9 ms·
I think we need some sort of awareness day for the general public to understand what internet security _really_ is. Whenever I see news reports, it's always cas
by milesf 11y ago
I think we need some sort of awareness day for the general public to understand what internet security _really_ is. Whenever I see news reports, it's always cast as "hackers broke in to..." such and such. Yet if some brick-and-mortar business is robbed because the owner left the front door unlocked, people would rightfully put the onus mostly on the store owner.
EDIT: Wow. I'm being modded into the basement. When did Hacker News become so PC? Victim-blaming? Seriously? The VNC connections illustrated on this site are that way because of incompetence and ignorance. The reason there are no unlocked brick-and-mortar businesses is because it is due diligence to protect one's assets from not just criminals, but simple mischief.
- donatj 11y agoI think it's even worse than leaving the front door unlocked, it's more akin to leaving it open.
- imtringued 11y agoThese analogies are all bad. There is no door, no lock or any other kind of security.
- drdaeman 11y agoThere can be a door, but there is arguably no burglary or theft. 1. You drive to a random address(es), accessible from the public premises (IP). 2. You knock on the door (TCP SYN). 3. Someone comes and opens it for you (TCP SYN+ACK). 4. You ask what's here (VNC handshake). 5. You're told it's a power plant or doctor's office or whatever (VNC frame data). 6. Sometimes the replies aren't fun, sometimes it's really weird - some pal seems to be willing to control a nuclear reactor for you, no questions asked. 7. You blog about your experience, including a conversation transcript. It could be wrong to publicly announce (step 7) that there's a weird person in there (with full address details) that can do anything for you, as this can put others in danger. It's ethically unclear: it requires a human review and judgment (a robot can't tell if it's weird, so if data collection is fully automatic and unsupervised it becomes complicated), and even for humans it's probably not completely wrong to disclose, if done responsibly. But just driving by and knocking on the random doors asking what's there - it would be really weird to me if we'd say this is anything wrong with this.
- barbs 11y agoIsn't that victim-blaming?
- ctpide 11y agoPretty sure theft is still theft, even if the door was unlocked. Of course negligence can make it your fault, but even if you find a million dollars on the street - legally - it's not yours.
- colejohnson66 11y agoSure, but when Target, LinkedIn, et. al. are hacked, why don't people blame them for poor security practices? It's always the "hacker's" fault. Sure, it's wrong to exploit those weaknesses, but so is robbing an unlocked store. The hacker (robber) is still wrong, but only in the physical world do people put some blame on the "hackee" (store).
- onion2k 11y agoSure, but when Target, LinkedIn, et. al. are hacked, why don't people blame them for poor security practices? Security is hard. Blaming the victim of a hack is pointless because usually you have no idea whether they did something wrong or if they were the target of a particularly clever attacker.
- hobs 11y agoMaybe when the victim isnt a billionaire organization that is true. In the case of these large corps being hacked, they are 100% responsible, and most of them we do know how they got hacked; its usually through very humdrum (if organized) means.
- Karunamon 11y ago100% responsible? The hackers that hacked them have no blame whatsoever?
- colejohnson66 11y agoSure, but when you find plain text passwords or unencrypted credit card info (two of the basics of starting ANY business), victim blaming seems warranted.
- BinaryIdiot 11y ago> I think we need some sort of awareness day for the general public to understand what internet security _really_ is. Nope. This would never work. People don't understand how much of it works. Taking a day out of the year to explain / re-explain isn't going to do a single thing. Instead you need to make computer classes mandatory in K-12 and get people educated on how they work so they can understand the issues. Take a topic you know absolutely nothing about. Let's say it's aerospace. Now every year we have an aerospace day to try and explain to you how various types of fan and jet engines work. You certainly wouldn't expect everyone to be able to handle fixing one after that one day, do you? Same with internet security. > owner left the front door unlocked, people would rightfully put the onus mostly on the store owner. So just because the store owner does something stupid you think most people would consider it his fault? That's...that's horrible. Yeah he possibly could have prevented it (though you don't actually know that as they could have broken in anyway; people don't just go up to stores at night to randomly test doors then go home).
- milesf 11y agoSchool District policies and (ultimately) curriculum are driven by public opinion. How can a public demand better if they are not able to understand the issue?
- thaumasiotes 11y ago> Now every year we have an aerospace day to try and explain to you how various types of fan and jet engines work. You certainly wouldn't expect everyone to be able to handle fixing one after that one day, do you? Same with internet security. Actually, I'd expect a lot of increase in awareness of what the relevant issues are. No, I wouldn't expect someone exposed to aerospace day to be able to fix a jet engine. But they're much more likely to know what problems commonly occur and who can fix them.
- bnegreve 11y ago> Take a topic you know absolutely nothing about. Let's say it's aerospace. Now every year we have an aerospace day to try and explain to you how various types of fan and jet engines work. You certainly wouldn't expect everyone to be able to handle fixing one after that one day, do you? Same with internet security. People don't interact with jet engines, but they do interact with planes. And they're lectured about airplane safty evey single time they get in a plane. So this might actually be an argument in favor of educating people about internet security. Bottom line: please don't overuse analogies. They don't prove anything. Edit: simplify
- biot 11y agoIt's a nice thought, but I suspect it to work as well as "safe electrical circuits" day would. The internet security equivalent is that companies are selling completely unsafe circuitry with live wires exposed, and we should mount an education campaign to teach people how to cover up the live wires. I suspect once the hardware/software industry matures, we'll see insurance companies become involved and there will be strict regulation around what is and is not safe.
- cm2187 11y agoAnd their insurance wouldn't cover them if they didn't lock the door.
- smt88 11y agoThat just isn't true. In fact, your homeowners insurance will cover your belongings even if they're in your unlocked car when they're stolen. Most home burglaries involve breaking a window or kicking in a door, which is why people say "locks just keep an honest man honest".
- cm2187 11y agoMust depends on jurisdictions then.
- nommm-nommm 11y agoIt depends on your policy. I can't remember what it's called but my insurance polcy has a clause that I have to do what a "reasonable" person would do to secure my belongings.
- smt88 11y agoReasonable people don't have their doors locked all the time. Maybe they should, but mistakes and oversights happen Edit: After some additional research, people on message boards pointed out that many home invasions are done with lock-pick kits, or the burglar breaks a window and unlocks the door. Homes are often broken into without any damage to the lock or door, so the insurance company would never even know if you locked the door or not. It just doesn't come up in the investigation.
- makomk 11y agoPretty sure people have had insurance claims refused in the UK because there was no visible sign of forced entry.
- 11y ago
- ekianjo 11y ago> Yet if some brick-and-mortar business is robbed because the owner left the front door unlocked, people would rightfully put the onus mostly on the store owner. No, there were days when people did not even lock their cars and their houses (but maybe you are too young to have known that time where you live) because it was not expected that anyone would actually rob anything. Especially in communities where everyone knew everyone else. And if a robbery happened, the blame would still have been put on the thief, not the owner.
- jakub_h 11y ago> No, there were days when people did not even lock their cars and their houses That must have been an extremely long time ago: http://www.ancientresource.com/lots/roman/romankeys_locks.html http://www.ancientresource.com/lots/roman/romankeys_locks.ht...
- sqren 11y agoJust because locks have existed for thousands of years doesn't mean they are used everywhere. When I lived on the countryside in Australia we didn't lock the doors. That's not "an extremely long time ago" ;)
- jakub_h 11y ago> When I lived on the countryside in Australia we didn't lock the doors. Well of course you don't; the robbers die while still crossing the perilous deserts and/or trying to avoid lethal wildlife.
- ekianjo 11y ago> That must have been an extremely long time ago: http://www.ancientresource.com/lots/roman/romankeys_locks.ht.. http://www.ancientresource.com/lots/roman/romankeys_locks.ht.... Nope. I can tell there are still people alive these days who remember that this was still the case in most places of Western Europe.
- yoha 11y ago
- Kiro 11y agoDownvoted you because of that edit.
- milesf 11y agoI don't understand what was so downvotable about my edit.
- MrJagil 11y agoComplaining about downvotes is usually frowned upon, as are phrases like "when did HN become so PC".
- milesf 11y agoYes, just had someone send me the link to the HN Guidelines https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html Makes sense. I will conduct myself differently in the future. Cheers :)
- hrktb 11y agoThe latest episode of ATP[0] had a section at the end about people roaming in the neighborhood checking car doors to see if any cars was unlocked and steal stuff when hiting the jackpot. The owner of the car can blame himself for forgeting to lock the car, the insurance won't blame anyone but won't pay for reparation, the justice system puts the blame on the thief but would not do much about it if it's petty. And of course if it was a bank leaving bags of notes on an unlocked cabinet in the entrance, people would go bat-shit about irresponsible behavior on the banks side. I feel that's how it would go for the online world as well.
- golergka 11y ago"Blame" is a complicated concept entangled with morality that a lot of people have conflicting and illogical opinions about. I think that unless you want to start conversation about what "blame" is, it's safer to use words describing strict logical causation instead. Unlike "blame", causation is objective and doesn't depend on morality.
- milesf 11y agoI didn't use the word "blame" :/
- dave2000 11y agoStuff should be secure by default. No default passwords. No open by default. Temporary dialing down of security should reset itself to secure mode by itself after a short time. Etc.
- dang 11y ago> Wow. I'm being modded into the basement. When did Hacker News become so PC? Victim-blaming? Seriously? It breaks the HN guidelines to do this in comments here, so please don't. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html