Porn-loving US official spreads malware to government network(bbc.com)
bbc.com
Porn-loving US official spreads malware to government network
https://www.bbc.com/news/technology-46030242
47 comments
Is the USGS too small to require firewalls that block obviously NSFW websites? At my workplace, going to such sites bring up a page saying the request was blocked before it left the corporate network.
Theres not really any place "too small" for systems like that that I can imagine anyway. we only have 15 people here and we implement filters like that. or in a rough pinch, use one of those free external DNS servers (opendns maybe?) that already have porn filtered out.
The other side Ive seen is "we're all adults, we don't need any filters here" coming from the higher ups. from my experiences, that usually means someone with significant say wants to look at that shit, or more rarely, feels that filters aren't a good use of ITs time.
just CYA on everything in those situations because it usually will end with fingers pointed at IT
The other side Ive seen is "we're all adults, we don't need any filters here" coming from the higher ups. from my experiences, that usually means someone with significant say wants to look at that shit, or more rarely, feels that filters aren't a good use of ITs time.
just CYA on everything in those situations because it usually will end with fingers pointed at IT
USGS is fairly big since they ended up with all the BIE (Bureau of Indian Education) lines. I get the feeling the person who did this doesn't have a problem getting around the firewall / web proxy since they control the thing.
No,you can even do that for your house. Porn is not hard to block.
It is not hard to block in the trivial case; after that you're playing cat & mouse and dealing with false positives.
Not in the trivial case. I meant most porn sites. All you have to do is use a reputation service and block uncategorized sites. Cisco OpenDNS actually offers a free DNS resolver that filters out most porn sites.
Also,surprised at the amount of responses on HN today that presume details....
Also,surprised at the amount of responses on HN today that presume details....
> use a reputation service and block uncategorized sites
This is what I was thinking of when I said "dealing with false positives"; those services make mistakes, and haven't hit every site.
This is what I was thinking of when I said "dealing with false positives"; those services make mistakes, and haven't hit every site.
I don't think anyone aims for perfection but a 90%+ true blocks and less than 5% false would be a high standard.
Ah, the long tail tautology. Everything is easy in the trivial case.
The problem is malware, not the porn.
What is the reasonable defense against this?
Intercepting firewalls like bluecoat are notoriously overbroad (and arguably open up MITM attacks on https). Desktop/laptop malware scanners notoriously use up CPU at murphaicly inconvenient moments.
Educating users is great, but attacks are getting sophisticated and it only takes one mistake.
Absent great intrusion detection, which I assume is not trivial, one that mistake is made, you have big problems. What is a realistic approach?
Intercepting firewalls like bluecoat are notoriously overbroad (and arguably open up MITM attacks on https). Desktop/laptop malware scanners notoriously use up CPU at murphaicly inconvenient moments.
Educating users is great, but attacks are getting sophisticated and it only takes one mistake.
Absent great intrusion detection, which I assume is not trivial, one that mistake is made, you have big problems. What is a realistic approach?
> Desktop/laptop malware scanners notoriously use up CPU at murphaicly inconvenient moments.
This isn't true at all. Sure for many "traditional" AV solutions it might be. But there is a pretty strong growing trend to use "next-gen" endpoint/AV protection that is extremely lightweight, so much so that users won't see any impact at all.
https://www.sentinelone.com/ https://www.crowdstrike.com/ https://www.carbonblack.com/
This isn't true at all. Sure for many "traditional" AV solutions it might be. But there is a pretty strong growing trend to use "next-gen" endpoint/AV protection that is extremely lightweight, so much so that users won't see any impact at all.
https://www.sentinelone.com/ https://www.crowdstrike.com/ https://www.carbonblack.com/
https://en.wikipedia.org/wiki/Principle_of_least_privilege
- Using a good OS (e.g. Linux w/ SELinux)
- Not giving admin access
- Block non-authorized peripherals
- Lock down network
You don't have to educate users if they can't make mistakes.
- Using a good OS (e.g. Linux w/ SELinux)
- Not giving admin access
- Block non-authorized peripherals
- Lock down network
You don't have to educate users if they can't make mistakes.
Ironic that he (or she) worked on a project called Eros.
I did desktop support for a fed agency in the early 2000s and this was so absurdly common that it was barely worth remarking about when it happened. I probably spent half of my day removing malware from people who went to porn and gambling sites.
The other half was from people who opened email attachments from pretty much anyone.
The other half was from people who opened email attachments from pretty much anyone.
Can I ask how did you become aware the machine was infected? Does not most malware hide itself? The way you describe it seems like it was easy for you to know. I consider myself pretty tech savvy but not sure how I would be aware if I had malware other then obvious things like page hijacking. Thanks
Most malware isn't designed by the likes of NSA, Mossad, FSB, or PLA, so you get reports unusual/excessive processor/storage/network activity. The time between something new showing up on the wildlist and antivirus/middlebox vendors creating signatures is also pretty short, so most of the time it's the antivirus/middlebox itself alerting you.
Also, malware with only regular user permissions can only do so much. This isn't like the good old days where everyone was logged into an administrator account or local privilege escalations were bountiful. Nowadays, you're stuck in an unprivileged login session that can't normally install a rootkit without giving yourself away via a UAC prompt.
Also, malware with only regular user permissions can only do so much. This isn't like the good old days where everyone was logged into an administrator account or local privilege escalations were bountiful. Nowadays, you're stuck in an unprivileged login session that can't normally install a rootkit without giving yourself away via a UAC prompt.
> Does not most malware hide itself?
The "cryptolockers" not, and what also regularly happened in the IE heydays was that suddenly there's a dozen toolbars in IE and every click anywhere would trigger another popup window with ads.
The "cryptolockers" not, and what also regularly happened in the IE heydays was that suddenly there's a dozen toolbars in IE and every click anywhere would trigger another popup window with ads.
Oh man, being old enough to remember those times I do not miss it. I do not miss dial up speeds as well.
At least the toolbars were easy enough to remove...
This was back in the windows 95/2000 days when it was mostly pop-up malware.
Who saves porn on a usb in 2018 tho
People who hate waiting for their 1080p video to buffer every time they want to skip around?
good point. The story said they were saving photos. Maybe the site of choice didn’t optimize their photos for performance?
[deleted]
People who like to make custom collections.
Is this supposed to be a shocking to us?
I find it more disgraceful that the Sys Admins of said Federal Agency aren't using GPOs to block unauthorized USB devices, than that fact than an employee was looking at porn.
I find it more disgraceful that the Sys Admins of said Federal Agency aren't using GPOs to block unauthorized USB devices, than that fact than an employee was looking at porn.
"An IT policy that prevents USB use should be implemented, the US Department of the Interior suggested."
...seriously? They want to make life harder for people that have legitimate USB mass storage needs because of this?
Do they have a DLP solution? DLP software can restrict what gets copied to and from a drive. Software restriction policies can be pushed to prevent execution from removable drives. Mind you,they said an "IT policy" meaning a rule that punishes anyone who uses a USB drive. This is the equivalent of your house getting broken into and your response is to have a rule thay punishes people for leaving the door unlocked instead of getting a home security system.
Also,why is this a bbc news story?
...seriously? They want to make life harder for people that have legitimate USB mass storage needs because of this?
Do they have a DLP solution? DLP software can restrict what gets copied to and from a drive. Software restriction policies can be pushed to prevent execution from removable drives. Mind you,they said an "IT policy" meaning a rule that punishes anyone who uses a USB drive. This is the equivalent of your house getting broken into and your response is to have a rule thay punishes people for leaving the door unlocked instead of getting a home security system.
Also,why is this a bbc news story?
For most enterprises, removage storage is a liability, e.g. ip thief, ip mismanagement, loss, security
There are better ways to handle file sharing than removable storage if an employee needs it
There are better ways to handle file sharing than removable storage if an employee needs it
And it's the security teams job to assess the security needs of the business and apply policies. If the entire business has a data loss risk then sure a blanket ban makes sense.
I disagree with what you said in that I believe "most businesses" need granular security policies that should be applied for specific departments.
There maybe better ways of handling files but say you're a news corp and sources give you data over USB or a fashion company that has freelancers walk into your location's in person to hand in photoshoots and large cad files. The resteiction would have an impact both to users and to the business.
For example,I worked at a company where specific departments were not restricted from accessing any website due to the possible business impact of them not being able to reach a required site.
I disagree with what you said in that I believe "most businesses" need granular security policies that should be applied for specific departments.
There maybe better ways of handling files but say you're a news corp and sources give you data over USB or a fashion company that has freelancers walk into your location's in person to hand in photoshoots and large cad files. The resteiction would have an impact both to users and to the business.
For example,I worked at a company where specific departments were not restricted from accessing any website due to the possible business impact of them not being able to reach a required site.
Honestly I am generally in favor of these policies. We have these at work. If you want to copy files, you use the network.
Note that they said "IT policy that prevents", not "IT policy that prohibits". So I am not reading the implication that people who use USB drives would be punished, rather, the OS would be configured not to allow USB drives.
Note that they said "IT policy that prevents", not "IT policy that prohibits". So I am not reading the implication that people who use USB drives would be punished, rather, the OS would be configured not to allow USB drives.
Fair enough,probably meant what you said.
In general these restrictions sound good but they're really bad when applied as a blanket policy to everyone. I prefet a "default" (not blanket) ban with exception/whitelist process in place. And this ,only for data sensitive departments.
The response to lateral movement via USB mass storage should be measured to restrict that specific attack vector(execution from mass storage). It is not an excuse to recommend a policy that solves problems outside the scope of the incident. If there are data loss concerns,the policy should be made after proper risk analysis,available solutions and user+business impact.
IMO,How you do these things tends to be more important than whether they get done or not(process>practice).
In general these restrictions sound good but they're really bad when applied as a blanket policy to everyone. I prefet a "default" (not blanket) ban with exception/whitelist process in place. And this ,only for data sensitive departments.
The response to lateral movement via USB mass storage should be measured to restrict that specific attack vector(execution from mass storage). It is not an excuse to recommend a policy that solves problems outside the scope of the incident. If there are data loss concerns,the policy should be made after proper risk analysis,available solutions and user+business impact.
IMO,How you do these things tends to be more important than whether they get done or not(process>practice).
No, they make the reccomendation because USB is not secure. Unless you can verify a USB device is not hostile, you should never plug it in to anything. Given how common and not suspisious USB storage device giveaways are, the policy makes sense.
Even leaving malisious USBs in the targets parking lot is a viable attack.
Even leaving malisious USBs in the targets parking lot is a viable attack.
If you're going that route,peripherals can also be "hostile" not just mass storage
...seriously? This has been best practice in government and enterprise for about as long as i can remember.
Lies. I know first hand a few very large corporations that don't have this restriction. I only know of one corporation that has a blanket ban.
"Government" is huge,the department in question does not handle confidential(classification) and above information.
"Government" is huge,the department in question does not handle confidential(classification) and above information.
My company, which is quite large, disabled all USB storage, with some exceptions. We survived.
I know of company that did that as well.
"We survived" is a very low standard. Security improvement should be measured against user impact and data being handled. The org. in the article does not have data confidentiality requirements that warrant such a severe user impact.
I know of first hand a corporation whose nationwide business would bw crippled by USB mass storage blanket ban. Context insensitivity is bad security.
"We survived" is a very low standard. Security improvement should be measured against user impact and data being handled. The org. in the article does not have data confidentiality requirements that warrant such a severe user impact.
I know of first hand a corporation whose nationwide business would bw crippled by USB mass storage blanket ban. Context insensitivity is bad security.
Blanket restrictions on USB drive usage is a good policy for any government or data sensitive organization. Considering that most people are idiots when it comes to security limiting the damage they can do is a good thing.
Respectfully disagree,blanket ban is good if the specific business unit handles sensitive data. Some departments might need to interact with external third parties and customers who would send them data over mass storage.
Most people are not idiots when it comes to security since it is the job of system and security engineers to design a secure system for "most people" ,however a security policy that does not take into measure context specific business impact is foolish.
Most people are not idiots when it comes to security since it is the job of system and security engineers to design a secure system for "most people" ,however a security policy that does not take into measure context specific business impact is foolish.
9000 porn sites? I can understand that if his job involved researching porn. Otherwise, who has time to visit that many websites at their job? Where does he find the time to do actual work with his busy porn-viewing schedule?
And most importantly, why is there no mention of termination of employment? How can someone spend all day at work browsing porn and jeopardize the network with malware/viruses and still be employed?
And most importantly, why is there no mention of termination of employment? How can someone spend all day at work browsing porn and jeopardize the network with malware/viruses and still be employed?
> How can someone spend all day at work browsing porn and jeopardize the network with malware/viruses and still be employed?
After doing some government consulting work, this does not surprise me in the slightest.
After doing some government consulting work, this does not surprise me in the slightest.
Actually, when I was a Fed worker, I was told that browsing porn sites was one of the very few things that could lead to immediate termination, without the usual Civil Service procedures (which take years to play out).
The operative word here is "could".
The articles (and report) says pages, not sites. It might just be different URLs of a handful of sites.
Purely hypothetical, as I dont know anything about this user, but I imagine the number is greatly increased if a site opened other pages when you visit a link, and if it required clicking through some pages to get what you are being promised.
...but porn sites wouldn't work like that, would they?
...but porn sites wouldn't work like that, would they?
What would be the solution to this in the future? As cybersecurity gets more and more serious, should we be essentially putting what would have been considered a decent corporate server in terms of speed/power 7 years before in front of every user?
Maybe Desktop-as-a-Service like with AWS Workspaces?
Or locked down, highly controlled devices like Chromebooks or a yet to be released Windowsbook?
Maybe Desktop-as-a-Service like with AWS Workspaces?
Or locked down, highly controlled devices like Chromebooks or a yet to be released Windowsbook?