HN user

bortels

3 karma
Posts0
Comments2
View on HN
No posts found.

Awesome Stamos talk (as per usual), but the headline here is a tad clickbaity. Perhaps more accurate to the talk is that they will matter less and less as time goes by. If you don't like that headline - do go watch the talk, there's a lot more subtlety than 8 words convey, and Alex is a fun speaker, with one of the highest signal-to-noise ratios around.

Heck - if you agree with the headline, still go watch the talk. If you care the slightest bit about security, you won't be sorry.

Firewalls are not a 100% solution, nor have they ever been. Defense done correctly is always defense in depth, and hardware firewalls are always likely to be part of that solution.

Alex's point in the video - and one well-made, I think - is that as the landscape evolves, the value-add of hardware firewalls becomes less and less, because assumptions about the environment they are in are changing. Anyone depending only on firewalls (I have called this the "hard candy shell" in the past) was vulnerable before - and as time passes, they are becoming increasingly vulnerable, because the things a firewall can be useful about are becoming less relevant, due to architectural changes and exploits moving up the stack toward the app.

I've said for a long, long time - I don't care how good your perimeter defenses are, you gotta harden the hosts. And in the end, this also is moving up the stacks. Your hypervisor may be secure as all-get-out, but if your app is open to trivial exploits, you're still screwed. You need to do a reasonable amount of security at all levels, including bits like user evangelism (disallowing of insecure passwords, perhaps promotion of MFA) if you want to have an expectation of security founded in reality.

The human element - users and passwords - cannot be underestimated, because a chain is only going to be as strong as it's weakest link, and if you do all of YOUR shit right - that's gonna be the end-user. Someone who can figure out how to replace passwords with a mechanism that ties access and authentication to a single human being in a non-trivially spoofable and inexpensive manner could become very rich...

It simply means you cannot rely on DNS (and domain names and such) for your security; your security must be achieved via other means (user auth or such). DNSSEC does not help that much, in reality, despite the implication it might, and that's part of why SSL and Signed Certs exist - it's a given that when I connect to www.microsoft.com from starbucks wifi, the IP DNS returns may or may not be microsoft's. With DNSSEC - presumably you may have a higher level of assurance the IP is from Microsoft, but it is not really practical to implement everywhere due to complexity, so you cannot depend on it to solve for this sort of issue.