So this has been a hell of a two weeks if you pay attention to security news, and I do, mostly because I keep having to change passwords.
First Twitter admitted on the 1st that something like 250,000 accounts got compromised — usernames, emails, encrypted passwords, session tokens, the works. They reset passwords for everyone affected and quietly mentioned it looked like the same kind of "sophisticated attack" that had just hit the New York Times and the Wall Street Journal a few days before that. Nobody's said outright who did it. Nobody ever does, really, until months later when some security firm publishes a PDF with a name like APT-something attached to it.
Then last Thursday Adobe pushed out another emergency Flash Player patch, the second one this year already, for two zero-days that were being actively used in the wild. One of them was apparently getting delivered through a Word document with an embedded SWF file, which is such a specifically 2013 sentence to type. The other targeted Firefox and Safari on Mac. I updated Flash on three machines that day and I am so tired of updating Flash. I know everyone says just get rid of it, and sure, fine, someday, but half the sites I still use for work require it and I don't get to pick.
And then last night, right in the middle of the State of the Union, Obama signed an executive order on cybersecurity for critical infrastructure. I watched about four minutes of the speech before I got bored and went back to reading about the Flash thing, but I caught the part where he mentioned it. The order is basically about getting power companies, water systems, that kind of thing, to start sharing threat information with the government and adopting some baseline security standards. Voluntary standards, is the catch. Congress didn't pass the actual cybersecurity bill last year; this is the White House doing what it can without them.
I have a hard time getting excited about executive orders in this space. Not because the goal is bad, the goal is obviously fine, nobody wants the power grid running on whatever a sysadmin configured in 2004 and never touched again. But an order that says "please share information and please follow good practices" doesn't really compare to, say, a Word document that installs malware when you double click it. Those aren't playing the same game. One is a policy memo. The other one is a guy in a data center somewhere right now trying to figure out which of his machines got hit.
What actually strikes me reading all three of these stories back to back is how boring the attacks themselves are. Nobody's doing anything clever with new exploit techniques nobody's ever seen. It's phishing emails with attachments, it's browser plugins that are eight years old architecturally, it's password reuse across a hundred sites so that one leaked database means twenty accounts are gone. The New York Times thing last month started with a phishing email. Twitter's issue, near as anyone can tell, traces back to the same rough playbook. It's not James Bond stuff, it's just that most people, including me half the time, click things they shouldn't and reuse a password they know they shouldn't reuse.
I finally set up 1Password properly this week, generated unique passwords for the maybe fifteen accounts I actually care about, and it took the better part of an evening and I still resent it a little. Not because it doesn't work (it works fine) but because it's one more piece of software I have to trust, sitting between me and everything else I use software for. That's the actual state of things right now if you're paying attention: patch your Flash, watch your email, and hope the accounts you don't personally control are being run by people who are paying as much attention as you are, which they mostly aren't.
Anyway. Go update your Flash player if you haven't. It'll ask you to restart your browser, it'll be annoying, do it anyway.