“Zero Sum Game” The Nature of INFOSEC
The Zero Sum Game
Lately I have been party to as well as watched debate on Twitter and other venues by my compatriots in Information Security on their woes. The woes consist of laments about certifications like CISSP, how “Company B” is not following its policies, or just how much FUD (Fear, Uncertainty, and Doubt) there is within the business as well as how much of that is being spun by the media and vendors.
In thinking about all of this, I have come to the conclusion that security really is a “Zero Sum Game” meaning that no matter what you do, no matter how many policies you have, or blinking lights on an appliance that is alleged to keep out #APT in the end, you really have not won the day. In fact, if you have not been hacked or abused that day, it was really just a fluke.
You just can’t win.
Human Nature: The Anathema to Security (AKA The Deadly Sins.. No not Seven of Them)
Now, why can’t you win? Well, one of the primary reasons that you can’t is the human element. You can design all the nice nice Visio’s of the network, you can buy all the hardware you want and configure it to work securely, but, eventually someone will screw up that config either by fubar’ing it by accident, or, some C level exec will decide he wants his open access to the latest and greatest www site or game and demands a rule be added that is insecure.
Well, ok, maybe I am being a little rough there.. More than likely it will be some “mission critical” application that will make gazillions of dollars (maybe) and they ABSOLUTELY MUST HAVE IT! Even after we tell you that its not a good idea and make you sign off on the risk (if you are lucky and that actually happens in your org) So, the human element is the most dangerous of them all. Core to that element is the very nature of it… “Human Nature”
Human nature has various components, but I will focus on a few of them for this article.
Many of you might be saying “AH HA! The Seven Deadly Sins!” but, alas, no.. I could not make all 7 fit into this story so, its the 4 deadly sins. All of these behaviours in human beings lead to security flaws to be introduced and exploited because people add them to the system. Step back and take a look at all of the problems that most of us are talking about in the community…
It’s not hardware issues.. It’s wetware! From coding practices to lack of policies, to FUDDERY and Luddites running the show.
Think about it.
The real problems revolve not only about 0day but the fact that people are able to “click shit” as someone on my flist says in hashtag form.
Skynet has it right.
Greed, FUD, Charlatanism
Ahh, one of my pet peeves lately.. The FUD, The Greed, and the Charlatans. What can one say? The INFOSEC sea is filled with trawling sales sharks seeking to use buzzwords to sell their crap to unsuspecting Luddites in positions of power. We, the Infosec community, roll our eyes and try to call them on the floor as they say they can stop all APT from breaching your network!
But… In the end, most of the time its the Luddite with the wallet and the agenda. They all too often reach for the easy solution that comes in a shiny package and think they will be safe… Thus making us, *security* more sickened and thinking;
“shit, why do I do this again?”
Meanwhile, you see trolls like Ligatt or others out there stealing others work and pimping themselves to the unwashed masses while you, the one who has been plagiarised cannot even mount an effective case against them because it costs 10K just to start talking about doing it. Sure, we can send DMCA letters and we can shame them… But.. My experience thus far has been that they do not go away.. They just keep scuttling along like a digital cockroach.
Personally, I have called BS on so much lately in the news and being spewed by alleged “experts” that I am just inured to it now. I give up really, because no matter how much you say;
“This guy’s a moron!”
The media and the masses usually aren’t listening.. And the travesty goes on…
Cults of Digital Personality
Meanwhile, within our little insular community we have the cult of digerati. My tweets today about Tao *Beitlich* being case in point on this. Some people agree but for the most part, he is seen only through the vacuum of the echo chamber that he lives in. The same can be said about others out there but I don’t have time to name them all.
Look, people are people.. We all have opinions but none are Gods. This whole infosec rockstar thing just shows the fact that you would love to be mainstream and loved.. But.. you’re geeks and don’t fit in with the beautiful people. Frankly, many people who I would consider to be some of the best of the best never get to see the light of a camera… and they want it that way.
Look! I Can PWN THIS!
Ugh, now this.. This is a whole issue unto itself that could get a separate post. However, the highlight is this..
Do you really have to pwn shit then show it to the world just to get attention? Can we just talk about responsible disclosure a bit? Even if you tell the company in question do you give them time to fix the issue? Then, think about this, do you even expect that the Pandora’s box you have created and just outed for the masses is going to be fixed by Jose Shmoe and his company who then get compromised from your little baby?
I think more can be done on this issue… I just wanted to toss that out there though.
Lastly, the certificate BINGO or as I see it, the Certificate Mafia. Being certified means shit. However, as per my twitter reposts yesterday, it is the go to for employment today even though the said certified person may not be capable for the said job. Certs are subjective really as are the notion that if you went to college that you are capable of doing anything well but drinking and throwing toilets out of dorm windows.
Simple as that.
So, all this talk about CISSP for instance.. I agree.. It’s BS.. The board needs a shake-up but we shall see what happens with the new members. However, yet again, we are forced to deal with human nature and peoples proclivities to believe in things because they have a title or a set of initials attached to their names.