Bruce Schneier Joins Startup Co3 Systems(threatpost.com)
threatpost.com
Bruce Schneier Joins Startup Co3 Systems
http://threatpost.com/bruce-schneier-joins-startup-co3-systems/103429
3 comments
Naive question, but common our enterprise break-ins where a company would need a tool devoted entirely to it?
That depends on the industry and company size, and also on your definition of a breach.
45% of all retail companies DETECTED at least one serious information systems breach in 2013. (Many more would have experienced a breach without knowing.)
According to Trustwave's 2013 Global Security Report, the top 5 most breached industries are 1. Retail 2. Food & Beverage 3. Hospitality 4. Financial Services and 5 Non-Profits, followed by High-Tech.
The Trustwave report doesn't break things down by company size. But you can be sure that large retail companies (Macy's, GoDaddy, Microsoft, Goodyear, Betty Crocker, etc) have many many incident response teams who follow up on multiple incidents each day. Most aren't serious, of course. But they all need to be handled thoroughly because one mishandled serious breach is all it takes to cost a company as much as hundreds of millions of dollars in damages.
A quick LinkedIn search shows 150,000 people working in incident response positions in the U.S. A good bit of those work for incident response service providers like Mandiant https://www.mandiant.com/services/incident-response/ Most companies under ~300 employees aren't going to have in-house IR teams (many do though). They'll hire companies like Mandiant to respond to serious incidents while letting insurance handle the less serious incidents.
45% of all retail companies DETECTED at least one serious information systems breach in 2013. (Many more would have experienced a breach without knowing.)
According to Trustwave's 2013 Global Security Report, the top 5 most breached industries are 1. Retail 2. Food & Beverage 3. Hospitality 4. Financial Services and 5 Non-Profits, followed by High-Tech.
The Trustwave report doesn't break things down by company size. But you can be sure that large retail companies (Macy's, GoDaddy, Microsoft, Goodyear, Betty Crocker, etc) have many many incident response teams who follow up on multiple incidents each day. Most aren't serious, of course. But they all need to be handled thoroughly because one mishandled serious breach is all it takes to cost a company as much as hundreds of millions of dollars in damages.
A quick LinkedIn search shows 150,000 people working in incident response positions in the U.S. A good bit of those work for incident response service providers like Mandiant https://www.mandiant.com/services/incident-response/ Most companies under ~300 employees aren't going to have in-house IR teams (many do though). They'll hire companies like Mandiant to respond to serious incidents while letting insurance handle the less serious incidents.
Among all enterprises? Very common. You don't hear about the vast majority of them.
(Keep in mind a break-in doesn't have to have been targeted specifically at you to cause damage or to be classified as a break-in.)
(Keep in mind a break-in doesn't have to have been targeted specifically at you to cause damage or to be classified as a break-in.)
It doesn't matter if they are common. What matters is that if/when it does happen, the results aren't catastrophic.
While I agree with his viewpoints, I just can't take a security professional (or CTO) seriously who uses Windows as their primary machine.
So basically you don't take something like 3 of the top 5 vulnerability researchers in the world seriously.
Can you please explain why? Is there some evidence you have that shows that Windows is less secure than any other OS? Please take into account the huge market share which means that malware writers will spend a disproportionate amount of time developing for Microsoft systems.
Also, people who run other Operating Systems tend to be more technically skilled than people using Windows.
This is not to excuse Microsoft, they could certainly do better. But so could Apple and Debian.
This is not to excuse Microsoft, they could certainly do better. But so could Apple and Debian.
My remark was certainly flippant. It was a gut reaction to statements he's made about a Linux machine as the best bet (see his interview with VICE), but yet he still primarily uses Windows.
I think there's a lot to be said for those who practice what they preach rather than sticking with a lesser option out of convenience.
I think there's a lot to be said for those who practice what they preach rather than sticking with a lesser option out of convenience.
Perhaps he's more skilled at Windows than at Linux? In which case, if he were to switch to a platform that's unfamiliar, he would be more likely to make an error that would lead him to being vulnerable.
I'd suggest that by using a platform that he knows how to make secure rather than one he's unfamiliar with, he is acting in the best way to ensure the security of his device.
I'd suggest that by using a platform that he knows how to make secure rather than one he's unfamiliar with, he is acting in the best way to ensure the security of his device.
Listen to what I say, don't do as I do.
Also there are very good reasons for using windows - dogfooding your own security solutions, fact that a lot of threats are targeting windows machines and the fact that he is not a high profile target (or wasn't before the NSA stuff) so no one will waste undisclosed zero day on him.
Also there are very good reasons for using windows - dogfooding your own security solutions, fact that a lot of threats are targeting windows machines and the fact that he is not a high profile target (or wasn't before the NSA stuff) so no one will waste undisclosed zero day on him.
Maybe they have done what is required to fully secure the box? (Short of removing whatever BD NSA might actually have in windows ;-) )
I really doubt the fact that NSA have direct backdoor in windows. A lot of countries will treat it as casus belli.
> I really doubt the fact that NSA have direct backdoor in windows. A lot of countries will treat it as casus belli.
Against the US? I doubt it. Countries sometimes fail to treat actual armed intrusions without local consent by the US as casus belli because of the imbalance in military power, and you want me to believe that there are "a lot" of countries that will treat a backdoor in Windows as an excuse for war?
Against the US? I doubt it. Countries sometimes fail to treat actual armed intrusions without local consent by the US as casus belli because of the imbalance in military power, and you want me to believe that there are "a lot" of countries that will treat a backdoor in Windows as an excuse for war?
I doubt that NSA has a Microsoft-complicit backdoor in Windows, but would be amazed to find out that they didn't have its functional equivalent. For any given mainstream OS, assume NSA can own it up at will.
I am absolutely sure they can enter almost anything not behind solid air gap.
Doesn't that contradict your previous post?
Not the way I read it. The previous post seems to be suggesting the NSA doesn't have some backdoor into Windows that Microsoft put there for them explicitly, while the followup suggests that even without such an explicit backdoor, one should assume the NSA can take control of just about any system with a network connection (which is probably not explicitly true, but is true enough that you should just assume it).
The second suggestion being they (the NSA) have a (likely lengthy) list of exploits found in common OSes (and/or firmware or CPU microcode) that they have never divulged and that they have discovered like any external security research would have (albeit one with a very large budget and a very strong incentive to find such control vectors).
The second suggestion being they (the NSA) have a (likely lengthy) list of exploits found in common OSes (and/or firmware or CPU microcode) that they have never divulged and that they have discovered like any external security research would have (albeit one with a very large budget and a very strong incentive to find such control vectors).
Ah - yes that makes good sense.
I prefer to assume that both are true.
I prefer to assume that both are true.
I suppose it's good to bear in mind that Schneier now has a dog in the race any time he writes about incident response. But then, he had one about managed security services while he worked at Counterpane and BT. It didn't seem to impact his writing much.
As far as I know, Schneier remains a fellow at Berkman at Harvard, which is presumably where most of the stuff he does that is actually interesting will be done.
(I worked with and very much some other people on the management team at Co3 in a previous life; I've got nothing bad to say about it, just some perspective.)