logoalt Hacker News

mapontoseventhsyesterday at 9:26 PM5 repliesview on HN

>in principle, cybersecurity is advantage defender

I disagree.

The defender must be right every single time. The attacker only has to get lucky and thanks to scale they can do that every day all day in most large organizations.


Replies

janalsncmyesterday at 9:35 PM

My understanding of defense in depth is that it is a hedge against this. By using multiple uncorrelated layers (e.g. the security guard shouldn’t get sleepier when the bank vault is unlocked) you are transforming a problem of “the defender has to get it right every time” into “the attacker has to get through each of the layers at the same time”.

show 1 reply
NegativeKtoday at 2:13 AM

The defender must be right every single time, and the attacker right only once.

Until the attacker has initial access.

Then the attacker needs to be right every single time.

traderj0eyesterday at 9:27 PM

Well, the attacker has something to lose too. It's not like the defender has to be perfect or else attacks will just happen, it takes time/money to invest in attacking.

coldteayesterday at 9:50 PM

Not to mention an attacker motivated by financial gain doesn't even need a particular targer defender. One/any found available will do.

tptacekyesterday at 9:39 PM

The attacker and defender have different constant factors, and, up until very recently, constant factors dominated the analysis.