Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I find it interesting that this article, while excellent and informative, does nothing to address the most frequent attack vectors to which most users remain vulnerable. Yes, it's true that simple theft (or worse, industrial espionage) is a real threat. People may take your hardware and attempt to steal your data. All of these solutions would certainly restrict their ability to do so (and as a security professional, I recommend following these procedures), but this article is analogous to putting a car without airbags in a garage with blast doors and calling it "safe."

The most common attack vectors are not super spies silently breaking into your home or office and attacking your boot loader. Far, far more frequently, the culprit is operating system and non-OS application vulnerabilities. Remote root exploits are obviously the most severe, but even information leaks, access gained without privilege escalation, insufficient transport layer security and others can relatively easily compromise the data that is being so thoroughly protected by complex security measures. The important thing to understand is that these attacks run while the computer is running, not against a cold hard disk. Military grade encryption would not protect against these threats.

Again, I would always say that the more security you can throw on a system without negatively impacting user experience, the better; that said, make sure to install malicious host detection software, use an IDS, employ access control lists, and more than anything, make sure you're checking security advisories and keeping your patch levels up to date. In my professional experience, the biggest security problems are caused by people using "very stable" software who don't want or see the need to update.

Anyway, I'm not trying to bash the article at all--I thought it was a great read--but while we're on the subject of security, it's better to protect against common threats than against a state-sponsored intelligence agency trying to steal your text files.



With regular users in mind, how much of a problem is social engineering these days?

A couple years ago some Cisco researchers infiltrated a botnet and got to interview the operator. They asked him what vulnerabilities he uses to grow his network, and he said none:

http://www.cisco.com/web/about/security/intelligence/bots.ht...

Instead he spams instant messaging networks with "check out this cool software: [link]", and he could count on 1% doing it.

This is the sort of thing my parents and grandparents fall for. Combine it with social networks and the message appears to come from a trusted person.

For this reason I'm glad to see the arrival of curated app stores, despite their many drawbacks. For regular users I think it will make it harder to be tricked into voluntarily installing malware. But I don't know how significant this problem is compared to not staying patched.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: