The Mistakes Behind Most Breaches
Could You Reconstruct It Afterwards
Last timeSomebody Else's Code
Every earlier lesson assumed you find out. The test of your logging is not whether it exists but whether you can answer, today, a question you will be asked under pressure.
The four questions
Every lesson so far has been about a mistake and its repair. This one is
about the case where the repair was missed, which is the case you should
plan for, since the whole course has been a list of things that keep
happening to competent teams.
When it happens, you will be asked four questions, in roughly this order,
by somebody who needs answers today. What did they reach. When did it
start. Is it still happening. Who else is affected.
That list is the entire specification for your logging. Anything that
helps answer those four is worth keeping, and anything that does not is
volume. The useful property of stating it this way is that it replaces an
unbounded ambition, log everything, with a finite test you can apply to
each decision.
| asked in every incident, | answerable from a typica | needs the record identif | needs retention beyond a | |
|---|---|---|---|---|
| what did they reach | 1 | 0 | 1 | 0 |
| when did it start | 1 | 1 | 0 | 0 |
| is it still happening | 1 | 1 | 0 | 0 |
| who else is affected | 1 | 0 | 1 | 1 |
The six fields
So what has to be in an event. Six things, and the two that go missing
are predictable.
who the acting account, by stable identifier
not a display name, which changes
what the action, from a fixed vocabulary
read, update, delete, export, grant
which the identifier of the record acted on
this is the field that gets omitted
and it is the one question one needs
where the source address, and the session
so two sessions of one account differ
when a timestamp with an offset, from a
clock synchronised to a known source
outcome succeeded, refused, or failed
refusals matter more than successes
when you are looking for an attempt
two rules about content:
no credentials, tokens or card numbers
no field whose own exposure would be an
incident, because a log is read widelyThe identifier of the record is the one that gets left out, and leaving it
out is the difference between knowing that somebody called the invoice
endpoint four thousand times and knowing which four thousand invoices
they received. The first is a shape. The second is the answer to question
one, and it is the one you will have to put in a letter to the people
affected.
Refusals are the second omission. A system that logs only what succeeded
cannot show you the eleven thousand attempts that failed before the
successful one, which is usually the clearest signal there was and often
the only thing distinguishing an attack from ordinary use.
The lesson stops here
4 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents