The theme of the release is a telecom leak on a national scale.
At the beginning of the week, it became known about the world's largest leak of details about the national surveillance and information collection system. Due to a Nokia employee who worked at home with service files, the details of the installation of SORM equipment in the MTS telecommunications infrastructure were lit up on the network for at least a few days.
1.7 terabytes of sensitive data were available without a password to anyone who would try to access a specific IP address on port 873. Judging by some reports, interested parties managed to download the archive.
A detailed account of the UpGuard specialists who discovered the leak is here , continued by TechCrunch. We have published several lessons that any business could learn from this story.
To avoid repetition, here we will briefly give some technical advice and details based on what is known about the leak.
- It doesn't take hackers or malware to harm a company. It only takes one person who does not comply with information security instructions and takes work home.
- The security of the system is equal to the security of the weakest element. Unlike other incidents, this is not the fault of incompetent officials, but the subcontractors of a commercial company. But no matter where the weak link is, the security of the entire chain suffers. It's best to design your security system with all the links insecure (a good example is the recent USBAnywhere vulnerability).
- The economic scale of SORM usually remains in the shadows. Meanwhile, the leaked files talk about upgrading the MTS infrastructure in 16 cities to meet the requirements of the Yarovaya Law. The Bell has already written about how a businessman connected with Alisher Usmanov, through the Citadel holding, actually monopolized the market for equipment for SORM with a volume of over 10 billion rubles.
- Around SORM, not only equipment manufacturers are emerging, but also, taking into account security requirements, an entire ecosystem. For example, the same "Citadel" invested in the startup "Bastion" of the son of the head of the Economic Security Service of the FSB, Sergei Korolev. "Bastion" initially specialized in ethical hacking - that is, testing information systems for vulnerabilities.
- SORM really would not interfere with specialists in operational testing of information systems of companies. Operators are required to purchase and install equipment at their own expense, but in case of detection of leaks in SORM equipment, it can take up to a year to eliminate them - and leaks are not found by people in uniform .
+25 Productivity
Blog host Little Blah! published a list of 25 things that are useful for the career and development of senior developers. The full list is available both as a service that allows you to filter tasks by category and required effort, and in machine-readable form on GitHub.
Many items on the list will be useful not only to developers. We have chosen and loosely translated ten:
- Understand the business side of your job. How does the company make money? Only this is important.
- Participate in the recruitment of your team and in the company's HR processes. Set the bar high to attract quality candidates.
- Demand responsibility not only from yourself, but also from others.
- Ask yourself “why” until you get to the root of the problem.
- Don't forget to build influence on other teams.
- Try to avoid ambiguous task setting. Always be specific.
- Take projects with high risk and high reward.
- Read several specialized books each year.
- Before introducing something fashionable, carefully weigh the pros and cons.
- Participate in several projects, but not as a leader, but as a consultant, auditor or mentor.
Read later
Representatives of various professions these days write open letters in defense of the defendants in the “Moscow case”. IT industry specialists approached the matter in their own way: they posted the letter in the form of a project on GitHub.
As a result, it contains 3999 edits from 1522 people at the time of writing, consists of 34 tasks (26 already completed) and generally looks like a self-organizing industry initiative with patches and variants.
This isn't the first time developers have used GitHub to express citizenship. For example, employees of Chinese technology companies collected information about the working hours of 996 (from 9 am to 9 pm 6 days a week) on this platform.