Jump to content

Recommended Posts

Posted
I agree that knowing your brands is not a security risk, but declaring specific models of copiers, firewalls and CCTV cameras IS however, I would argue a security risk. Especially in an education setting where upgrading these security risks isn't always seen by senior leaders as a priority.

 

Knowing that would be in the public interest would it not? Knowing that our schools aren't keeping their critical systems up to date? As I say, there is no specific exemption, in law, for perceived security risks.

Again, talk to your legal teams and DPO on this, but if there are specific reasons you believe that disclosure could prejudice the effective conduct of public affairs, then you do have mechanisms to reject it. It's up to your legal teams and DPO to help make that decision as to whether make and models could prejudice your day-to-day operations long term though.

I've just been through this with a request for info about our internet, firewall, filtering and safeguarding monitoring... No exemptions applied, as the public interest test outweighs them.

  • Thanks 1
Posted
security by obscurity should be by design part of your process....

 

Sorry but no. Security through obscurity is just not a thing that should be used. It should not be a layer, it shouldn't be even thought of as a part of a design. Attacker walks past your school, looks at camera, can tell what it is. Layer is gone. Looks through a window or pops in or gets a tour, sees a copier, layer gone. If by knowing what you have compromises your security plan, then you have lost already. It's not as if it isn't too hard to find out and if you are relying on that at all, even slightly, then you are lost.

 

You can do much more by segregating your network, keeping things updated and following standard security guidelines then by trying to hide what equipment you have, especially equipment that is out on show.

  • Thanks 2
Posted
Knowing that would be in the public interest would it not? Knowing that our schools aren't keeping their critical systems up to date? As I say, there is no specific exemption, in law, for perceived security risks.

Well perhaps it would be, but is that really the mechanism you want to do that with?

I've just been through this with a request for info about our internet, firewall, filtering and safeguarding monitoring... No exemptions applied, as the public interest test outweighs them.

 

I do not see where the public interest is in whether you're running a Fortigate FG/FWF-40F or FG/FWF-60F, personally.

Fortigate or Sophos XG, yes.

Posted
Well perhaps it would be, but is that really the mechanism you want to do that with?

 

That's the point of the FOIA... It isn't our choice. Its the public's choice - it is their info, after all...

I do not see where the public interest is in whether you're running a Fortigate FG/FWF-40F or FG/FWF-60F, personally.

Fortigate or Sophos XG, yes.

 

The law disagrees with you generally here. The default position should be to give the information requested unless it fits with one of the exemptions, and even if it does fit an exemption you have to do the public interest test.

Posted (edited)
The law disagrees with you generally here. The default position should be to give the information requested unless it fits with one of the exemptions, and even if it does fit an exemption you have to do the public interest test.

 

Yes. I agree regarding public interest, but I would argue until Section 31 (Disclosure would be likely to prejudice the prevention of crime) and Section 36 (Disclosure would prejudice the effective conduct of public affairs) of the Act that detailed disclosure of models of equipment used could and should apply here as it could easily be used to launch attacks against your institution, just as it would if you were asked by FOI to disclose every single email address on your system.

 

And these are the decisions people have to take in different organisations. Different DPOs and lawyers would argue differently for different organisations. I'm not saying I'm right and you're wrong. I'm saying I disagree that the detail is required and that the law requires you to disclose it and that it should be discussed throughly with your DPO and legal representation before you disclose anything. Ironically, just because you would disclose it, doesn't mean that all organisations would disclose it, and saying your organisation did so, so mine must is not and hasn't ever been considered a valid argument either.

 

The company whose devices you use: Yeah, sure

The number of devices : Yeah, fine.

How much the cost of the contract is : OK. Fine.

The individual make and model of each device : No need and no public benefit.

Edited by paulkerton
Posted (edited)
Sorry but no. Security through obscurity is just not a thing that should be used. It should not be a layer, it shouldn't be even thought of as a part of a design. Attacker walks past your school, looks at camera, can tell what it is. Layer is gone. Looks through a window or pops in or gets a tour, sees a copier, layer gone. If by knowing what you have compromises your security plan, then you have lost already. It's not as if it isn't too hard to find out and if you are relying on that at all, even slightly, then you are lost.

 

Absolutely fundamentally disagree with you on the most basic of levels I'm afraid.

It should not be the only layer, a dependent layer, nor should it be a main layer - but it should absolutely be a layer.

A good system uses security by design, open security and security by obscurity in tandem. Witholding knowledge of what makes up your systems behind the scenes is different to camoflague.

 

For those of you that don't think obscurity should be a part of it, if I put a freedom of information request in and I ask for "every email address and for each one, whether they are using two factor authentication for their cloud email account" how are you going to respond?

Edited by paulkerton
Posted
For those of you that don't think obscurity should be a part of it, if I put a freedom of information request in and I ask for "every email address and for each one, whether they are using two factor authentication for their cloud email account" how are you going to respond?

That one has already been covered by the ICO. https://ico.org.uk/media/action-weve-taken/2619472/fs50344341.pdf

 

However, in that case, knowing everyone's email addresses is indeed a security risk. There's good reasoning in the ICO's response too.

Posted
That one has already been covered by the ICO. https://ico.org.uk/media/action-weve-taken/2619472/fs50344341.pdf

 

However, in that case, knowing everyone's email addresses is indeed a security risk. There's good reasoning in the ICO's response too.

 

And I would argue, reasonably, that making each and every make and model of every piece of hardware you have freely shared in the public sphere is also indeed a security risk.

Posted
Absolutely fundamentally disagree with you on the most basic of levels I'm afraid.

It should not be the only layer, a dependent layer, nor should it be a main layer - but it should absolutely be a layer.

A good system uses security by design, open security and security by obscurity in tandem. Witholding knowledge of what makes up your systems behind the scenes is different to camoflague.

 

For those of you that don't think obscurity should be a part of it, if I put a freedom of information request in and I ask for "every email address and for each one, whether they are using two factor authentication for their cloud email account" how are you going to respond?

 

I agree with the fundamentally disagreement. If obscurity is any part of your security plan you are relying on smoke and mirrors. If it you are not making it a dependent layer, what is the point?

Feel free to put an FOI in and find out. But a list of emails and how they are configured is very different to what kit you have. And to be honest it isn't like working out that information isn't that hard. So relying on people not knowing your email is, again, security through obscurity and completely pointless.

 

Pretending people can't find out easy information is not security by design. In fact, I would go as far as to say security by design and STO are opposite ends of the spectrum so incompatible. The former, you make things secure so anything that can happen will be anticipated by design, the later you cross your fingers and hope.

 

You are also pulling away from talking about types of copiers and CCTV cameras, when there is no obscurity around them. Unless you are using shape camouflage, like car manufacturers do, or putting sheets over them, then they are easily spotted and easily identifiable.

 

Yes it is sensible not to stand out on the road yelling out the network specs, IP ranges, and what patches you are missing. I will give you that. But hoping no one can find that information out is naïve at best. And if you are going to base your security design on people being able to find out that information anyway, then what is the point in even considering that information hidden anyway?

  • Thanks 1
Posted
Yes it is sensible not to stand out on the road yelling out the network specs, IP ranges, and what patches you are missing. I will give you that. But hoping no one can find that information out is naïve at best.

 

Relying purely on the data being unknown is clearly not secure, but there's no reason not to make it tricky for hackers to find. If a hacker wanted to exploit the vulnerability in Papercut, they could start with the list of schools who have posted to that site saying they have Papercut, and target them. Obscurity doesn't make my network impenetrable but it does make it a bit stronger than an otherwise identical yet publicly-documented network.

Posted
In fact, I would go as far as to say security by design and STO are opposite ends of the spectrum so incompatible. The former, you make things secure so anything that can happen will be anticipated by design, the later you cross your fingers and hope.

 

Absolutely completely not true! They're absolutely compatible to the point that NIST suggest that both are part of your strategy. As they should be. I'm not going to make "secret can't tell you" the lynchpin of my security systems, just as much as I'm not about to go "Well I'm fully patched so I'm totally safe, so I'll just advertise my public facing IP for remote desktop on my website and let everyone know exact the model of my Firewall, CCTV DVR and Copiers on WDTK and trust that Sophos, Microsoft, Hikvision and Canon haven't got exploits they've failed to patch or disclose"

You are also pulling away from talking about types of copiers and CCTV cameras, when there is no obscurity around them. Unless you are using shape camouflage, like car manufacturers do, or putting sheets over them, then they are easily spotted and easily identifiable.

 

OK, so please tell me when looking at your CCTV and copiers without going near them anything other than the manufacturer? Generally, you can't. But please continue to ignore the fact that I've said disclosing manufacturers isn't an issue, but disclosing makes and models is, especially when it comes to equipment and systems behind. There is absolutely no public interest in knowing I have a particular model of a device, but there is to people who might want to attempt to use that device as a backdoor.

Yes it is sensible not to stand out on the road yelling out the network specs, IP ranges, and what patches you are missing. I will give you that. But hoping no one can find that information out is naïve at best. And if you are going to base your security design on people being able to find out that information anyway, then what is the point in even considering that information hidden anyway?

 

It's not about hoping no one can find that information, its about not openly disclosing information that could be useful whilst using security by design practices to try and lock it down. Even segmenting your network wouldn't be enough if your hardware is still vulnerable.

If you're basing your security by design principle on being able to close all attack vectors and hoping you don't have a huge security hole in a device that you've just disclosed is on your network publicy, then you're being naive at the very, very best. Having blind faith and trust in companies that produce your hardware such as OS's, copiers, firewalls to keep you secure without using all vectors available to you is absolutely wild.

Posted
Relying purely on the data being unknown is clearly not secure, but there's no reason not to make it tricky for hackers to find. If a hacker wanted to exploit the vulnerability in Papercut, they could start with the list of schools who have posted to that site saying they have Papercut, and target them. Obscurity doesn't make my network impenetrable but it does make it a bit stronger than an otherwise identical yet publicly-documented network.

 

But it doesn't make it stronger, it does nothing. If you think hackers are not scanning your public IPs, looking for servers or services that could be compromised then you should keep hoping that obscurity covers you, right up until the point you are receiving a ransom request. If you think a hacker that has penetrated your network isn't scanning every IP range possible and then every port on every device it finds looking for servers and services to compromise then I'll repeat the above.

 

If you did not patch your Papercut server ASAP then you will have problems.

 

There was a thread recently where people were unhappy that management don't take security seriously but how do they take it serious when we are more worried about if someone finds out what model copier we have, or if they find out what printing solution we have, rather than actually fixing the issue.

Posted
But it doesn't make it stronger, it does nothing. If you think hackers are not scanning your public IPs, looking for servers or services that could be compromised then you should keep hoping that obscurity covers you

 

I'm not hoping obscurity covers me, I'm using at as one of the tools in my box. That and a firewall which detects and blocks port scanners.

  • Thanks 1
Posted (edited)
The big issue for me @paulkerton, is that you are making a judgement that doesn't appear to have any grounding in law?

 

Likewise, I could say the same of your judgement.

You seem to think the law says you must disclose everything. It doesn't. At all. By any grounds. It explicitly has clauses that allow you not to disclose things that may be a security concern. I would argue with my DPO, or anyone else that disclosing information of this kind is a massive security concern and the last thing anyone should do is open up your infrastructure by basically doing the IT equivalent of saying to people "Well I'm not going to give you the keys, but I'll tell you the barrel code so you can go get one yourself and let yourself in"

 

I would have real concerns with anyone who thinks disclosing this information isn't a potential problem.

Edited by paulkerton
Posted (edited)
If you think a hacker that has penetrated your network isn't scanning every IP range possible and then every port on every device it finds looking for servers and services to compromise then I'll repeat the above.

and do you know what a good way to penetrate your network would be? To know the exact make and model of hardware on your network and use a known exploit for that device to penetrate your systems... :rolleyes:

 

There was a thread recently where people were unhappy that management don't take security seriously but how do they take it serious when we are more worried about if someone finds out what model copier we have, or if they find out what printing solution we have, rather than actually fixing the issue.

 

Because famously, being told you can't buy a replacement for a device that is out of support, but needs to be kept up and running because people use it never happens in the EDU sector does it?

 

Because exploits always get disclosed and patched instantly, and are never taken advantage of, before even the manufacturers and developers know and patches never fail to do the job...

Edited by paulkerton
Posted
Absolutely completely not true! They're absolutely compatible to the point that NIST suggest that both are part of your strategy. As they should be. I'm not going to make "secret can't tell you" the lynchpin of my security systems, just as much as I'm not about to go "Well I'm fully patched so I'm totally safe, so I'll just advertise my public facing IP for remote desktop on my website and let everyone know exact the model of my Firewall, CCTV DVR and Copiers on WDTK and trust that Sophos, Microsoft, Hikvision and Canon haven't got exploits they've failed to patch or disclose"

OK, so please tell me when looking at your CCTV and copiers without going near them anything other than the manufacturer? Generally, you can't. But please continue to ignore the fact that I've said disclosing manufacturers isn't an issue, but disclosing makes and models is, especially when it comes to equipment and systems behind. There is absolutely no public interest in knowing I have a particular model of a device, but there is to people who might want to attempt to use that device as a backdoor.

It's not about hoping no one can find that information, its about not openly disclosing information that could be useful whilst using security by design practices to try and lock it down. Even segmenting your network wouldn't be enough if your hardware is still vulnerable.

If you're basing your security by design principle on being able to close all attack vectors and hoping you don't have a huge security hole in a device that you've just disclosed is on your network publicy, then you're being naive at the very, very best. Having blind faith and trust in companies that produce your hardware such as OS's, copiers, firewalls to keep you secure without using all vectors available to you is absolutely wild.

 

Could you point me to the guidance by NIST to use security through obscurity? I'd be very interested to read up on it.

It's also interesting that in all my studies and all the articles I've read about security directly say that security through obscurity is the direct opposite of security by design and open security.

 

Public interest is that if you are spending £5,000,000 on 3 MX3405 copiers on a three year lease from your uncle Bob when market value is actually £3,000 then either there is fraud, incompetence or malevolence. Schools are spending public money so the public interest is that it is being spent properly. Hence why the ICO specifically say you don't get choose what is and isn't relevant.

 

You say follow the tenants of security by design, which I have agreed with, then say I trust all those companies blindly. At no point have I said this. I will repeat again slowly.

Security. Through. Obscurity. Is. Not. A. Security. Vector.

Security. Through. Obscurity. Is. Not. A. Security. Layer.

 

If you are following security through design or open security then you would never trust anything blindly, you use the layers to protect your self. Considering open security is based on open source philosophies, your scorn over publishing security details publicly is in contrast with your trumpeting open security. Open security was in response to traditional application security that relied on STO.

 

If you know any information can be found out, STO is completely pointless considering for even a second. It would be like using a zip tie to secure a door, with more security behind. Yes it is a layer but what is the point?

Posted
Yeah, I see where you're coming from and quantifying it could be difficult, but I'm sure you agree a newspaper with a potential story of mismanaged public money is not the same as a sales company who don't want to pay cold-callers. Maybe we need to put up with these misuses of the FOIA to ensure the legitimate uses are still possible.

 

I don't see it as a misuse and I don't see a workable way of deciding who should be allowed to request information and for what reason(s). Whose going to decide, Priti Patel?[1] It's possible that this guy working for a printer company requests the information for his own purposes and someone else spots some anomaly with the data who then reports it to the correct authorities. Without the data being freely available to anyone, that couldn't happen. Anyway, are you saying that someone working for a phone hacking newspaper[1] should have more right to that information than me, an honest tax payer?

 

[1]Extreme examples used for the sake of argument, obviously.

Posted
I don't see it as a misuse and I don't see a workable way of deciding who should be allowed to request information and for what reason(s). Whose going to decide, Priti Patel?

 

Indeed, which is why I said we unfortunately just need to suck it up when it happens.

 

Anyway, are you saying that someone working for a phone hacking newspaper[1] should have more right to that information than me, an honest tax payer?

 

No, I'm not endorsing the illegal action of newspapers at all. I did, however, say that in an ideal world a newspaper or a concerned citizen wishing to expose something should be given the data when a salesman wanting to save his company some money shouldn't. I always get rid of cold callers when they phone asking me what printers I have, so In my ideal world it would be the same with FOI requests asking what printers I have.

 

Don't get me wrong, I've seen FOI used very effectively and indeed have made FOI requests myself where I had a concern, but I don't personally think this instance is why the Act was created.

Posted
Could you point me to the guidance by NIST to use security through obscurity? I'd be very interested to read up on it.

https://csrc.nist.gov/publications/detail/sp/800-160/vol-2-rev-1/final

Public interest is that if you are spending £5,000,000 on 3 MX3405 copiers on a three year lease from your uncle Bob when market value is actually £3,000 then either there is fraud, incompetence or malevolence.

I dunno, I think the half a million per year, per copier might make that obvious - regardless. Might just be me mind you.

If you are following security through design or open security then you would never trust anything blindly, you use the layers to protect your self. Considering open security is based on open source philosophies, your scorn over publishing security details publicly is in contrast with your trumpeting open security. Open security was in response to traditional application security that relied on STO.

 

Nonsense. Open security is completely different to relying on the goodwill of a vendor to make sure their security issues are patched.

Posted
https://csrc.nist.gov/publications/detail/sp/800-160/vol-2-rev-1/final

 

I dunno, I think the half a million per year, per copier might make that obvious - regardless. Might just be me mind you.

 

 

Nonsense. Open security is completely different to relying on the goodwill of a vendor to make sure their security issues are patched.

 

Sorry, being dense, can't find a single mention of security through obscurity in that document. Could you give me a section or page number?

 

If the half a mill per copier isn't published, it isn't obvious. That is what FOI is about, bringing these things to light. And sorry, I thought it was fairly obvious they were exaggerated figures to make the example clear. I will try and be more literal from now on.

 

Where did I say Open Security is about relying on the vendor? It is nothing of the sort. In fact I quite clearly wrote, with no exaggerations or sarcasm to obfuscate, that:

following security through design or open security then you would never trust anything blindly

So I am confused where your comment came from. Could you enlighten me?

 

Maybe there is a difference in understanding of security terms here. Could you define what you understand to be security through obscurity, Security by design and open security? What you are arguing does not align with my understanding of the definitions of these terms.

Posted (edited)
I dunno, I think the half a million per year, per copier might make that obvious - regardless. Might just be me mind you.

 

OK, here's one for you. We pay a considerable sum per quarter for two copiers at one of our schools. At a glance, someone would look at our copier rental costs on our published accounts and think "they're being ripped off, why would a small school be paying that?". So, an FOI to find out what exactly it is would be entirely legitimate. They'd discover they're production print machines, and not the usual little machines most schools have.

 

An FOI request would be completely legit there. Yet, using your view, the public (who have a right to hold us to account) would not be able to find out what it is we're spending our money on.

 

 

Can you provide advice that comes from the UK instead? Mainly because it would be provided within the context of UK law...

Edited by localzuk
Posted

@localzuk and @paulkerton

 

This has been an interesting dialogue between you both (with some good interjections from others) and, in my typical fence-sitting fashion, I can honestly say that I can see both positions and feel your frustrations.

 

The problem with the use of FOIA is that there is scope for arguing about lots of things, and many will make the most of small things to justify why they work in a particular way. But we all know that anyway.

 

Yes, there is annoying, but it is a reasonable request. It is not nasty, aimed at wasting your time or trying to trick you into say/doing/sharing something.

It is not vexatious. But that is not to say that some exemptions might not wholly or partially be relevant.

These exemptions need to be looked at very carefully though, and with the support of experienced advice.

The requestor knows this and so has worded the request carefully so there is little chance of it being thrown away.

 

Be very careful about refusing requests. If you do, then make sure they are still logged and all decisions are noted and justified. Be professional and, most importantly, treat each request on its own merits.

  • Thanks 1
Posted (edited)

I am no FoI expert but I do give my opinion on security matters to case officers who deal with complaints about exemptions so I can give some input on what I would be looking at.

 

For some further input too - advice and guidance from NIST can and does get used in tribunals as an industry standard of best practice. I've citied NIST in many cases including ones at low tier tribunals to support my security assessments.

 

What I would be looking at the organisation to demonstrate is why the release of the information would likely cause a security risk. For example, if an organisation said the release of its photo-copy make and model would cause a security risk, well why, what risks exactly and what is the likelihood of the risk occuring?

 

This isn't formally defined, but I think I’d be looking at where the risks fit into the following:

 

• Impossible - no possible security risks can come of it

 

• Theoretically possible - but unlikely due to resources required (i.e. would involve the attacker creating a zero-day, or would need the attacker to already have gained unauthorised but authenticated access first)

 

• Theoretically possible - and likely (i.e. resources such as a time and effort are unlikely to be a barrier. Compromise would be trivial)

 

• Certain - the release of the information would certainly and without questions cause a our system to be compromised

 

What I would not factor in, is my opinion on whether the release of the information should cause a security risk. As a bad example because its not public sector, but Microsoft argue the release of its source code can cause a security risk because it allows people to view it and identify vulnerabilities. Some people in the security industry disagree with this position. I would not make an assessment on who is right and wrong, the facts of the case are Microsoft do rely on security by obscurity and I can't undermine that because of my own opinion of what I think it right.

 

If the school was taking the position that it lacks good patch management as a reason to do not release make and model, I'd be looking at written statements from the most senior management setting that out. And in addition, why the lack of poor patch management would cause a risk in the context of releasing information about the make and model of a printer, and the likelihood etc as listed above.

 

I couldn’t take the position that the school should be patching, because if its senior management has set out that it does not, then that is the fact of the matter.

Edited by rom1984
  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...