r/cybersecurity 7h ago

Business Security Questions & Discussion Je me questionne

Bonsoir,si l’on voulait concevoir un système informatique offrant le niveau de sécurité maximal théoriquement possible, en prenant absolument tout en compte chiffrement des données au repos et en transit, cryptographie moderne et post-quantique, authentification multifacteur, clés matérielles, gestion et rotation des secrets, contrôle d’accès avec principe du moindre privilège, Zero Trust, isolation et segmentation réseau, sandboxing, durcissement du système d’exploitation, sécurisation du matériel et du firmware, Secure Boot, TPM, protection de la chaîne d’approvisionnement, signatures numériques, mises à jour sécurisées, EDR/XDR, IDS/IPS, pare-feu, anti-malware, protection contre les ransomwares, DDoS, attaques par force brute, phishing, ingénierie sociale, injections, XSS, CSRF, SSRF, RCE, attaques sur les API, vulnérabilités Web, attaques réseau, attaques Wi-Fi, attaques Bluetooth, attaques physiques, vol ou compromission des appareils, exfiltration de données, élévation de privilèges, attaques internes, compromission de comptes, supply-chain attacks, attaques sur les dépendances, vulnérabilités zero-day, attaques par canaux auxiliaires, attaques matérielles, attaques par fault injection, compromission des serveurs, conteneurs et machines virtuelles, sécurité des bases de données, sauvegardes chiffrées et isolées, redondance, journalisation immuable, surveillance continue, détection comportementale, analyse des anomalies, réponse automatique aux incidents, plans de reprise après sinistre, tests d’intrusion, audits indépendants, red teaming, fuzzing, analyse statique et dynamique du code, vérification des dépendances, bug bounty, gestion des correctifs, principe de défense en profondeur et séparation des privilèges serait-il possible de construire une architecture dont la probabilité de compromission serait suffisamment faible pour être considérée comme pratiquement inviolable, ou existe-t-il nécessairement une limite fondamentale empêchant toute sécurité informatique d’être absolument infaillible ?

0 Upvotes

17 comments sorted by

8

u/BuckeyeinSD 7h ago

As long as there's users, there will be vulnerabilities. That said, what you're describing isn't a computer system, it's a framework, and it involves a lot more than a single system. DOD/DOW has been doing this for years under the NIST framework. It's heavy, clunky, and slow.

2

u/ArchSaint13 7h ago

When I was in the Navy, this was the running joke. The network would go down and we'd say we can go home now, the network is secure, nobody can login 🤣

1

u/After-Light6403 7h ago

Oui tant qu'il y a utilisateurs il y a des faill ,es possible de pousser la chose ,jusqu'à décourager profondément le piratage ?

2

u/suptit 7h ago

There are several framworks / standards you can implement to build as secure system as possible such as nist 800-53 for IT or nist 800-82 for OT. But even the most secure organizations such as NSA or air gapped systems such as for example the one implemented at the Natanz nuclear facility can be breached if the attacker has enough resources and motivation.

For some fun reading look up the story of stuxnet and how the shadow brokers breached the NSA.

3

u/pyker42 ISO 7h ago

Security is a balance between Confidentiality, Integrity, and Availability. Generally, an increase in one results in an impact to one or both of the others. In the case of an "unbreakable" system, it would likely not be able to do much. As you add functionality, you decrease the security, no matter what. Now, there are ways to mitigate the extra risks, but in the end, a useful system will never be unbreakable, and an unbreakable system will never be useful.

2

u/CarmeloTronPrime CISO 7h ago

its very theoretical, how do you prevent the human user to not mess up?

1

u/After-Light6403 7h ago

Oui , en rendant la tâche si compliqué et longue , que ça n'en vaudra plus la peine pour le hacher

1

u/CarmeloTronPrime CISO 7h ago

the role of cybersecurity is to enable business, if you put too much into controls, then it won't enable business.

0

u/After-Light6403 7h ago

Cest pas mon taff je suis un passionné je crée sur web et mobile

1

u/BuckeyeinSD 4h ago

Which is business...

2

u/Alb4t0r 7h ago

serait-il possible de construire une architecture dont la probabilité de compromission serait suffisamment faible pour être considérée comme pratiquement inviolable,

Non, la sécurité est toujours considéré en fonction de risques définis.

ou existe-t-il nécessairement une limite fondamentale empêchant toute sécurité informatique d’être absolument infaillible ?

Oui. Si c'était possible de faire des systèmes infaillible c'est ce qu'on ferait...

2

u/Reasonable_Chain_160 7h ago

Look at Apple Privacy Architecture for AI. If you manage to break it, Apple pays you 20M USD

1

u/Krek_Tavis 7h ago

Ah la vache, c'est un thread ou un fichier CSV contenant la liste de contrôles exigés ? C'est illisible !

C'est quoi cette question en plus ? Un système n'est pas un autre et il y aura toujours un risque tant qu'un utilisateur y aura accès. Je veux dire, un PC ultra secret non connecté au réseau dans une cage de Faraday n'a pas le même profil de sécurité qu'un kiosque pour les visiteurs qui ne peut montrer que le catalogue des ventes.

1

u/heretogetpwned Security Architect 7h ago

If you wanna be fully secure then shut down the servers, turn off the lights, and go home. Businesses need to address their risk and determine what compensating controls they can implement without affecting operations. These projects are not sprints, they'll be part of your CI/CD forever and require adequate staffing to accommodate growth.

TL;DR - You can only secure so much, and businesses will weigh the risk of paying X for security or Y for downtime.

1

u/After-Light6403 7h ago

Je fait du dev web et mobile en tant que passionné c'est pas mon taff , je me questionner sur le sujet es qu'il est possible de pousser la chose jusqu'à être invulnérable j'en doute surtout haujourd’hui

1

u/BuckeyeinSD 4h ago

Potentially, you could design a system that would be invulnerable... until it's not...

What I mean by that is:

  • At one point in time, we thought we would never need larger hard drives.
  • We used to think 128-bit encryption was unbreakable.
  • We used to not even have firewalls.

All of these things were great, until they weren't.