Infosec not your job but your responsibility? How to be smarter than the average bear
- Reference: 1658748427
- News link: https://www.theregister.co.uk/2022/07/25/infosec_not_your_job/
- Source link:
Those, it seems, belong to a shady organization called… [1]Microsoft .
What the hell are we supposed to do with this information? Is this an error in the suspicious activity detector? Is this the result of hacking attempts via compromised Microsoft systems? Is it Microsoft bungling some sort of management task? At the time of writing, nobody knows. Microsoft hasn't offered an explanation. That means that nobody can be sure how to react. There's clearly something wrong, but what is the risk? If you don't know, you don't do much about it. Wise?
[2]
Things can go the other way. "Why is nobody writing about this?" one correspondent asked this week, going on to say they did their most sensitive work on pre-2005 technology air-gapped from the internet.
[3]
[4]
Why 2005? Because that's roughly the date that undocumented independent processors like [5]Intel's Management Engine started to be widely deployed on motherboards and in CPUs. That's quite a remarkable response to a threat that's difficult to enumerate. It's possible because it happens that manufacturers [6]plant secret backdoors in systems at the behest of state agencies, but are they coming for our correspondent? Are they coming for you?
No, they are not, not unless you are doing things that interest state-level agencies. And if you are, you can't stop them by vintage computing. Talking to friends around the world and scared of supply chain compromise? You could build a worldwide network of completely unbreakable encrypted voice circuits using ZX Spectrums sourced from eBay. The Spectrum has a 1970s-vintage processor that is guaranteed not to be backdoored, with just enough horsepower to do one-time pad encryption. There's literally nowhere for a hardware or software intercept to hide. But if your messages are important enough to an attacker, they'll burgle, bribe or bug their way to the data before or after it's encrypted.
[7]
This basic equation, the cost to the attacker versus the value of what they might get, is the cheapest yet most effective infosec aid on the market. There's always a cost to an attack, whether it's the risk of detection or being traced, or in the use of exfiltrated data giving the game away. As a defender, you need to be in the Goldilocks Zone of infosec paranoia – not too much, not too little, but just right. A sober view of your attractiveness as a target will get you there.
[8]Engineers on the brink of extinction threaten entire tech ecosystems
[9]Even robots have the right to learn from open source
[10]We need a Library of Congress – but for the digital world
[11]Cloudflare's outage was human error. There's a way to make tech divinely forgive
Applying that to the Outlook mystery helps diagnosis, even in the absence of any help from Microsoft, the curs. Pretend you're Evil Haxxor who's got into Microsoft's systems. Have you done this to conduct random acts on random users, risking triggering the tripwires? Bad guys pay opportunity costs just like the rest of us. Time spent building a major compromise can't be blown on low-value results, not while phishing and other intrusions work so much better.
Conclusion: cock-up, not criminals. And so it was. When Microsoft eventually responded, it waved the white flag of fiasco. "We're working to resolve a configuration issue causing some customers to receive these notifications in error."
Take another of last week's security stories, the tired old tale of [12]out-of-date WordPress plugins opening up millions of sites to automated attacks. Extremely low cost to le chapeau noir, who can get a script, make a coffee, and come back to a list of interesting targets who clearly don't have much of a clue.
If you have a WordPress instance, is it worth the extra vigilance keeping up with plugin patches? You might find a better, simpler way of doing whatever it is you're doing, or decide it's not worth doing at all. Aerospace engineers know the safest, cheapest component to fly is the one that's not there. You don't need to understand plugin vulns to come to the same conclusion, just by being clear about what things cost compared to what’s on offer.
[13]
Some things can't be helped. Should you apply security patches as soon as they're available? Yes, of course. Everyone says so. [14]Unless they're broken , then you should wait a bit for others to take the pain. It's not a winnable war, and that's OK.
If you're not paid to spend all your time as a security professional but have to make decisions about security, and that's most of us, it's a numbers game.
Think like an attacker – and their accountants – and a lot of hard decisions become easier. You won't make all the right calls, but you'll do a lot better than the average bear. That's OK too. ®
Get our [15]Tech Resources
[1] https://www.theregister.com/2022/07/21/outlook_sign_ins/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yt6@JyvBOkh8NL83lzVXbwAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yt6@JyvBOkh8NL83lzVXbwAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yt6@JyvBOkh8NL83lzVXbwAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://en.wikipedia.org/wiki/Intel_Management_Engine
[6] https://www.npr.org/2020/03/05/812499752/uncovering-the-cias-audacious-operation-that-gave-them-access-to-state-secrets?t=1658442483747&t=1658481434377
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yt6@JyvBOkh8NL83lzVXbwAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/07/18/electrical_engineers_extinction/
[9] https://www.theregister.com/2022/07/11/robots_open_source/
[10] https://www.theregister.com/2022/07/04/digital_museum/
[11] https://www.theregister.com/2022/06/27/cloudflares_outage_opinion_column/
[12] https://www.theregister.com/2022/07/15/buggy_wordpress_plugin/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yt6@JyvBOkh8NL83lzVXbwAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.theregister.com/2022/07/18/windows_11_patch_problems/
[15] https://whitepapers.theregister.com/
Not just for the non-pro
" If you're not paid to spend all your time as a security professional but have to make decisions about security, and that's most of us, it's a numbers game. "
Even if you're paid to spend all your time as a security professional, it's still a numbers game. What's more, it's a statistical numbers game because individual instances are imponderable, and it's a non-stationary statistical numbers game because the attack space is constantly changing. So the best course of action is affordable pre-emptive resilience (proportionate common sense protection against generic threats) so as much as possible of the bad stuff bounces off leaving you unharmed. Then you can concentrate your day to day attention on the residue that needs special treatment as it arises.
Re: Not just for the non-pro
I have literally just come back from having lunch with one of my closest friends. He explained how he was happy to branch out into cybersecurity. He created a new company for that (he already has several that are functioning fine, so he has form in that), company which has secured partnerships with major anti-virus companies present in Europe. He told me how happy he was that this new creation already had about a quarter million euros in orders and upcoming sales.
The whole time I couldn't help thinking : my God what have you gotten yourself into ?
Sure, the money appears to be rolling in now, but what's going to happen to you six months down the line when Putin's dogs savage your clients' data through whatever means ?
I fear for him. Cybersecurity is a world of treason and backstabbing, and you never know where it'll come from.
Are you a target?
> A sober view of your attractiveness as a target will get you there.
That's true of course, but needs to be taken with a grain of salt: The "carpet bombing" method of compromising targets (to use as attack relays or simply to steal banking credentials from) doesn't really care if you're the financial director of a Fortune 500 company or a penniless student. This is the basic threat level everybody needs to be protected from, and unfortunately it's a moving target for laymen, since at any moment the world can discover that some widely used piece of kit has hardcoded admin passwords or some such (and unfortunately given the quality of today's kit it's not "if", it's "when").
"Sober view of your attractiveness" indeed, but don't find yourself in the situation to say "Hey, I'm not attractive, why do you hack me?"
Re: Are you a target?
Ah that is the problem, my attractiveness seems to depend on others not being sober :(
False Flag???
Quote: "...cock-up, not criminals. And so it was. When Microsoft eventually responded, it waved the white flag of fiasco..."
Huh......or maybe a false flag.....the so-called "cock-up" was actually in Fort Meade, MD.....by dubious actors at a "known associate" of the dubious actors located in Redmond, WA......
I think we should be told!
So an IP address assigned to Microsoft? So like an IP for anything anyone pays to be hosted in azure?
Same issue with domain names, anybody can buy Azure storage are hosted on *.microsoft.net DNS addresses, even has a MS company HTTPS cert! that's been used for years in phishing.
https://www.bleepingcomputer.com/news/security/phishing-attack-uses-azure-blob-storage-to-impersonate-microsoft/
"This basic equation, the cost to the attacker versus the value of what they might get, is the cheapest yet most effective infosec aid on the market."
Also include the elapsed time taken to attack vs the time the information is likely to remain valuable.