跳到主内容
@wquguru
精选75MicroConf(YouTube)独立开发与小生意

SaaS创始人本周必做的3项安全修复:防密码复用与钓鱼

3 Security Fixes Every SaaS Founder Should Make This Week

原文
发到 X

Howdy folks, that was a really good lead in, and I'm not Kevin Mitnick, very important to clarify. He was a friend of friends, so RIP Kevin. This is what I'm here to talk to you about. I'm also going to go fast, there's a lot of specifics in here. I do not expect you to memorize it, the slides are going to be up at this link, so just pull that up on your phone. And they'll be up after the conference. So, I'm going to tell you about some interventions that I've made in my own business to keep us delivering customer success and not getting hacked, because it's really embarrassing if you're a cybersecurity consultancy and you get hacked.

大家好,刚才的开场白非常精彩,而且我不是凯文·米特尼克(Kevin Mitnick),这点必须澄清。他是朋友的朋友,所以愿他安息。我今天要和大家聊的就是这个。我还会讲得很快,因为这里有很多细节。我不指望你们记住所有内容,幻灯片会上传到这个链接,所以你们可以在手机上查看。会议结束后也会提供下载。所以,我要分享一些我在自己的业务中实施的干预措施,以确保我们持续交付客户成功,同时避免被黑客攻击,因为作为一家网络安全咨询公司,如果被黑那就太尴尬了。

So, there's a joke in cybersecurity that we all think that we're this guy, and we all really think that this is what we do all day, and the reality is that we're this guy, and this is what we do all day. We yell at our computers a lot. And as a bootstrap founder as well, not of a SAS business, but of my little cybersecurity consultancy, you know, I would really like to believe that I'm this guy every day, you know. Um, I would really like to believe, you know, ton of happy customers, you know, revenue graph up into the right, which is how which is how it is every day, right, Rob?

在网络安全领域有个笑话:我们都以为自己是这个人,并且真心认为我们整天都在做这种事;但现实是,我们是另一个人,这才是我们整天真正在做的事。我们经常对着电脑大喊大叫。作为一名自举创业(bootstrap founder)的创始人——虽然不是SaaS企业的创始人,而是我这家小型网络安全咨询公司的创始人——说实话,我真希望每天都能觉得自己是前者。嗯,我真希望如此,你知道的,一堆开心的客户,收入曲线一路向右上方攀升,就像每天都这样,对吧,Rob?

Like, 100%. Oh, yeah. Yeah. But the reality is that as a bootstrap founder, I am still this guy. I spend most of my day yelling at computers, staring at my screen. It's not great. So, when some well-meaning colleague of mine, I love his theory, comes to me and is like, "Don't click links in emails. You know, set up your firewall properly. Like, buy our, you know, security solution." I You could be asking me if my TPS reports are filed properly.

完全同意。哦,是的。没错。但现实是,作为一名自举创业者,我依然是后者。我大部分时间都在对着电脑大喊大叫,盯着屏幕看。这并不好。所以,当我一位出于好意的同事来找我,说:“别点击邮件里的链接。你知道的,正确配置你的防火墙。比如,购买我们的安全解决方案。”这时候你简直可以问我我的TPS报告是否按规定归档了。

They're not. My taxes are also not filed. Don't tell the IRS. We're working on it. And the plain fact is we've been giving bad security advice for a long time as a cybersecurity community, and it's kind a problem. Uh there are good reasons for this, uh but the biggest reason is that it's not the 1990s anymore. Uh and that is where our advice continues to be stuck. Um it it's probably good that it's not the '90s. It is definitely not this '90s anymore.

并没有。我的税也没申报。别告诉国税局(IRS)。我们正在处理。事实是,作为网络安全社区,我们长期以来一直在提供糟糕的安全建议,这确实是个问题。当然,这背后有合理的原因,但最大的原因是时代变了,现在已不是20世纪90年代。而我们的建议却还停滞在那个年代。不过,幸好现在不是90年代了。它绝对不再是那个‘90s’了。

Uh but it is also not this '90s anymore, and a lot of our security advice assumes that these are still the computers that we're using. Uh so, from you know, the and the the the TLDR did not fit in this talk. Believe me, I tried. Uh find me afterwards. But the the reason here is that the internet happened. Like, we connected all of our computers together. Uh and now, you know, the advice that worked when we were all sitting in cubicles in, you know, uh beige offices uh 20 years ago just doesn't apply.

嗯,但如今也不再是那个‘90年代了,而我们许多安全建议都假设我们使用的仍然是那些计算机。嗯,所以,你知道的,以及……总之,TLDR(太长不看)放不进这个演讲里。相信我,我试过了。之后可以找我聊聊。但这里的原因是互联网出现了。就像,我们把所有的电脑都连接在了一起。嗯,而现在,你知道的,20年前当我们都坐在米色办公室的隔间里时适用的建议,现在已经不再适用了。

Um yeah, yeah, yeah. But the internet is the reason that we're all here. So, we have to figure out what to do about it. Uh and so, uh from the background of working in security at one of the software companies, some of which you might have uh heard of, uh like how do people actually get hurt? Like, what did we see being on the receiving end of a lot of adversarial behavior, uh like we were just talking, uh that actually mattered?

嗯,是的,是的,是的。但互联网正是我们所有人齐聚于此的原因。所以,我们必须弄清楚该如何应对它。嗯,因此,基于我在一家软件公司从事安全工作的背景,其中一些公司你可能听说过,比如人们究竟是如何受到伤害的?也就是说,作为大量对抗性行为的承受方,我们看到了什么实际产生了影响的事情?就像我们刚才讨论的那样,哪些是真正重要的?

And the flip side of that being, like, where then can we target the most effective interventions so that we are, you know, making the most uh best use of our time, our money, our energy, and our customers' time, money, and energy? Uh so, that brings me to to the subject of my talk. Uh these are again, like, interventions that I made in my own organization, little organization, um about three people. It's me and a few 1099s, uh but that have really moved the needle for us, and that were, you know, straightforward things that we could do just every day as part of our processes to, like, improve uh the way that we work.

而另一方面则是,我们可以将最有效的干预措施针对哪里,以便我们能最好地利用我们的时间、金钱、精力,以及客户的时间、金钱和精力?嗯,这就引出了我演讲的主题。嗯,这些 again 是我在我自己的组织——一个小型组织,大约三个人——中实施的干预措施。就是我加上几位独立承包商(1099),但它们确实为我们带来了显著的进展,而且是一些 straightforward(简单直接)的事情,我们可以每天作为流程的一部分来做,以改进我们的工作方式。

Um and so, you know, the first threat that gets people in trouble, uh one of the first threats that get people in trouble is password reuse. This is where your CFO or your bookkeeper turns out to have used the same password uh on a Minecraft forum that they use for a bank. That's bad. And you you wouldn't think that it happens, but oh boy.

嗯,你知道,第一个让人陷入麻烦的威胁,或者说让人陷入麻烦的早期威胁之一,就是密码重用。这是指你的首席财务官或簿记员被发现他们在 Minecraft 论坛上使用的密码与银行密码相同。这很糟糕。你本以为这种情况不会发生,但哦,天哪。

[laughter]

[笑声]

Stuff like that happens too often. Uh and so what I want to encourage you all to do is to start using a password manager uh if you're not already. Now, audience participation time. Quick show of hands, who here is already using a password manager? That can be LastPass, that can be Oh my god. I'm going to need to update my advice. This is great. Uh you can be writing something down on a piece of paper. This is another way our advice has changed since the '90s.

诸如此类的事情发生得太频繁了。嗯,所以我想鼓励大家开始使用密码管理器,如果你还没有的话。现在,观众互动时间。快速举手示意,在座谁已经在使用密码管理器了?可以是 LastPass,也可以是……哦,天哪。我需要更新我的建议了。这太棒了。嗯,你也可以把东西写在纸上。这也是我们的建议自‘90年代以来发生变化的一种方式。

Write your passwords down if it means you're not reusing them. Um awesome. So, for all of you who just raised your hand, that's incredible. I love you. Uh if you didn't just raise your hand, come join us. It is better over here. Using a password manager has genuinely made my experience of the internet way better. It's just easier, it's faster. Come join us. I use and recommend LastPass. Uh I use and recommend LastPass for a whole host of reasons, that it works great for teams.

如果这意味着你没有重复使用密码,那就把你的密码写下来。嗯,太棒了。所以,对于所有刚刚举手的朋友们,这简直太不可思议了。我爱你们。如果你刚才没有举手,快来加入我们吧。在这里会更好。使用密码管理器确实让我的互联网体验变得好得多。它更简单、更快。快来加入我们吧。我使用并推荐 LastPass。嗯,出于多种原因,我使用并推荐 LastPass,比如它非常适合团队使用。

So, like I can share my airline password with my admin through a secure vault. Uh when I change my airline password, she can still log in. When she changes my airline password, I can still log in. Um it's subscription-based, which means you can be assured that you'll get security updates and they won't sell out to Russia anytime soon. It is worth every penny. Uh I have a giveaway at the end of the talk, but uh we'll get to that in a second.

所以,比如我可以通过安全保险库与我的管理员共享我的航空公司密码。当我更改我的航空公司密码时,她仍然可以登录。当她更改我的航空公司密码时,我仍然可以登录。嗯,它是基于订阅的,这意味着你可以放心地获得安全更新,而且他们不会很快被俄罗斯收购。每一分钱都花得值。嗯,我在演讲结束时有一个抽奖活动,但我们稍后会谈到这一点。

Uh we're actually going to pause now. If you do not have a password manager, get out your phone. Uh

嗯,我们现在实际上要暂停一下。如果你还没有密码管理器,请拿出你的手机。嗯

You said one password. Is there LastPass or one password?

你说了一个密码。有 LastPass 或 one password 吗?

One password. Did I say LastPass? Oh my god. I'm so sorry. Uh I recommend one password because LastPass has had a bad history of security breaches and I'm tired of and I'm tired of answering the question every 6 months like is LastPass still okay to use? Just use one password. So, anybody take out your phone. Going once, going twice. All right, great. Um So, that's password reuse. Uh start using a password manager.

one password。我说的是 LastPass 吗?天哪。非常抱歉。嗯,我推荐 one password,因为 LastPass 有过不良的安全漏洞历史,而且我厌倦了每六个月就要回答一次“LastPass 是否还可以使用?”这个问题。就用 one password 吧。所以,任何人拿出你的手机。第一次叫价,第二次叫价。好吧,太好了。嗯,这就是密码重用问题。开始使用密码管理器吧。

You don't have to get all your passwords in. Uh you can add them as you go. Uh don't boil the ocean, but get started. Um second threat, something called spear phishing. Uh you might think the answer to this is implementing two-factor authentication. It's not. Uh implement an agreement with your staff that money never moves without strong authentication and authorization. So, what's the threat here? Uh me, Kevin, sends an email to my admin Sasha, which is like, "Just get on the plane.

你不必一次性导入所有密码。嗯,你可以边用边添加。嗯,不要试图一口吃成个胖子,但要先开始。第二个威胁,叫做鱼叉式网络钓鱼。嗯,你可能会认为解决这个问题的方法是实施双因素认证。并不是。嗯,与你的员工达成协议,没有强大的身份验证和授权,资金就不会转移。那么,这里的威胁是什么?嗯,我,Kevin,给管理员 Sasha 发了一封电子邮件,内容是,“赶紧上飞机。”

Uh close the deal. Please wire money to this uh account number. I can't talk now. Bye." Uh you would be surprised how often this uh works. Uh it's been hitting a lot of nonprofits lately. They have a decent amount of money and a wide variation, let's say, in their accounting controls. Um my bookkeeper and my admin and I have a pre-existing agreement that I will never ask them to move money via email. Uh they know there are some invoices that are automatically approved, like my admin's invoice comes through first of the month, uh $900 goes out to Sasha.

“呃,尽快成交。请把钱汇到这个呃账号。我现在没法说话。再见。”呃,你会惊讶于这种手段奏效的频率有多高。呃,最近它盯上了很多非营利组织。它们有相当可观的资金,而且会计控制方面存在很大差异,这么说吧。我和我的记账员以及行政人员之间有一个预先存在的协议:我绝不会要求他们通过电子邮件转账。呃,他们知道有些发票是自动批准的,比如我的行政人员的发票每月1号会进来,然后900美元会支付给Sasha。

Everything else I log into our accounts payable system and manually approve. No exceptions. They know that if they get an email from me saying, you know, "Hey, Darcy, go move the money." it's it's it's an attack. Um This tactic accounts for millions of dollars in fraud every year. People do not get their money back. Uh this puts people out of business. They have to go ask friends and family to bail them out. It is bad.

其他所有款项我都会登录我们的应付账款系统并手动批准。没有例外。他们知道,如果收到我发来的邮件说,“嘿,Darcy,去把钱转了”,那这就是一次攻击。呃,这种手法每年导致数百万美元的欺诈案件。人们拿不回他们的钱。呃,这会导致企业破产。他们不得不向亲朋好友求助以渡过难关。这很糟糕。

Uh and it is really simple. It is cheap for advertisers. They find you on LinkedIn. They send some emails. Uh they don't get caught. Little bit of planning and process discipline. I it feels silly. And, you know, if this has happened to you, like, no judgment here. Um we've all been there. We're all firing out of system one. It's just like getting through the day, closing our inbox out, and it happens to people even after you implement this, it might still happen to you, but a

呃,而且这非常简单。对广告商来说成本很低。他们在LinkedIn上找到你。他们发送一些电子邮件。呃,他们不会被抓到。稍微有点规划和流程纪律。我觉得这很可笑。而且,你知道,如果这事发生在你身上,这里没有任何评判。呃,我们都经历过。我们都是在系统一(System One)的驱动下做出反应。就像熬过一天、清空收件箱一样,即使你实施了这些措施,这种事可能还是会发生在你们身上,但a

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近