I know I have been going on and on about Moxie’s talk, but that is just one example of the larger issue that Dan Kaminsky pointed out a year ago. Directionally thinking, using moxie’s example, apply the thought process to email, or ftp or sshd or any service… As Dan says, “In the face of a bug, of this severity, they realized this is going to really affect our customers.” (Corporate vendors) Take a look…
Remember, this was last year and sure DNS implementation vendors’ have responded well, but how long does it take for patches to get out?. Moxie is just detailing one aspect of it of one exploit ecosystem. There really are several patches out there, but the request for comments flaw is still the standard. (as an example) The patches will keep coming until corporate America feels their servers are locked down, but then the researchers will simply change the target to the person sitting in the chair or the client they are using and clearly they already are. If you had an illusion of cyber security, I would encourage you to rethink your position and invest in things like gold that aren’t subject to the system. Numbers on a page are one thing, but gold is a whole different discussion.
No Comments