{"id":2967,"date":"2016-10-17T11:52:13","date_gmt":"2016-10-17T17:52:13","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2967"},"modified":"2018-02-01T15:33:11","modified_gmt":"2018-02-01T22:33:11","slug":"sucuri-makes-a-persuasive-case-that-you-should-avoid-using-their-services","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/10\/17\/sucuri-makes-a-persuasive-case-that-you-should-avoid-using-their-services\/","title":{"rendered":"Sucuri Makes A Persuasive Case That You Should Avoid Using Their Services"},"content":{"rendered":"<p>When it comes to the security of websites the situation isn&#8217;t good these days. Who&#8217;s to blame for that? Well there is plenty of blame to go around, but in dealing in the field we can say that one of the big culprits is security companies. The reality is that most of them don&#8217;t know and or care much about security, so they end up in many cases being counter productive to improving security. You won&#8217;t hear much about that, as\u00a0these companies seem to have realized that as long as they all keep quiet about how bad they all are then they can get away with it. That has lead to what appears to be a de facto code of silence in the industry, which we have come to notice since we have\u00a0pointed out problems with security companies&#8217; products and services on a number of occasion and\u00a0have had more than a few people contact us and tell us we shouldn&#8217;t being doing that. They have never were claiming that we had said something false, just that we shouldn&#8217;t be pointing out problems, which obviously sounds rather odd. In one recent case someone from a security company said that if we kept doing this, other security companies would turn &#8220;against you as it already happened to others in the past&#8221;.<\/p>\n<p>Recently though a couple of web security\u00a0companies with a focus on WordPress security criticized each other. Though one of them, Sucuri, ended up making a persuasive case that you should avoid them as well as the other company (which seems to be a good example why these companies normally keep quiet).<\/p>\n<p>Last week Sucuri put out a post on their blog,\u00a0<a href=\"https:\/\/blog.sucuri.net\/2016\/10\/security-confusion-fud-factor.html\">Security Through Confusion \u2013 The FUD Factor<\/a>. While the post doesn&#8217;t mention any companies by name, in a now deleted tweet they specifically mentioned the company Wordfence, who wrote a couple of posts that pointed to problems with Sucuri&#8217;s service (not surprisingly <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/08\/24\/its-scary-how-little-wordfence-knows-about-security\/\">considering Wordfence&#8217;s poor understanding of security<\/a>, they missed a key element of the topic). If you are in even vaguely familiar with the truth about Sucuri, you can&#8217;t help but notice how much of their post applies to them as well.<\/p>\n<p>In several of the early paragraphs they describe companies as using FUD (fear, uncertainty, and doubt) to sell products:<\/p>\n<blockquote><p><i>FUD<\/i> is very common in the infosec domain and used to gain advantage over competitors. It is often done by companies when\u00a0they find themselves hurting financially, desperate for attention, lacking in adoption or the perceived\u00a0real value of a product does not materialize. The goal is simple. <strong>D<\/strong><strong>o whatever possible\u00a0to divert attention and confuse an\u00a0audience so that they buy X\u00a0product<\/strong>.<\/p><\/blockquote>\n<p>and<\/p>\n<blockquote><p>In a crowded space like this, where anyone can be an expert, how are these organizations supposed to stand out? Unfortunately, the apparent answer\u00a0to some seems to be to grow through the employment of disinformation strategies, the FUD factor.<\/p>\n<p>More concerning is that some might\u00a0not be doing it intentionally. They don\u2019t understand security and are mixing FUD with misinformation and taking advantage of the average low-level aptitude of many WordPress users. That creates this concept of\u00a0<b>Security Through Confusion<\/b>.<\/p><\/blockquote>\n<p>Next up the they have list of FUD triggers, which\u00a0are &#8220;designed to help you know if you\u2019re being deceived.&#8221; One of those is<\/p>\n<blockquote><p><strong>An organization who claims \u201cWe\u2019re the best!\u201d or \u201cWe\u2019re the experts!\u201d or \u201cWe beat everyone by a wide margin!\u201d<\/strong> \u2013&gt; Everyone is the best in their own eyes.<\/p><\/blockquote>\n<p>You don&#8217;t have to look far to see Sucuri doing that, here is the first sentence of the <a href=\"https:\/\/wordpress.org\/plugins\/sucuri-scanner\/\">description page<\/a> for their WordPress plugin:<\/p>\n<blockquote><p>Sucuri is a globally recognized authority in all matters related to website security, with specialization in WordPress Security.<\/p><\/blockquote>\n<p>Seriously, they wrote that. And now they are telling you to watch out for just that thing.<\/p>\n<p>Right after that in the post they write this:<\/p>\n<blockquote><p>If you see any of these red flags it\u2019s time to approach them carefully. In some instances, you\u2019ll want to run the other direction quickly. Instead, spend the time to perform some critical thinking when working with an organization. Why are they making these claims, and is there anything that is supporting these claims?<\/p><\/blockquote>\n<p>Next they write this:<\/p>\n<blockquote><p>The more challenging triggers are those that are technical because not everyone is able to appreciate the nuances of an argument. You hear what you perceive to be an authority and believe them to be accurate.<\/p><\/blockquote>\n<p>This could apply to many things we have seen with Sucuri, but let&#8217;s look at one. Before that though, let&#8217;s look at example of this they provide.<\/p>\n<blockquote><p><strong>Plugin creators that misuse terminology<\/strong>. An example of this would be claiming they are the only \u201cdefense in depth\u201d solution as it contradicts the very idea of a defense in depth strategy.<\/p><\/blockquote>\n<p>It was just at the end of last month we looked at an example of <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/09\/28\/sucuri-doesnt-have-a-clue-what-brute-forcing-actually-refers-to\/\">them not having a clue what a brute force attack is<\/a>, that is despite it being a common enough term that it has a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Dictionary_attack\">Wikipedia page<\/a>. That is only really the tip of the iceberg though. As we discussed back in August, either Sucuri doesn&#8217;t understand that <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/08\/02\/no-one-is-trying-to-brute-force-your-wordpress-admin-password\/\">brute force attacks against WordPress admin passwords are not happening<\/a> or they are intentionally misleading the public\u00a0to think they are.\u00a0They even have a <a href=\"https:\/\/sucuri.net\/security-reports\/brute-force\/\">page<\/a> that supposedly tracks brute force attacks against WordPress, but instead highlights that they are not happening.<\/p>\n<p>One of the final elements of the post ends up pointing to them not being able to provide proper protection. They state:<\/p>\n<blockquote><p>A protection product should have enough threat-detection and analysis research to share.<\/p><\/blockquote>\n<p>We can say without any doubt that when it comes to security vulnerabilities in WordPress plugins, which is a major source of WordPress hackings, that Sucuri isn&#8217;t failing on the threat detection front based on the work we do for our <a href=\"https:\/\/www.pluginvulnerabilities.com\/\">Plugin Vulnerabilities service<\/a>. One of the things we do to keep track of vulnerabilities in WordPress plugins is to monitor our websites and third-party websites for hacker activity. Through that we have found numerous vulnerabilities that exist in the then current versions of plugins, which hackers are have been probing for usage of, and would likely be targeted by hackers. When we started finding those we figured that other security companies would also be spotting those as well and wanted to see how our response time compared. You would assume that\u00a0Sucuri would be looking for those as well, otherwise how are they supposed to protect against them if they are not aware of them. Much to our surprise we found that the other security companies <a href=\"https:\/\/www.pluginvulnerabilities.com\/2016\/08\/01\/yet-more-wordpress-plugins-with-apparent-zero-day-vulnerabilities-go-unnoticed-by-security-companies\/\">are not spotting these<\/a>. Through our work we have we have been able to insure\u00a0many of those\u00a0vulnerabilities get\u00a0fixed, so even those not using our service are\u00a0getting improved security thanks to us. By comparison, no one was given any additional protection\u00a0by Sucuri, since they were\u00a0not even aware of the vulnerabilities.<\/p>\n<p>The one time that Sucuri <a href=\"https:\/\/blog.sucuri.net\/2016\/06\/wp-mobile-detector-vulnerability-being-exploited-in-the-wild.html\">mentioned one of those vulnerabilites<\/a> it just went to show that they don&#8217;t really know what they are doing. The post starts with the following image:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2970\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/Disclosure-Image-Wordpress-768x361.jpg\" alt=\"disclosure-image-wordpress-768x361\" width=\"768\" height=\"361\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/Disclosure-Image-Wordpress-768x361.jpg 768w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/Disclosure-Image-Wordpress-768x361-300x141.jpg 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p>While they proclaim this to be their &#8220;security disclosure&#8221;, we had actually <a href=\"https:\/\/www.pluginvulnerabilities.com\/2016\/05\/31\/aribitrary-file-upload-vulnerability-in-wp-mobile-detector\/\">disclosed the vulnerability<\/a> a couple days before, which they were aware since they had repeatedly visited our post before releasing their post.<\/p>\n<p>Here how the post originally started out (it was later edited after we had gotten news outlets to accurately reflect who had disclosed the vulnerability):<\/p>\n<blockquote><p>For the last few days, we have noticed an increasing number of websites infected without any outdated plugin or known vulnerability. In most cases it was a porn spam infection. Our research team started to dig into the issue\u00a0and found that the common denominator across these WordPress sites was the plugin <strong>WP Mobile Detector<\/strong> that had a 0-day arbitrary file upload vulnerability disclosed\u00a0on May 31st. The plugin has since been removed from the WordPress repository and no patches are available.<\/p><\/blockquote>\n<p>In that there are several huge red flags. Let&#8217;s start with the fact that Sucuri did not detect this vulnerability as it was originally being exploited,\u00a0which they should have been able to do. We were able to do that and we don&#8217;t claim to be a &#8220;globally recognized authority in all matters related to website security&#8221;. Right there you can see they don&#8217;t have\u00a0&#8220;enough threat-detection&#8221;. Then they fail on the &#8220;analysis research&#8221; front as well. \u00a0When you are cleaning up a hacked website one of the basic steps is to determine how the website was hacked and you do that in large part by reviewing the log files. We know that Sucuri didn&#8217;t do that in this case, because if they did they would have easily found the vulnerability. Instead for some reason they were relying on trying to find a common denominator between the hacked websites (which shows they lack even basic skills). If we hadn&#8217;t already identified the vulnerability in the plugin they may have still been in the dark.<\/p>\n<p>The fact that they didn&#8217;t looks at the logs in this case isn&#8217;t an aberration, if you take a look at a <a href=\"https:\/\/sucuri.net\/documentation\/Infographics\/16-infographic-how-to-clean-hacked-wordpress-site.png\">recent infographic they put together on cleaning up hacked WordPress websites<\/a>, you will see there is no mentioning of determining how the website was hacked. That is despite that being one of three main components of hack cleanups. This point to the fact that they don&#8217;t properly clean up hacked websites and that they can&#8217;t properly protect websites as they don&#8217;t even know what the real threats out there are.<\/p>\n<p>Also problematic on the &#8220;analysis research&#8221; front is that they didn&#8217;t mention that the vulnerability was only exploitable if you had PHP option enabled that is known to permit just this type of vulnerability. We prominently mentioned it in our post, so they were aware of it. Either they didn&#8217;t understand the significance of it or they didn&#8217;t want to mention it, since knowing that would allow a lot of people to easy see that they were not vulnerable and it would also show that you can actually take actions that will protect your website, instead or relying on a paid service.<\/p>\n<p>Another one of the last things they say in the post is this<\/p>\n<blockquote><p>Be mindful of bold claims with no supporting data, or extremely vague descriptions.<\/p><\/blockquote>\n<p>If you look at how they promote their service, they also line up with this.<\/p>\n<p>On their homepage here is how they advertise their protection as:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2976\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-protect-my-website.png\" alt=\"PROTECT MY WEBSITE Currently under DDoS Attacks Stop Vulnerability Exploit Attempts Undergoing Brute Force Attacks\" width=\"350\" height=\"275\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-protect-my-website.png 350w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-protect-my-website-300x236.png 300w\" sizes=\"auto, (max-width: 350px) 85vw, 350px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Beyond the fact that almost no one is actually undergoing brute force attacks ever (they really are pushing that falsehood), as we just discussed Sucuri isn&#8217;t even aware of many vulnerabilities, so their ability to protect against them is limited to say the least (also it can be incredibly easy to get around their protection, as well touch on in a future post).<\/p>\n<p>If you click the link you will get a whole host of claimed protections, without any supporting data:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2977\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-unsupported-claims-1.png\" alt=\"Protect Your Website. We Stop Website Hacks and DDoS Attacks. We mitigate DDoS attacks, improve and optimize your website's performance, and stop hackers from exploiting software vulnerabilities (i.e., SQLi, XSS, RCE, etc...). Cloud-based protection, no installation required.\" width=\"480\" height=\"220\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-unsupported-claims-1.png 480w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-unsupported-claims-1-300x138.png 300w\" sizes=\"auto, (max-width: 480px) 85vw, 480px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2978\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-unsupported-claims-2.png\" alt=\"Complete Website Protection DDoS Mitigation and Hack Prevention Mitigate DDoS Attacks Stop Vulnerability Exploits Prevent Website Reinfections Proactive Website Protection Global Anycast Network Content Distribution Network (CDN) Performance Optimization \/ Acceleration Full DNS Management Customer Support $19.98\/month Annual Billing Available 24\/7\/365 Attacks We Prevent: TCP SYN Flood HTTP\/s Flood SQL Injection (SQli) Brute Force Attempts Vulnerability Exploits Malformed Requests Zero Day Prevention Bot Requests \/ Traffic Many More\" width=\"940\" height=\"450\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-unsupported-claims-2.png 940w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-unsupported-claims-2-300x144.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/10\/sucuri-unsupported-claims-2-768x368.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>Their claim of &#8220;Zero Day Prevention&#8221; also should be a red flag. A zero-day vulnerability is any vulnerability that is being exploited before the developer of the relevant software is aware of it, so to prevent those you are really saying you can prevent any vulnerability from being exploited, which isn&#8217;t all that believable.<\/p>\n<h2>Help\u00a0Improve Security By Warning Others About Sucuri<\/h2>\n<p>As long as bad security companies like Sucuri are to flourish, security companies are going to continue to be an impediment to improving to improving the security of websites. So by letting others know that they should avoid Sucuri,\u00a0you will be helping to improve the situation. You don&#8217;t need to take our word that they should be avoided, Sucuri has made the case themselves that they should be avoided.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to the security of websites the situation isn&#8217;t good these days. Who&#8217;s to blame for that? Well there is plenty of blame to go around, but in dealing in the field we can say that one of the big culprits is security companies. The reality is that most of them don&#8217;t know &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/10\/17\/sucuri-makes-a-persuasive-case-that-you-should-avoid-using-their-services\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Sucuri Makes A Persuasive Case That You Should Avoid Using Their Services&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[68],"class_list":["post-2967","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-sucuri"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2967","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2967"}],"version-history":[{"count":9,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2967\/revisions"}],"predecessor-version":[{"id":3899,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2967\/revisions\/3899"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2967"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}