HN user

altharaz

209 karma

French InfoSec Engineer

https://www.cyberwatch.fr - Vulnerability Monitoring Software

Posts8
Comments64
View on HN

Very great article.

At the moment IMHO the major issue comes from that people use only the Basic Score of the CVSS 3.1, issued by the NVD.

Indeed, if you also take the Temporal Score (with CTI feeds for example), and if you add the Environmental Score, then you can have very good results to help prioritizing the vulnerabilities on your assets and reflect the real threat.

I would also like, however, to see the CVSS4 with a "cost to patch" component: in OT environments, CISO like to use the SSVC because it’s the easiest way to say "wait" instead of "patch now". But since SSVC is not really recognized by all auditors, it generates conflicts. Bringing a component in the CVSS to reflect the cost of remediation on very complex devices, where deploying a KB requires to stop a full factory, could help getting the same results (aka "don’t patch now and wait") but with a more respected scoring system.

From my perspective, that’s the only missing component for a good CVSS system :).

https://sievedata.com seems very promising, a search engine for videos, with specific tags, sounds like a very good idea.

I'd like the same for all my photos and videos: that would be so much easier to find specific pictures by keywords

TL;DR:

Some Windows configuration have bad permissions on their SAM database. If a standard user has access to shadow copies (VSS), this can lead to privilege escalation.

Microsoft recommends to [1]:

1) Restrict access to the contents of %windir%\system32\config: - Command Prompt (Run as administrator): icacls %windir%\system32\config*.* /inheritance:e - Windows PowerShell (Run as administrator): icacls $env:windir\system32\config*.* /inheritance:e

2) Delete Volume Shadow Copy Service (VSS) shadow copies: - Delete any System Restore points and Shadow volumes that existed prior to restricting access to %windir%\system32\config. - Create a new System Restore point (if desired).

--

Also, please note that some authorities seem to adress this subject carefully. The French national cybersecurity agency (ANSSI) has for instance published a News bulletin [2] but no "real" Security bulletin of this vulnerability [3].

In its News bulletin, the ANSSI specifies that it also affects Windows Vista RTM :).

However, the ANSSI also says that deleting VSS entries (step 2 of Microsoft recommendations) "must be decided after evaluating the advantages and disadvantages with regard to the risks, in particular because there may be other possibilities for privilege escalation depending on the level of security of your information system."

[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...

[2] https://www.cert.ssi.gouv.fr/actualite/CERTFR-2021-ACT-031/

[3] https://www.cert.ssi.gouv.fr/alerte/

Unity has also a lot of potential in the Cybersecurity industry, for people that wants to train themselves on Industrial Systems.

The only thing that makes industrial Cybersecurity really hard for students is the industrial systems laboratory requirements.

With Unity, some people are trying to build completely virtual pentest labs on industrial systems, such as GRFICS (https://github.com/Fortiphyd/GRFICSv2).

Great app, I just bought it and I will try it on the next WebEx conference calls :).

Some remarks:

- the "Highlight cursor at app launch" has a "Start sdf sdfsdf" tooltip

- I can not change the keyboard shortcuts (when I click on the button to configure them, nothing happens)

- the default keyboard shortcut "Control + Option + A" presented in the menu does not work on French keyboards and requires instead to push "Control + Option + Q", which looks like a AZERTY / QWERTY configuration issue?

Meditations, Marcus Aurelius => A lot of wisdom on how to lead and live

On The Shortness of Life, Seneca => An essay about how to handle life and how to see what is really important

On War, Clausewitz => An important essay about strategy and war, politics and management

The Prince, Machiavelli => A little bit cynical but quite realistic about the nature of power in the hands of humans

Thirty-Six Stratagems, multiple authors => A list of strategies that can be used in any situation, whether when winning or losing

From my experience, the password manager is just another issue to solve for this kind of people: it’s another software to use and these users do not like to use software.

As a result, paper is sort of natural for them, and the only way I found to impeach them from writing down their passwords is to make them use passphrases instead of passwords.

They do remember the passphrases they typed in, however the issue is that some websites still refuse passphrases because they are too long :(.

My recipe is AdBlocks + automated updates enabled + firewall enabled + desktop shortcut for web browser + regular antimalware check.

Regarding phishing, I set them up with a GMail account and their filter is quite good against this.

So far, not anything bad happened, some minor malware were installed through malicious web browser extensions, but no financial damage or identity theft.

In France, this kind of work is proposed by a lot of real estate agencies. Real estate agencies can even collect the rent for you and “guarantee” you the amount you will get each month. This point is very important as it is a nightmare to evict a bad tenant.

Do you have the same issues in the US? If so, do you plan to manage the rent payment as well?

From my experience, it seems that the daily digest is not enough :). And they still seem to blacklist WebEx invitations, which is really weird as it is definitely a "standard" in web-conferences.

I haven't used WebEx, but what is the problem exactly? Are you concerned you won't see the invite or that the sender will get an annoying automatic response?

Basically, WebEx sends invites from their own email address. If your customer has not white-listed the WebEx domain, they will not receive the WebEx invitation. The only solution we found for our sales team is to "double" the invitation with a manual email sent separately, with the link to the WebEx invitation...

Also, I just realized that I was not very clear in my comment: my company does NOT use MailInBlack :). However, a lot of our customers do, and this has been a nightmare for our WebEx invitations process.

In France we have a software vendor called MailInBlack.

Their solution is exactly the one proposed in this article, where the sender has to solve a “challenge” to get in your mailbox.

If I think this approach is really effective, it also creates a huge pain for a lot of tools relying on emails such as WebEx invites or when you want to contact someone for sales.

As a result I think that this approach might be better if it was for instance triggered only on emails with an “Unsubscribe” link, or on emails with specific keywords.

I didn’t know about Hummingbird. This is really cool.

I think I prefer Hummingbird’s approach to OP’s because it makes deciphering the notes way easier with its symbol mnemonic, and I think deciphering the notes is the hardest part.

Actually we have two common cases which make it harder to work with contractor.

1. If your contractor has just you as a client for a long time, if you stop the mission he can sue you for « economical dependance »

2. The real estate market does not let you rent without a solid employee contract, making it very hard to independent contractors to find a house.

The important market is not in contractors but rather in « contractors supporters », basically buying contractors time and selling it to big corporations.

These « middlemen » take the juridical risk, which make the big corporations accepting the contractors, and help the contractors finding missions.

These middlemen also take fees on missions.

The "glass ceiling" statement is true in big corporations (you'll never get to the top if you have not graduated from the top Engineering Schools, even if you have the skills).

However, in Small & Medium Businesses, the startup movement has changed that a bit and the diploma is way less important than before.

In terms of mindset, it seems that it is an important part of our culture: Philippe d'Iribarne calls it "The logic of Honor" [1].

To sum up the differences between French and US management (at least, according to Iribarne)[2]:

- French relies on the concept of honor and duty. French employees consider that their honor and rank is way more important than their contract. You must manage with this in mind, and accept to be flexible in order to show consideration. You must also explain what are the limits so that employees will not go over them. Managers must give free space to their employees, being "invisible" when everything works out, respecting their honor, but must also go on the field when it goes wrong in order to show "how it's supposed to be done" and to inspire respect by example.

- US relies on honesty, and on the transparency of a work contract. Managers must control the work on their contractors on a periodic base in order to show interest and respect, as part of the contractual relationship.

=> In France, according to this study, the "Us vs Them" should be accepted by management as long as the companies goes well.

[1] https://www.ecole.org/fr/662/VA021205-ENG.pdf

[2] http://lirsa.cnam.fr/medias/fichier/diribarne2html__12633047...

To those who talk about the administrative & HR issues in France: these are definitely true.

However, the government is running two programs that will try to improve these elements[1][2].

For instance:

- the French Public Investment Bank (BPI) will receive more money in order to create a better leverage for fund raising, co-investing with private funds in startups;

- France will work with European Union to create the european equivalent of the DARPA challenges;

- France Expérimentation will provide exemptions to some startups trying new business models;

- new APIs will be provided to help accomplishing administrative tasks automatically;

- public contracts will have lower entry barriers;

- public aids (which are really important in France) will be simplified;

- the HR thresholds will be reviewed in order to promote startup growth;

- a study will be conducted on "renting contracts" for startups (most contracts have a 3/6/9-years engagement clause, which is not adapted to startup growth);

- corporate tax will be lowered;

- ...

This is not perfect and we are indeed accustomed to a lot of rules and administrative work, but still: it is good and motivating to see that the government is trying to do something.

Moreover, we have great landscapes and food, so let's give France a try :).

[1] https://www.numerique.gouv.fr/actions-startups/elements-de-p... (in French)

[2] https://www.pacte-entreprises.gouv.fr/

[edit] styling

I started a first company with some friend. I was in charge of the IT, he was in charge on Sales. However, things were catastrophic as I was selling more than him. A huge conflict occurred and I closed the company. => I lost some money in the process, but I learnt a lot.

Then, a friend from Engineering school just graduated. We had previously worked together on side-projects, and we had a common passion for cybersecurity. We decided to launch our company.

After three years of hard work, we are now profitable and really happy about this choice :).

I use Quiver every day. I really like the way I can organize my notes and projects. However the main issue I have with this software is the absence of synchronisation between devices: I can’t browse on my iPhone what I wrote on my Mac.

I met Max just before his YC interview. The fun fact there was that we both have the same firstname, came from the same region (Europe), and work on the same product family (Vulnerability Management).

AppCanary went to YC, and Cyberwatch went back to France.

However, for us that was for the best! Most of our customers indeed really liked the fact that we are a 100% French company.

We are now profitable and provide a complete Server Vulnerability Management + Patch Management solution.

Different paths to glory, but the world is small and I'm sure we'll meet again someday :)

=> I wish you the best at GitHub!

"Is there any link between data science and cyber security?"

Data Science might be useful if you want to work in Security Information Management or in malware analysis: big companies try to identify "weird behavior" in their networks, based on "normal behavior" records.

"Where can I learn cyber security stuff?"

Well, that depends on the stuff you are interested in...

You should focus at first on learning "system administration" and at least a programming language like Python or Ruby. Network protocols would also be a bonus.

Then, if you want to learn "offensive techniques" or "penetration testing", I suggest that you try websites like RootMe https://www.root-me.org/?lang=en or Cryptopals cryptopals.com.

Once you'll have resolved by yourself some of these challenges, you'll be able to try the "industrialized approach" of penetration testing. For this, this book is quite cool: https://www.nostarch.com/pentesting.

If you're more interested in "defensive techniques", you have tons of resources online.

For instance:

Secure Coding Best Practices: - https://www.owasp.org/index.php/OWASP_Secure_Coding_Practice... - https://security.berkeley.edu/secure-coding-practice-guideli...

=> These documents will help you to understand what are the main risks in your apps

For "general" cybersecurity: - ISO27001 standard - The NIST Cybersecurity Framework https://www.nist.gov/cybersecurity-framework - PCI/DSS - https://www.us-cert.gov/

=> These documents will help you to understand what are the main risks in an organization based on their assets.