Info-saturated techie builds bug alert service that phones you to warn of new vulns
- Reference: 1641985331
- News link: https://www.theregister.co.uk/2022/01/12/bugalert_matt_sullivan_interview/
- Source link:
Bugalert, founded by product manager Matt Sullivan, is a crowdsourced venture that he hopes will take the pain out of trying to tell the signal from the noise when security researchers make high-impact vulnerability disclosures.
Keeping up with fast-developing situations, such as the Log4j vuln and its iterations, is "extraordinarily overwhelming," he told The Register – and he reckons relying on CVE number assignations is just too slow in this day and age. (It took around a day and a half for the initial [1]Log4j vuln to be given a CVE in November 2021, before an exploit made its way onto Twitter a week later.)
[2]
"You know, I'm reading about this vulnerability," sighed Sullivan as he described the Log4j frustration that led to Bugalert. "It's midnight in my time zone. And this tweet had gone out at nine in the morning in my local time, saying that there had been this catastrophic issue. And I found myself extraordinarily frustrated that somebody had a 15-hour lead time and we couldn't, you know, get the word out."
[3]
[4]
There will be very few people in infosec who don't recognise that problem. If you follow the right pseudonymous Twitter accounts, you can gain [5]crucial hours or even minutes when a new vuln becomes public knowledge. Folk who rarely look away from Twitter are even more likely to spot a new vuln needing immediate remedial action – while those who insist on having lives in meatspace (or even sleeping, the weirdos) can be left behind.
Sullivan described Bugalert as depending on vetted volunteers ("somebody who has depth of experience in the industry, to know if something's a big deal or not") who send push alerts to registered subscribers.
[6]
People do this via Bugalert's GitHub page, explained its founder, saying this lets him "select a number of repository maintainers who are geographically dispersed" for round-the-clock coverage. As for the process, it sounds very simple: "When they see that a notice is needing to be reviewed and to be merged in, which will trigger the alert process, they can react to those."
It's an intentionally human-dependent process so far and doesn't rely on ingesting or digesting traditional threat intelligence feeds. With that in mind, what's the difference between Bugalert and traditional mailing lists or RSS feeds?
Critical notifications sent by Dell to enterprise customers
Mailing lists, as their name suggests, send emails. "I don't know about you, but my email is a disaster," said Sullivan semi-seriously. "Pressing things and email are not a good mixture for me."
The other problem with mailing lists, in his view, is that vuln notification services from vendors "are held to a very high standard of accuracy."
Sometimes it's more important to quickly apply mitigations than to spend time being precisely correct about the way a particular vuln affects certain environments or deployments.
[7]
"I think it's reasonable that you alert someone, saying 'there is an issue, and we don't know how to tell you to fix it'. But your job now is to be aware of it and at least detect it," explained Sullivan.
In his vision, Bugalert-subscribing organisations will receive an alert, "grab a cup of tea while their build completes," increment their product's version number: "And an hour later it's out in production, and they go back to bed."
Very neat on paper. But what of the telephone option? If you sign up for that, Bugalert will call your phone and play a text-to-speech version of a vuln alert created by one of Bugalert's volunteer bug triagers. Sullivan said he imagined users saving Bugalert's phone number and allowing it to bypass their Do Not Disturb settings, something El Reg thinks might be a little fanciful.
More concretely, however, he estimated about three-quarters of Bugalert's 600 current subscribers have signed up for SMS alerts: "There's clearly value there. People are again saying 'My email is not enough, I need something that's a little bit more direct for me'… people are sure interested in early notification, but they're also interested in different types of notification than they currently are receiving."
[8]Miscreants started scanning for Exchange Hafnium vulns five minutes after Microsoft told world about zero-days
[9]Four million outdated Log4j downloads were served from Apache Maven Central alone despite vuln publicity blitz
[10]Just 2.6% of 2019's 18,000 tracked vulnerabilities were actively exploited in the wild
[11]We regret to inform you there's an RCE vuln in old version of WinRAR. Yes, the file decompression utility
Industry reaction has been mixed, with a Reddit thread about Bugalert containing both praise and informed criticism. One poster observed: "You built an infrastructure to send emails/SMS but you are also looking for volunteers to report, triage, validate, and approve vulnerabilities. The volunteer phase is what CVE is doing, albeit too slowly."
As for funding, so far it's all dependent on Sullivan's bank account. He told us he'd consider financial contributions or sponsorship in the future but rejected the idea of sticking up banner ads, something that'll doubtless please Vulture Central's backroom gremlins.
Some won't see the value of this project, arguing Bugalert reproduces any number of notification mechanisms. Others will be horrified at the idea of strangers being able to wake them up with robots reading words down their phones in the middle of the night. Nonetheless, a few hundred sysadmins out there think it fills a niche. ®
Get our [12]Tech Resources
[1] https://www.theregister.com/2021/12/13/log4j_rce_latest/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yd8JOZ1J3ordlDAu5w9dbAAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yd8JOZ1J3ordlDAu5w9dbAAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yd8JOZ1J3ordlDAu5w9dbAAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/05/19/hafnium_scans_5_mins_post_disclosure/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yd8JOZ1J3ordlDAu5w9dbAAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yd8JOZ1J3ordlDAu5w9dbAAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2021/05/19/hafnium_scans_5_mins_post_disclosure/
[9] https://www.theregister.com/2022/01/11/outdated_log4j_downloads/
[10] https://www.theregister.com/2021/02/18/cve_exploitation_2_6pc_kenna_security/
[11] https://www.theregister.com/2021/10/21/winrar_rce_vuln_positive_technologies/
[12] https://whitepapers.theregister.com/
be horrified at the idea of strangers being able to wake them
Well, I get that, but isn't that more or less what the "On Call" people are for?
Re: be horrified at the idea of strangers being able to wake them
I used to be "On Call" in a big multinational telecom company some years ago.
They would give you bonus + expensive equipment to receive the calls and do the job.
Unfortunately one of the engineers once left the company and took the equipment and tools to the adversary.
Management got really angry.
Reader
Now they need to make an app that will read all these notifications and "take care" of them.
What usually happens is that when there is too many of those and most of them are irrelevant, the engineer sets up a filter and get them to land in a folder bypassing the main mailbox. Ignorance is bliss.
When something hits the fan? "We get so many alerts, we must have missed that one".
Re: Reader
Exactly this :(
This morning my 'Alerts' folder had 261 alerts, ranging from server down, system down, HA unavailable, latest vulnerability patch from Aruba, cert expiration warnings and so on and so forth.
Ops doesn't get say in 50% of how these alerts are set. Random project team sets up new system, creates alerts... not sure which ones they should use...*shrug...select all, assign to Ops team distribution list...
Been a sys eng for 18 years now and i just let alerts wash over me like a wave. No chance to review them, definitely no chance to deal with them, no chance manager layer will agree to more sys engs in my team..
So I just add a line to our Risk register every 3 months saying ' not enough resource, can't cover all vulnerabilities '
Management review register every 3 months and I never hear a thing back.
Oh well..
Re: Reader
That's being set up for failure and low moral. Nobody should be put in that place.
Treat yourself better than they do, offer a solution (staffing) with a "there arn't worse jobs out there" or "I can't watch the place burn down anymore, it's to hot in here" type notice. You deserve better.
Re: Reader
One important piece of context missing from the article is that alerts are only sent for vulnerabilities bad enough that you should literally be waking up out of bed to handle them. We're talking one to two alerts a year. More info: https://mattslifebytes.com/2022/01/04/bugalert-org/
I'd be tempted to make a tiny mobile app with Firebase just to receive notifications, though I'm not sure how you'd get it past Apple reviewers.
Sending a broadcast message with GCM or APNs is free. Sending SMS is relatively expensive.