(ISC)² Twitter Updates

  • (ISC)² Twitter Updates

    About the
    (ISC)² Blog

    • (ISC)² believes in the importance of open dialogue and collaboration, between both (ISC)², its certified members and members of business and society.

      (ISC)² established this blog to provide a voice to its certified members, who have significant knowledge and valuable insights to share that can benefit the information security industry, the people in it and the public at large.

      The postings on this site are the author's own and don't necessarily represent
      (ISC)²'s positions, strategies or opinions. (ISC)² does not control, monitor, or endorse any links provided in this blog and makes no warranty or statement regarding the content on any linked website.

      Those who post comments to blogs should ensure their comments are focused on the topic at hand. (ISC)² reserves the right to remove any post or comment from this site.

      Should you find objectionable content in this blog, please notify us as soon as possible at blog@isc2.org.

      Please click here for FAQs.

      Please click here for the Blog guidelines.

    Enter your email address:

    Delivered by FeedBurner

    « Open Source Computer Forensics Manual | Main | Weekly Summary of the "DHS Daily Open Source Infrastructure Report" »

    13 June 2009

    TrackBack

    TrackBack URL for this entry:
    http://www.typepad.com/services/trackback/6a00e54f109b67883401157108f652970b

    Listed below are links to weblogs that reference Bandwidth Caps Means Bad Security:

    Comments

    Before you get worried about the effects of bandwidth caps on the download habits of customers of American ISPs, please have a look at security patterns in countries which have never enjoyed unlimited bandwidth.

    Australia (my country), for example, is similar socially to the USA, but has never had unlimited bandwidth offered by ISPs - mostly due to the cost of rolling out the required infrastructure across a large country for a relatively small customer base. Our ISPs offer a range of plans (at a range of costs) from 400MB/month up to "unlimited" plans, which in parctice are actually capped at about 20GB. The lower end plans usually charge around 15c per MB above the cap. The higher end plans are pretty expensive, particularly comapred to US rates, but often don't charge for excess downloads. Instead the ISP throttles the customer's speed down to 56kbps or less until the start of the next billing cycle.

    I don't have any objective evidence for this, but I don't think the high cost of bandwidth in Australia means that Australian users are any less secure than American users.

    Also, given the logisitcal difficulties, do you really think that sneaker-net is a solution to regular patch rollouts? Who is really going to send a USB key every month to the half-dozen software vendors they rely upon in order to keep their systems up-to-date? Not to mention the manual update process required once the key is returned. I would think that setting aside a proportion of your bandwidth cap (a bandwidth budget, if you like) for essential traffic like security patches would be easier for most users to handle.

    The positive side of bandwidth caps is that users then end up paying for the bandwidth they use. The grandma who just want to receive email from her grandchildren could pay for a plan with a 2GB cap (my mother works happily within 400MB and accepts the need to occasionally pay for extra bandwidth for a large security update). The movie junkie could pay more for a plan with a much larger cap (say 50 - 100GB). The customers who actually use the bandwidth are then paying for the development/maintenance of the infrastructure required to support that volume of traffic.

    Speaking from my own experience, I recently switched to a 5GB/month plan. It was a new experience to have to keep track of what and how much I was downloading. It was toward the end of the billing cycle when I got a Mac Software Update notice telling me I had over 400MB of updates ready for download. So I had to make a choice: update my OS or wait until next month and do it then. I also had the choice not to update at all. For customers on the 400MB/month plan, will they always choose to update their OS above all else?

    I posit that PCs of customers with bandwidth caps may be more likely to be compromised, because they are less likely to be updating their PC due to cost. I also suggest that the current update process has an unlimited bandwidth mindset. I agree a physical delivery method isn't the best either, but I do think we need at least a second (less costly) option for consumer to choose from. Thanks for a perspective from outside America!

    A download cap and penalty fees for going over the cap are not new. I have read them in ISP contracts for a long - long time. What is new, is that some of the vendors have finally decided to invoke the billing for overages or cut backs in service speeds after the overages start. This had to start sometime. You can’t put the verbiage into the contract and not charge for it in a ever tightening economy.

    The risks are real based on user actions. 1. Some users will skip the updates completely. 2. Some users will delay the updates. 3. Fewer will pay extra to get the updates now.

    Yes this increases the risk for all of us.

    But this is not a new experience. Keep yourself safe by doing the updates. Keep yourself safe by have reasonable protection from a botnet denial of service attack. Keep up on your endpoint security. Use software and systems that are designed to weather the storm.

    And keep working, because the run and hide mentality is an even higher risk.

    Don: Your problem is caused by charging extra when you go over the limit, instead of being shaped. The other thing that's very common in Australia is local traffic is free, so Linux mirrors, Apple updates (they use Akamai) don't count towards the limit.

    Microsoft did offer to send WinXP SP2 on CD for free to anyone.

    That would be great if update downloads were free--this should be required of all ISPs. It would take some logistical work by the OS vendors and internet providers, but would definitely address the problem.

    And true, many major updates are also available via CD--I just updated my Ubuntu from 8 to 9 by getting a CD off eBay. It's the customer not getting all the smaller updates and security patches that can be the problem. Thanks for the input!

    The comments to this entry are closed.

    The (ISC)² bloggers

    • Tipton W. Hord Tipton, CISSP-ISSEP, CAP, (ISC)² Executive Director
      Schmidt Prof. Howard A. Schmidt, CISSP, CISM (Hon.)
      Sarah E. Bohne, Director of Communications & Member Services

    Recent Contributors

    Past Contributors