@renatevdzee Your country is the Colombia of Europe not because of pot smoking but because of violent crime that the drug traffickers are imposing on your government, politicians, judges and the population. How about some solutions to that ? Just asking…
@renatevdzee I just read your surprising article about prisons in the Guardian and my reaction is « well done NL ! » Now, how about you put some energy on a paper about drug related high level crime in NL ?
This nationwide outage is more important than you think. It exposes a critical weakness of emergency services, government, and other critical infrastructure....It all goes offline with the compromise of one application (doesn't have to be Crowdstrike).
We've seen this before. This isn't a solution writeup, more of an explainer of the bigger problem. It's kind-of one of the reasons I left Cybersecurity and Cyber Intelligence roles after 12 years. My CISSP is about to show.
Crowdstrike rolling out an update that crashes as much as it did is a function of Crowdstrike's proliferation as one of the best endpoint protection suites that is out there. Although this isn't necessarily a compromise externally (i.e. a 'hackerrrr'), the effects of a compromise at the application level are the same. Should someone desire (a-la Solarwinds) to attack such a broad range of services and organizations, they can target security platforms like Crowdstrike on the vendor side that can control whether or not those services can communicate with one-another, effectively shutting them down. Security teams now need to scramble to fix it, in a game of cat and mouse.
It's ultimately supply-chain risk, and with lots and lots of organizations shifting to vendor-hosted cloud services for instance management, rather than deploying solutions on-premise and doing their own patch management (under the guise of reduced cost), you're centralizing access to these critical tools that have necessary administrative-level access to make changes to every endpoint they're installed on. So WHEN (not if) one of these vendors of critical security tools gets compromised and their cloud exposed, an attacker makes a change that can/will shut everything down running that service/tool.
I'll give you a scenario. Crowdstrike is common. We've established that based on the impact of this outage. Imagine you're a Russian or Chinese cyber operator and you want to 'shut down' the US. Or you're a US Cyber Operator and want to 'shut down' another. Instead of targeting multiple Government agencies and critical services, each with a depth-oriented defensive posture unique to that agency or organization, you'd target the private companies providing security and infrastructure management tools and services to multiple services and organizations. Accessing those centralized companies that are providing services to each of these other critical organizations bypasses (to an extent) the necessity to plan for each defensive posture of each of their security plans. So as the cyber operator you've potentially removed the ability for emergency services to provide medical support, or for administrative military functions running on an IP-based backbone (served by the systems that are now offline).
There are absolutely things that are being done by some very, very smart people to counter this. Engineers and analysts are innovating and developing solutions to minimize this risk. Network and service segmentation, air-gapped critical systems, etc. They're countered, though, by the continued interconnection of everything. The security triad (Confidentiality, Integrity, Availability) tells us that weighting too much in any one direction is disastrous. Think of it like a gun safe. Yes, you can lock up all your guns in a safe, but ultimately when you need them your access (availability) is diminished. We want ease of use and access as a society, prioritizing availability over confidentiality and integrity of data. With that availability comes the exposure of those systems to compromise, whether intentional or not. This is a tactful way of saying we're all absolutely SOFT and NEED our app for ___ to connect to ___ so that it has all the stuff we need in it to ___.
I left Cyber full-time (very lucrative, you should get into it) because I just want to bury my head and shoot my guns/train for whatever's coming. Every security team is ten steps behind the opportunities that someone has to shut 'everyone' down. It's just unavoidable and you should prepare yourself for when that happens.
There's the reason for this post. More of the things that keep 'society' moving as we know it are reliant on things that can go away in an instant. I've spent the last handful of years in a mild panic over stuff like this, working to become more resilient as a family to it.
On devrait passer ça dans un cours de sciences politiques pour définir le Front national et son électorat d’hier et d’aujourd’hui.
Très juste Bernard Tapie
Écoutez qui sont-ils. Et si vous votez facho écoutez qui êtes vous. Vous allez probablement vous reconnaître en étant quelque peu honnête avec vous même !
♦️Il est probablement celui qui a fait le plus avancer la France depuis Valérie Giscard d’Estaing, il est aussi celui qui a fait le plus bouger l’UE depuis la Présidence de Nicolas Sarkozy
Il est également celui qui nous a le plus bousculés dans nos petites habitudes bien confortables pour nous propulser directement vers le 21eme siècle
Il a relancé l’industrialisation du pays
Il a fait baisser le chômage de masse
Il a augmenté drastiquement le nombre de policier et apporté des moyens considérable à la police
Il a réarmé nos armées, il est, de ce point de vue, le plus Gaulliste des Présidents depuis Pompidou
Il a lancé le plan Ségur pour les hôpitaux et relevé les rémunérations des personnels hospitaliers
Il a dédoublé les classes scolaires dans les zones difficiles
Il a augmenté de manière importante la rémunération des enseignants
Il a répondu aux revendications des gilets jaunes avec 17 milliards d’investissement pour aider les plus démunis
Il a relancé l’investissement dans le nucléaire comme jamais aucun Président ne l’avait fait depuis Giscard d’Estaing
Il a engagé la France dans une baisse drastique des gaz à effet de serre
Il a eu le courage de remettre la France au travail et allongé l’âge de la retraite
Il a assuré un minimum de pension et de retraite pour les plus démunis
Il y a 7 ans, nous avons fait le choix d’un Président jeune, dynamique, européen, libéral, social, courageux, il est à la fois Valérie Giscard d’Estaing et Jacques Delors, il est le Mendes France du 21eme siècle, il représente une chance inimaginable pour l’avenir de notre pays
Mais les Français préfèrent visiblement la vieille garde rancie de la politique, l’outrance antisémite de l’extrême-droite comme de l’extrême-gauche, préférant une dictature collectiviste à la Chavez ou au ringardisme rétrograde à la Orban
La France mérite mieux, et tous les Républicains devraient s’unir au lieu de jouer l’attente de 2027
Le non renouvellement du mandat du Président de la République met à mal la démocratie
Je soutiens sans réserve le Président de la République @EmmanuelMacron
@WalterJanD@WalterJanD I read your DW paper about Frontex and I think you are a real disgrace. Your view on the matter discards the nuisance to the lives of millions of people impacted by noncontrolled immigration. After that you’re surprised that the extremist right wing scores high ?
60 years ago, Walter Cronkite of @CBSNews interviewed Gen. Dwight D. Eisenhower, the Supreme Allied Commander for Operation Overlord: “These people gave us a chance and they bought time for us so that we can do better than we have before.” #DDay80
@brahilly@achrisafis @anissa_yamna The Guardian correspondents in France are hardcore leftists with a deeply biased view of the french society. They most certainly live in a french leftist bubble too !
@karenmcveigh1 you avoid to eat some species but you certainly don’t “replace” tuna with sardines. #newStupid
Five to ditch and five to try: what fish should we be eating in 2024? https://t.co/TfPInXPcDb