader. What do you think of Google’s voting scheme? ®
[7]
JavaScript Disabled Please Enable JavaScript to use this feature.
Get our [8]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YEC9zeyLvckks9HCnSvI2wAAAA4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://cloud.google.com/blog/topics/developers-practitioners/peer-reviewed-allow-and-deny-software-installation-decisions-enable-scalable-protection
[3] https://github.com/google/upvote
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YEC9zeyLvckks9HCnSvI2wAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2020/04/29/new_google_borg_data_revealed/
[6] https://github.com/google/santa
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YEC9zeyLvckks9HCnSvI2wAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://whitepapers.theregister.com/
Convenience trumps security.....?
I believe that the saying is "Convenience trumps security"?
I am surprised that corporate policy allows the downloading of random software on to corporate machines, since for most use cases surely the tools required for people to do their jobs are pretty well-defined, and there is a process to request new software approvals.
With this approach the bad guys only have to be lucky once (dependent on other security countermeasures), and it doesn't matter if the user will downvote in future, the damage is done?
McBoatfacing
To get Boaty McBoatfaced means that you’ve made the critical mistake of letting the internet decide things. In other words, as much as we revere democracy, there are times — and they do typically involve the internet — when one’s fellow citizens deliberately make their choices not in order to foster the greatest societal good, but, instead, to mess with you.
The city of Austin, Texas, got McBoatfaced, for example, when it asked the internet to name its waste management service. The internet obliged by suggesting it be named in honor of Fred Durst, the frontman of the rock band Limp Bizkit.
Taylor Swift and VH1 got McBoatfaced when they asked the internet to choose a location for her forthcoming concert. The internet obliged by choosing the Horace Mann School for the Deaf and Hard of Hearing. (Ms. Swift, proving once and for all that she is a good sport, donated $10,000 to the school, before settling on another venue.)
But sometimes these episodes can take a darker turn. Mountain Dew got McBoatfaced when it asked the internet to name its new flavor. The internet — largely driven by members of the message boards Reddit and 4chan — obliged by naming the new flavor “Hitler Did Nothing Wrong.”
I don't get it
Either you know the software is safe (you wrote it, you audited it), or you do not. Therefore how can the majority vouch for it?
"I used it before" isn't exactly a glowing security review.
This is not gonna end well
So software installed on a single machine on your network is not going to be able to 'infect' other machines on the same network?!?
If forced to use this I would certainly have this facility disabled for the coloured crayon departments!