I think we need some sort of awareness day for the general public to understand what internet security _really_ is. Whenever I see news reports, it's always cast as "hackers broke in to..." such and such. Yet if some brick-and-mortar business is robbed because the owner left the front door unlocked, people would rightfully put the onus mostly on the store owner.
EDIT: Wow. I'm being modded into the basement. When did Hacker News become so PC? Victim-blaming? Seriously? The VNC connections illustrated on this site are that way because of incompetence and ignorance. The reason there are no unlocked brick-and-mortar businesses is because it is due diligence to protect one's assets from not just criminals, but simple mischief.
> Yet if some brick-and-mortar business is robbed because the owner left the front door unlocked, people would rightfully put the onus mostly on the store owner.
No, there were days when people did not even lock their cars and their houses (but maybe you are too young to have known that time where you live) because it was not expected that anyone would actually rob anything. Especially in communities where everyone knew everyone else. And if a robbery happened, the blame would still have been put on the thief, not the owner.
This is a sensible argument, but here is my counterpoint.
Such situation rely on mutual trust, and only work on small scales (village, loose neighborhood). On the Internet, there are billions of people that live close by.
I think the main discrepancy is that people really do not understand either that the Internet connect them to everyone or how vast the world really is.
there were days when people did not even lock their cars and their houses
These are still are such days. There still are thousands of communities, even in California, where you can get away with this. The difference is not time but population density. There was probably never a time when you could leave your home unlocked and unguarded in urban cities.
>>The difference is not time but population density. There was probably never a time when you could leave your home unlocked and unguarded in urban cities.
There was and not so long ago (e.g. 40 years ago in Portugal or Poland. Probably many other countries). So I would change your statement:
The difference is not time but population density and specially politics/religion.
I'm 46, and yes I remember those days. In fact I live in Canada, and in my neighbourhood it is not uncommon for people to leave their doors unlocked. But if I lived in a different neighbourhood with a high crime rate, my doors would not only be locked, but probably bolted and an alarm system would be set every time I left the building.
The burden and responsibility to protect my home is mine. This isn't an either/or as to who to blame, it's a both/and. So back to the link. If you have a high-value service like an electrical grid, or dam, or nuclear plant that is open to the Internet (the most crime-ridden neighbourhood on the planet), do you really honesty think the media's typical response of "hackers broke in to..." is the correct narrative?
I pick number four: education. Which goes back to my point, that we need some sort of public awareness day on what Internet security _really_ is, or something - I don't really care what it is - to change the narrative. Otherwise we're going to have some huge disaster to some major infrastructure because of an unprotected remote connection like the article shows, and the company that committed it will likely cover up the cause.
People make well-meaning assumptions about security. For example, most of the oscilloscopes that we use at work have remote access turned on with a trivial password (the scopes themselves run windows, and have a VNC server installed [1]).
If you go read Tektronix's instructions - their screenshots show "no authentication" selected.
This itself isn't really an issue, since the networks that we're connecting these to are isolated, inbound-only lab networks. We know that. Our lab admins know that. The network security guys know that. There are exceptions filed for the IPs of these devices.
However, if someone ever -changed- that network configuration and opened it up to the rest of the corporate network (or for some terrible reason, the internet), those scopes would be just as ripe for takedown as the stuff shown in TFA.
It just takes that small network change to enable something -else- to access the WWW (code download for security updates, anyone?) that exposes our other items on the network. In fact, I can think of several reasons why someone might expose a VNC:
1. Actual remote control -within- a facility, but probably in the deployment guide says "use a secure network"
2. Someone wrote a cool Web GUI to "modernize" something, and used VNC (undocumented and poorly-configured) to pull off what they pulled off
3. Someone exposed a subnet to the internet to enable remote access for something -else- which was probably properly-secured, but happened to -also- expose the thing hosting the VNC server.
I live in one of the largest cities in Finland, and I routinely see people leave their bicycles unlocked in the town center, because bike theft is so rare that most people don't worry about it, or only take minimal precautions.
Meanwhile, in my tiny town in the States bike theft was basically the single most common form of crime, and I know of one house I would walk by every week that would openly have as many as half-a-dozen stolen bikes displayed for sale in their front yard.
About 4000 bikes were stolen in Helsinki ([0], pop. 600k) in 2014. This is about the same number as in the city I live in (Germany, around the same population), where I'd never leave a bike unlocked, and where bike theft is considered a problem. Though I am sure there are places where it's much worse, and conversely that it's much better in other cities in Finland.
In Japan street crime is very low but both bicycles and umbrellas are 'borrowed' on a routine basis. Kind of like an informal bike sharing system. Consequently most bicycles are of the $80 made in China variety.
Here in Canberra Australia I would regularly come back to my bike to find new marks in the plastic around my chain where somebody had tried to cut through. Your chain has to go through both wheels if you have quick release on the front, and you can't leave any clip on lights or your water bottle or it will be gone.
A few years ago I watched a junky go from bike to bike in a bike rack testing each lock to see if it would open easily. Right in plain view of everybody. When I confronted him he launched into some long and carefully rehearsed sob story about how his friend told him to come and get his bike but didn't know which one it was.
I actually accidentally left my bike beside a busy street last night here in Seoul unlocked. I went back and got it today (Sunday night) and not a single person had touched it.
I don't think that it's population density as much as the shared culture of the place you live. I would have totally blamed myself if my bike wasn't there today, and I think it would be stupid to blame anyone else.
Density, shared culture, and perhaps a functioning social services. Thus there is less of a incentive for petty crime, as basic needs are covered via less risky means.
I wouldn't leave my bike unlocked in Helsinki. Just last year my bike was stolen near the Parliament house (Kiasma) even though it was locked to the stand.
Just because locks have existed for thousands of years doesn't mean they are used everywhere. When I lived on the countryside in Australia we didn't lock the doors. That's not "an extremely long time ago" ;)
Most often people had nothing to steal and often couldn't afford good locks anyway. When the last of my grandparents 13 kids left the house and they actually started to have enough money to buy nice stuff, they also bought and used a lock.
While I agree with the sentiment for physical objects it doesn't apply to things connected to the Internet. An old "smart" TV may have no resale value whatsoever but that doesn't mean it has no value from an attacker's perspective.
From the attacker's perspective something like a connected smart TV has extremely high value as a mechanism for further penetrating a network. Black boxes that no one can login to under normal circumstances are the perfect secret strongholds to maintain a persistent presence on any given network.
These days still exist. And nearby some people even leave their keys on the cars. However, in a city, you just can't do it. Too many risks and people barely know each other.
Now comes the Internet. It's a huge giga-city. Expect robbery, larceny, hacking, and more.
That not locking the door stuff was simply because back then people didn't fetish objects, and also because they were too poor to have anything worth stealing. Rich people always made sure their stuff was protected (from the poor).
But do we blame Google when their robot indexes some completely unprotected webpage that the host owner didn't mean to be public but haven't did anything to claim so?
> I think we need some sort of awareness day for the general public to understand what internet security _really_ is.
Nope. This would never work. People don't understand how much of it works. Taking a day out of the year to explain / re-explain isn't going to do a single thing. Instead you need to make computer classes mandatory in K-12 and get people educated on how they work so they can understand the issues.
Take a topic you know absolutely nothing about. Let's say it's aerospace. Now every year we have an aerospace day to try and explain to you how various types of fan and jet engines work. You certainly wouldn't expect everyone to be able to handle fixing one after that one day, do you? Same with internet security.
> owner left the front door unlocked, people would rightfully put the onus mostly on the store owner.
So just because the store owner does something stupid you think most people would consider it his fault? That's...that's horrible. Yeah he possibly could have prevented it (though you don't actually know that as they could have broken in anyway; people don't just go up to stores at night to randomly test doors then go home).
I taught high-school computer science. I taught about how the internet works, password security, encryption as well as programming.
I once had a lad declare that GitHub was stupid, because it locked out our IP for 5 minutes after the class tried to login to their accounts with at least half of them forgetting the strong passwords I insisted they use.
I watched a girl log into her vps by running her finger across the top row of her keyboard. When I insisted she change her password, she ran her finger across the keyboard in the opposite direction.
Many people know and understand basic security, they just don't care. They think they have nothing of worth losing, and so don't need to be secure. Even after I explained to the student that their vps could be used to mine bitcoin, fetch pornographic material or send out phishing emails, their attitude was very much - meh!
I'm all for educating people on these issues, but the true way to protect them from their own stupidity is to ensure that it is impossible for them to start up a vnc server without enforcing a strong password. Security by design will be even more important as iot becomes more prevalent.
tl;dr - You can't rely on users to protect themselves.
> I'm all for educating people on these issues, but the true way to protect them from their own stupidity is to ensure that it is impossible for them to start up a vnc server without enforcing a strong password.
What is a 'strong password'? Minimum 12 characters, 2 symbols, 2 caps, 2 lower case? "1!qQaAzX2@wWsSxX" fits (and exceeds) those requirements.
Trying to enforce strong passwords doesn't work; people just make up new insecure passwords.
> Take a topic you know absolutely nothing about. Let's say it's aerospace. Now every year we have an aerospace day to try and explain to you how various types of fan and jet engines work. You certainly wouldn't expect everyone to be able to handle fixing one after that one day, do you? Same with internet security.
People don't interact with jet engines, but they do interact with planes. And they're lectured about airplane safty evey single time they get in a plane. So this might actually be an argument in favor of educating people about internet security.
Bottom line: please don't overuse analogies. They don't prove anything.
People also don't interact with security on their computer pretty much ever but they do interact with their computer / the internet. Seems like a perfect analogy to me.
> Now every year we have an aerospace day to try and explain to you how various types of fan and jet engines work. You certainly wouldn't expect everyone to be able to handle fixing one after that one day, do you? Same with internet security.
Actually, I'd expect a lot of increase in awareness of what the relevant issues are. No, I wouldn't expect someone exposed to aerospace day to be able to fix a jet engine. But they're much more likely to know what problems commonly occur and who can fix them.
School District policies and (ultimately) curriculum are driven by public opinion. How can a public demand better if they are not able to understand the issue?
It's a nice thought, but I suspect it to work as well as "safe electrical circuits" day would. The internet security equivalent is that companies are selling completely unsafe circuitry with live wires exposed, and we should mount an education campaign to teach people how to cover up the live wires. I suspect once the hardware/software industry matures, we'll see insurance companies become involved and there will be strict regulation around what is and is not safe.
The latest episode of ATP[0] had a section at the end about people roaming in the neighborhood checking car doors to see if any cars was unlocked and steal stuff when hiting the jackpot.
The owner of the car can blame himself for forgeting to lock the car, the insurance won't blame anyone but won't pay for reparation, the justice system puts the blame on the thief but would not do much about it if it's petty.
And of course if it was a bank leaving bags of notes on an unlocked cabinet in the entrance, people would go bat-shit about irresponsible behavior on the banks side.
I feel that's how it would go for the online world as well.
Pretty sure theft is still theft, even if the door was unlocked. Of course negligence can make it your fault, but even if you find a million dollars on the street - legally - it's not yours.
Sure, but when Target, LinkedIn, et. al. are hacked, why don't people blame them for poor security practices? It's always the "hacker's" fault. Sure, it's wrong to exploit those weaknesses, but so is robbing an unlocked store. The hacker (robber) is still wrong, but only in the physical world do people put some blame on the "hackee" (store).
When I get robbed: the robber hurt me, and I failed to protect myself. Failing to protect myself is not a social problem.
When my bank gets robbed: the robber hurt me and the bank, and the bank failed to protect me. The robber is at fault, and the bank is at fault for breaking it's promise to me. That's a social problem.
Sure, but when Target, LinkedIn, et. al. are hacked, why don't people blame them for poor security practices?
Security is hard. Blaming the victim of a hack is pointless because usually you have no idea whether they did something wrong or if they were the target of a particularly clever attacker.
Maybe when the victim isnt a billionaire organization that is true.
In the case of these large corps being hacked, they are 100% responsible, and most of them we do know how they got hacked; its usually through very humdrum (if organized) means.
Sure, but when you find plain text passwords or unencrypted credit card info (two of the basics of starting ANY business), victim blaming seems warranted.
There can be a door, but there is arguably no burglary or theft.
1. You drive to a random address(es), accessible from the public premises (IP).
2. You knock on the door (TCP SYN).
3. Someone comes and opens it for you (TCP SYN+ACK).
4. You ask what's here (VNC handshake).
5. You're told it's a power plant or doctor's office or whatever (VNC frame data).
6. Sometimes the replies aren't fun, sometimes it's really weird - some pal seems to be willing to control a nuclear reactor for you, no questions asked.
7. You blog about your experience, including a conversation transcript.
It could be wrong to publicly announce (step 7) that there's a weird person in there (with full address details) that can do anything for you, as this can put others in danger. It's ethically unclear: it requires a human review and judgment (a robot can't tell if it's weird, so if data collection is fully automatic and unsupervised it becomes complicated), and even for humans it's probably not completely wrong to disclose, if done responsibly.
But just driving by and knocking on the random doors asking what's there - it would be really weird to me if we'd say this is anything wrong with this.
"Blame" is a complicated concept entangled with morality that a lot of people have conflicting and illogical opinions about.
I think that unless you want to start conversation about what "blame" is, it's safer to use words describing strict logical causation instead. Unlike "blame", causation is objective and doesn't depend on morality.
Stuff should be secure by default. No default passwords. No open by default. Temporary dialing down of security should reset itself to secure mode by itself after a short time. Etc.
Reasonable people don't have their doors locked all the time. Maybe they should, but mistakes and oversights happen
Edit: After some additional research, people on message boards pointed out that many home invasions are done with lock-pick kits, or the burglar breaks a window and unlocks the door. Homes are often broken into without any damage to the lock or door, so the insurance company would never even know if you locked the door or not. It just doesn't come up in the investigation.
EDIT: Wow. I'm being modded into the basement. When did Hacker News become so PC? Victim-blaming? Seriously? The VNC connections illustrated on this site are that way because of incompetence and ignorance. The reason there are no unlocked brick-and-mortar businesses is because it is due diligence to protect one's assets from not just criminals, but simple mischief.