Re: firewall-wizards Digest, Vol 64, Issue 3 phishing
Kyle Creyts <[email protected]> Fri, 12 Apr 2013 18:01:46 -0700
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <CA+TcGd8Prar1GyK4OmrfQ0sP-ouspMGRt46_bjOpckeu=8RTaQ@mail.gmail.com> |
--===============0530172406== Content-Type: multipart/alternative; boundary=047d7bea42e051199d04da33906b --047d7bea42e051199d04da33906b Content-Type: text/plain; charset=ISO-8859-1 For one, the ship's hull is supposed to have "leaks" because water is supposed to flow through the hull, this is how this particularly strange ship operates and provides the passengers with essentials to do their duties. Otherwise we'd keep it out of the water. (ha ha, air gap) However, as security folk, we're rather concerned about things that are toxic to the passengers coming in with the water... Unfortunately, to most of the systems we use to filter hull intake and output, protecting the passengers and their belongings, the toxic materials tend to look a lot like water. Most of these filters don't even know what the toxins are today. They're mostly throwback technology from a time before toxins, which only had to know the difference between water, seaweed, and sand. They know what water typically looks like, and they'll keep out the seaweed and sand, but we've told them that we want to let water in. Some newer systems are a bit better about filtering out the toxins, but they frequently cost quite a bit, and most ships continue to run without them in place. Of course most of the passengers can't distinguish either. In spite of people running around and announcing the dangers of toxins, nobody really seems to know how to teach the passengers to identify them, and most of the passengers are in too big of a hurry to care; drinking one glass of water with toxins in it probably won't kill them. Besides, many of them have filters on the faucets. Even if most of the faucet filters can only catch toxins they've seen before... Some passengers even bring toxins with them onto the ship. As others have mentioned, this whole process is only one of many responsibilities of those responsible for it, if they are even still with the ship. There are only so many engineers on the boat, they usually have to be trained to maintain this process or clean up toxins, and they have a lot of other systems to care for. On Fri, Apr 12, 2013 at 1:33 AM, Dave Piscitello <[email protected]> wrote: > Stephen, > > I think your premise - that we are comfortable with this architecture > - is wrong, at least for this choir. > > Your analog also only looks at one dimension of the problem space. > > - the ship hull is compromised > - the pumps are working because someone thought to enable this > automation, and he's now serving on another ship > - much of the crew are not competent to deal with the crisis, and > don't have the time to fully assess the damage because they are > distracted by requests to solve far less critical issues so that other > of the ship's services remain in operation for the passengers > - the passengers pay no attention to the warnings, alarms, and have no > clue as to how to abandon ship > > I suspect that few on this list are comfortable with this scene. The > pump is there for many because it's keeping the ship afloat while we > patch and re-think how to prevent future hull breaches. Part of > re-thinking is coming up with better monitoring (of hull integrity) > and AWS; part is raising competencies among crew, and part is raising > security awareness among passengers. All of these require the > captain's approval and the captain has to empower the officers. > > On Thu, Apr 11, 2013 at 8:46 PM, Stephen P. Berry <[email protected]> > wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > > > John Michealson writes: > > > >>Check Point's gateway based AV went cloud based last fall. It has over 6M > >>signatures. They also have AntiBot, which has hundreds of millions of IP > >>and hosts classified. They are reclassifying 50k sites/hosts a day with > >>their ThreatCloud, and ThreatEmulation is in EA. Their Application > Control > >>has 4900 apps defined locally and 300K in the cloud. Combined with > >>education these are very effective tools. > > > > Perhaps I just have a bad attitude, but I'm imagining a ship with a > > great jagged hole below the water line and a very high output bilge > > pump that's almost but not quite keeping up with the flooding. The ship > > doesn't sink -immediately-, and hey that is a pretty impressive pump. > But > > I'm not sure that I'd say that the pump is a very effective tool, because > > the task I'm actually concerned with isn't---or, I would argue shouldn't > > be---pumping water out, which the pump does quite well, but rather with > > keeping the ship seaworthy by keeping the water from getting in in the > > first place, and the pump doesn't do that at all. > > > > I'm not trying to badmouth Checkpoint here. I'm sure their product is > > wonderful for what it is. But I find it distressing how comfortable > > we've become with living with network architectures that are perpetually > > in a state of failure. That are designed failed. You speak in glowing > words > > of the monumental efforts expended by Checkpoint. But while I can admire > > all that hard work, when I see as system that -needs- this sort of heroic > > effort -on an ongoing basis- just to continue functioning, I see a system > > that is fundamentally broken. > > > > > > > > - -spb > > > > -----BEGIN PGP SIGNATURE----- > > Version: GnuPG v1.4.10 (GNU/Linux) > > > > iQEVAwUBUWcEsR+T8Ptkg9h9AQI4swf/SAXPVaI8DXdOZ7OaUpcBUe6t2Y6ZQCGX > > 9VB0F2/3pyTWWdcVNUcDMVAiasgF1Pc/uHEhGFbFJNB13ubiUDsvQmjwJMkhN5fk > > GRT1eJLQrwSjAhzpwnQxTnQQQxwGBlaCb9Lo3db/PMZcxwFaYjzWncthZ6tX9YW5 > > IOD1Th0fvOEEJvtl+imqYanWUC2HXFJPP+F2f8eswOv2EI80C38EnTd/+Bn6vRcW > > PkCKJO3RCwRjdDACIlS/bx4aMrt36M/bbGgF+mRtn3NNNHqeGkMQV490b8pvRlxM > > DfeH/RAdUdOMQ7PVRCJAEKreI268ywabltzOya5MPBhY3RjRgJeBJQ== > > =JaqR > > -----END PGP SIGNATURE----- > > _______________________________________________ > > firewall-wizards mailing list > > [email protected] > > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards > _______________________________________________ > firewall-wizards mailing list > [email protected] > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards > -- Kyle Creyts Information Assurance Professional BSidesDetroit Organizer --047d7bea42e051199d04da33906b Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>For one, the ship's hull is supposed to have &quo= t;leaks" because water is supposed to flow through the hull, this is h= ow this particularly strange ship operates and provides the passengers with= essentials to do their duties.=A0<br> </div><div><br></div><div>Otherwise we'd keep it out of the water. (ha = ha, air gap)</div><div><br></div><div>However, as security folk, we're = rather concerned about things that are toxic to the passengers coming in wi= th the water...=A0</div> <div><br></div><div>Unfortunately, to most of the systems we use to filter = hull intake and output, protecting the passengers and their belongings, the= toxic materials tend to look a lot like water.=A0<br></div><div><br></div> <div>Most of these filters don't even know what the toxins are today. T= hey're mostly throwback technology from a time before toxins, which onl= y had to know the difference between water, seaweed, and sand. They know wh= at water typically looks like, and they'll keep out the seaweed and san= d, but we've told them that we want to let water in.=A0</div> <div><br></div><div>Some newer systems are a bit better about filtering out= the toxins, but they frequently cost quite a bit, and most ships continue = to run without them in place.=A0</div><div><br></div><div> Of course most of the passengers can't distinguish either.=A0</div><div= ><br></div><div>In spite of people running around and announcing the danger= s of toxins, nobody really seems to know how to teach the passengers to ide= ntify them, and most of the passengers are in too big of a hurry to care; d= rinking one glass of water with toxins in it probably won't kill them. = Besides, many of them have filters on the faucets. Even if most of the fauc= et filters can only catch toxins they've seen before...</div> <div><br>Some passengers even bring toxins with them onto the ship.=A0<br><= /div><div><br></div><div>As others have mentioned, this whole process is on= ly one of many responsibilities of those responsible for it, if they are ev= en still with the ship. There are only so many engineers on the boat, they = usually have to be trained to maintain this process or clean up toxins, and= they have a lot of other systems to care for.</div> <div><br></div></div><div class=3D"gmail_extra"><br><br><div class=3D"gmail= _quote">On Fri, Apr 12, 2013 at 1:33 AM, Dave Piscitello <span dir=3D"ltr">= <<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]<= /a>></span> wrote:<br> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex">Stephen,<br> <br> I think your premise - that we are comfortable with this architecture<br> - is wrong, at least for this choir.<br> <br> Your analog also only looks at one dimension of the problem space.<br> <br> - the ship hull is compromised<br> - the pumps are working because someone thought to enable this<br> automation, and he's now serving on another ship<br> - much of the crew are not competent to deal with the crisis, and<br> don't have the time to fully assess the damage because they are<br> distracted by requests to solve far less critical issues so that other<br> of the ship's services remain in operation for the passengers<br> - the passengers pay no attention to the warnings, alarms, and have no<br> clue as to how to abandon ship<br> <br> I suspect that few on this list are comfortable with this scene. The<br> pump is there for many because it's keeping the ship afloat while we<br= > patch and re-think how to prevent future hull breaches. Part of<br> re-thinking is coming up with better monitoring (of hull integrity)<br> and AWS; part is raising competencies among crew, and part is raising<br> security awareness among passengers. All of these require the<br> captain's approval and the captain has to empower the officers.<br> <div class=3D"HOEnZb"><div class=3D"h5"><br> On Thu, Apr 11, 2013 at 8:46 PM, Stephen P. Berry <<a href=3D"mailto:spb= @meshuggeneh.net">[email protected]</a>> wrote:<br> > -----BEGIN PGP SIGNED MESSAGE-----<br> > Hash: SHA1<br> ><br> ><br> > John Michealson writes:<br> ><br> >>Check Point's gateway based AV went cloud based last fall. It h= as over 6M<br> >>signatures. They also have AntiBot, which has hundreds of millions = of IP<br> >>and hosts classified. They are reclassifying 50k sites/hosts a day = with<br> >>their ThreatCloud, and ThreatEmulation is in EA. Their Application = Control<br> >>has 4900 apps defined locally and 300K in the cloud. Combined with<= br> >>education these are very effective tools.<br> ><br> > Perhaps I just have a bad attitude, but I'm imagining a ship with = a<br> > great jagged hole below the water line and a very high output bilge<br= > > pump that's almost but not quite keeping up with the flooding. =A0= The ship<br> > doesn't sink -immediately-, and hey that is a pretty impressive pu= mp. =A0But<br> > I'm not sure that I'd say that the pump is a very effective to= ol, because<br> > the task I'm actually concerned with isn't---or, I would argue= shouldn't<br> > be---pumping water out, which the pump does quite well, but rather wit= h<br> > keeping the ship seaworthy by keeping the water from getting in in the= <br> > first place, and the pump doesn't do that at all.<br> ><br> > I'm not trying to badmouth Checkpoint here. =A0I'm sure their = product is<br> > wonderful for what it is. =A0But I find it distressing how comfortable= <br> > we've become with living with network architectures that are perpe= tually<br> > in a state of failure. =A0That are designed failed. =A0You speak in gl= owing words<br> > of the monumental efforts expended by Checkpoint. =A0But while I can a= dmire<br> > all that hard work, when I see as system that -needs- this sort of her= oic<br> > effort -on an ongoing basis- just to continue functioning, I see a sys= tem<br> > that is fundamentally broken.<br> ><br> ><br> ><br> > - -spb<br> ><br> > -----BEGIN PGP SIGNATURE-----<br> > Version: GnuPG v1.4.10 (GNU/Linux)<br> ><br> > iQEVAwUBUWcEsR+T8Ptkg9h9AQI4swf/SAXPVaI8DXdOZ7OaUpcBUe6t2Y6ZQCGX<br> > 9VB0F2/3pyTWWdcVNUcDMVAiasgF1Pc/uHEhGFbFJNB13ubiUDsvQmjwJMkhN5fk<br> > GRT1eJLQrwSjAhzpwnQxTnQQQxwGBlaCb9Lo3db/PMZcxwFaYjzWncthZ6tX9YW5<br> > IOD1Th0fvOEEJvtl+imqYanWUC2HXFJPP+F2f8eswOv2EI80C38EnTd/+Bn6vRcW<br> > PkCKJO3RCwRjdDACIlS/bx4aMrt36M/bbGgF+mRtn3NNNHqeGkMQV490b8pvRlxM<br> > DfeH/RAdUdOMQ7PVRCJAEKreI268ywabltzOya5MPBhY3RjRgJeBJQ=3D=3D<br> > =3DJaqR<br> > -----END PGP SIGNATURE-----<br> > _______________________________________________<br> > firewall-wizards mailing list<br> > <a href=3D"mailto:[email protected]">firewall-wiz= [email protected]</a><br> > <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wiz= ards" target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/fire= wall-wizards</a><br> _______________________________________________<br> firewall-wizards mailing list<br> <a href=3D"mailto:[email protected]">firewall-wizards@= listserv.icsalabs.com</a><br> <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"= target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-= wizards</a><br> </div></div></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br>= Kyle Creyts<br><br>Information Assurance Professional<br>BSidesDetroit Orga= nizer </div> --047d7bea42e051199d04da33906b-- --===============0530172406== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============0530172406==--