Damus
Final profile picture
Final
@Final
Contrary to popculture and internet trend narratives, the majority of cyber attacks are not sophisticated. Behind some of the worst cyber attacks are what an industry worker would refer to as a common security deficiency.

These are flaws that are very common and are regularly discussed. These things could be:

- Delayed or no security patching
- Missing second factor authentication
- A misconfiguration or using a insecure configuration, whether it be crypto, application settings, etc.
- Insufficient or lack of access control
- Lack of due diligence or awareness from the victim
- Insufficient logging or monitoring
- Lack of transit or at-rest encryption

Equifax, one of the worst data breaches in modern times, was thanks to them not performing security patching on Apache Struts which allowed a threat actor to exploit a known vulnerability. GTA 6 was leaked from a staff member being socially engineered. Snowden perhaps could not have done his whistleblowing if the NSA has stricter access control.

The best threat actors use the easiest way in to get what they want. The big letter agencies do not jump through hoops and set up big conspiracies rather they exploit software the same way a professional researcher would try to. This also makes an operation far less attributable, because a common security deficiency could be exploited by anybody.

When you regularly see coverage about North Korea ('Lazarus') compromising cryptocurrency companies or users, they are often exploiting these same easily explained weaknesses. If something is too secure, many will easily decide to find a victim that is easier to compromise. What makes them so dangerous isn't their technical capabilities rather than they have far more time and resources because they are state sponsored. They will *never* be held accountable.

When you cover all of these deficiencies and more, your tech is probably more secure than 99.9% of people. Now you go from being a victim of a common attack, to something that would need to be bespoke and targeted.

When working on security or privacy focused software, think long and hard about the quality of the implementation of your functions. You could have many features, but they may not be helpful if their implementation is poor. A poor implementation of a feature may introduce weaknesses compared to not having the feature introduced at all. Less can truly be more.
17❤️12❤️21💯1
John ₿ Wick · 6d
https://primal.net/e/nevent1qqsw5su0652w2lah9newftqvhscmtem7y3jkh78afqrc7ruf2f6xergc28rcc