The motivation for security

Winter Soldier

Level 25
Thread author
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
We often discuss how the attacks are sophisticated, since the malware is advanced and how much it is easy or difficult to organize defenses more or less stratified.

But I would like to consider another perspective in this post

The defence exists if there is the need for security relating to personal data and, unfortunately, of interest to others.
The defense then must be organized by thinking about how we know our enemy, and especially his motivation.
Because the state of the threat today allows anyone, with a strong motivation, to take advantage of a real industry of cybercrime, which provides services and tools for the less skilled people to carry out attacks.

Fortunately, the defense is from the culture and from the information combined with a little bit of healthy paranoia. That is, from the knowledge of the enemy.

Just a thought :)
 

Handsome Recluse

Level 23
Verified
Top Poster
Well-known
Nov 17, 2016
1,242
Paranoia is an emotion nonetheless. You need to be calm and know and implement what you're doing based on your calculated threat model and any potential changes in the future. This is gonna be better than relying on some cheese tactic of an emotion.
 
  • Like
Reactions: Winter Soldier

BugCode

Level 10
Verified
Well-known
Jan 9, 2017
468
Yeah, my post are pretty much often "like child understanding mode". I quoted this my one of favorited movie "My momma always said, "Life was like a box of chocolates. You never know what you're gonna get." <= & that's make it interesting! So, it's like that altrought "know your enemy" is good sentence, but thruth is far beyond :p Thanks WS for starting interesting topic :)
 

Winter Soldier

Level 25
Thread author
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
Paranoia is an emotion nonetheless. You need to be calm and know and implement what you're doing based on your calculated threat model and any potential changes in the future. This is gonna be better than relying on some cheese tactic of an emotion.
A bit of paranoia is how to take awareness of the problem and begin to understand the functioning of the tools that we use on a daily basis. Unfortunately, even on a secure machine, an inexperienced user could create damage.
Unlike what many believe, the "security process" is not a simple product to buy and install, but includes both, material factor and human factor, which notoriously is the weak link of the security chain. The security then has be understood as a process where no solution is final and that has to be managed continuously, in which there are only different levels, proportionate to the importance of the good things to be preserved.
 

Handsome Recluse

Level 23
Verified
Top Poster
Well-known
Nov 17, 2016
1,242
A bit of paranoia is how to take awareness of the problem and begin to understand the functioning of the tools that we use on a daily basis. Unfortunately, even on a secure machine, an inexperienced user could create damage.
Unlike what many believe, the "security process" is not a simple product to buy and install, but includes both, material factor and human factor, which notoriously is the weak link of the security chain. The security then has be understood as a process where no solution is final and that has to be managed continuously, in which there are only different levels, proportionate to the importance of the good things to be preserved.
Paradoxically, maybe, management also incurs cost.
Difference in importance relating to difference in security sounds like principle of least privilege to me. Doesn't Principle of Least Privilege also include things other than the system like data, etc.
 
D

Deleted member 178

Do you know the story of Umbra The Wise? no? shame on you ! so for your personal enlightenment , there is the short version:

Once upon a time , the great Umbra had enough money to buy a PC !!! then he , like any noobs , used is 56k connection to discover the mysterious realm called "Internet" and because Umbra was always touched by the Dark Side , he wandered to the dark corner of the web...especially some hackers forums (mostly a place populated by some advanced script kiddies), then after a while he became friend with some of them. Unfortunately, Umbra The Wise , known at that time under a different and now long forgotten nickname, discussed about the great Subseven, Back Orifice (love the name :p ) and other Poison-Ivy and how to spread them to innocent users...with time some were willing to teach Umbra the art of hacking , but Umbra didn't had the time nor the Will to learn how to code and study attacks procedure, he spent most of his time to challenge real life people on Street Fighter or King od Fighters. However, he decided to challenge his friends to "hack" him then start to learn about defense methods instead of attack. Because Umbra the Wise , knew how his "hacker" friends thinks, he could defeat all their attempts...From that time, Umbra the wise, allow only the worthy to learn his secrets ...

Be a bit paranoid and mostly "know your enemy" !!! (awesome song from Rage against the machine) are the keys.
 
Last edited by a moderator:

frogboy

In memoriam 1961-2018
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Do you know the story of Umbra The Wise? no? shame on you ! so for your personal enlightenment , there is the short version:

Once upon a time , the great Umbra had enough money to buy a PC !!! then he , like any noobs , used is 56k connection to discover the mysterious realm called "Internet" and because Umbra was always touched by the Dark Side , he wandered to the dark corner of the web...especially some hackers forums (mostly a place populated by some advanced script kiddies), then after a while he became friend with some of them. Unfortunately, Umbra The Wise , known at that time under a different and now long forgotten nickname, discussed about the great Subseven, Back Orifice (love the name :p ) and other Poison-Ivy and how to spread them to innocent users...with time some were willing to teach Umbra the art of hacking , but Umbra didn't had the time nor the Will to learn how to code and study attacks procedure, he spent most of his time to challenge real life people on Street Fighter or King od Fighters. However, he decided to challenge his friends to "hack" him then start to learn about defense methods instead of attack. Because Umbra the Wise , knew how his "hacker" friends thinks, he could defeat all their attempts...From that time, Umbra the wise, allow only the worthy to learn his secrets ...

Be a bit paranoid and mostly "know your enemy" !!! (awesome song from Rage against the machine) are the keys.
And this I will wager is a true story i reckon. :D
 
Last edited:
D

Deleted member 178

Paranoid users are mostly those that have doubts because they don't understand. Their thinking typically manifests as something like this: "I will take a T-99 main battle tank to a knife fight."
And wear a kevlar vest to avoid mosquitoes' bites :p
 
  • Like
Reactions: roger_m

larry goes to church

Level 3
Verified
Mar 10, 2017
103
I think this stops alot of script kiddies first and foremost.

If you're going to attack something you opsec must be PERFECT no if and or buts about that.
Paranoia is pretty much the first stepping top to good opsec.
 
  • Like
Reactions: AtlBo

Solarquest

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Do you know the story of Umbra The Wise? no? shame on you ! so for your personal enlightenment , there is the short version:

Once upon a time , the great Umbra had enough money to buy a PC !!! then he , like any noobs , used is 56k connection to discover the mysterious realm called "Internet" and because Umbra was always touched by the Dark Side , he wandered to the dark corner of the web...especially some hackers forums (mostly a place populated by some advanced script kiddies), then after a while he became friend with some of them. Unfortunately, Umbra The Wise , known at that time under a different and now long forgotten nickname, discussed about the great Subseven, Back Orifice (love the name :p ) and other Poison-Ivy and how to spread them to innocent users...with time some were willing to teach Umbra the art of hacking , but Umbra didn't had the time nor the Will to learn how to code and study attacks procedure, he spent most of his time to challenge real life people on Street Fighter or King od Fighters. However, he decided to challenge his friends to "hack" him then start to learn about defense methods instead of attack. Because Umbra the Wise , knew how his "hacker" friends thinks, he could defeat all their attempts...From that time, Umbra the wise, allow only the worthy to learn his secrets ...

Be a bit paranoid and mostly "know your enemy" !!! (awesome song from Rage against the machine) are the keys.

Nice story, I like it! ;)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top