3 ms·
I hate to break it to you, but "uniform" security standards that are out there in the open would be like a whole can of worms. That is like showing someone "he
by tamar 10y ago
I hate to break it to you, but "uniform" security standards that are out there in the open would be like a whole can of worms.
That is like showing someone "here's a lock and what's inside of it."
In time, someone will pick that lock.
Uniformity is what you don't need, nor would you want to know the nuances of how security and privacy are handled at a company so that you know exactly what holes need to be exposed.
You can't standardize security. It's way too risky.
- gherkin0 10y agoYou're basically advocating for security through obscurity. A standardized process design could be carefully examined and improved to plug the holes, so all you're left with are implementation bugs. You'll never get there with a thousand disparate processes: they'll have design and implementation bugs, as well situations where system compromises data used to secure another. Plus, standardized processes would allow implementation of more expensive processes. For instance, you could have a higher-grade fallback "prove who you are" process that involves going to some designated office in-person with all the right documents. Not even Google would pay to setup such offices in every city, but if Google, Amazon, Online Banks, etc. all would use it, it might be possible.
- tamar 10y agoThat's exactly what I'm advocating. Standardization would expose millions of people to policies that can be exploited in time. It's better for all of us not to know. I know, this is an issue some would disagree with. I do not think it's safe to standardize at all.
- neohaven 10y ago"Here's a lock and here's what inside it, but you still can't break it because you lack a separate secret of no mechanical relevance" is the only way to make a system secure. If it is possible at all, you WANT a system where knowledge of all the mechanics do not allow people to crack the safe. See encryption. A secure crypto mechanism is not vulnerable to disclosure of its mechanism. The key is the secret. The mechanism is not. Having a secret mechanism that relies on its own secrecy means your main weakness is someone explaining how it works to the outside world. RSA is perfectly well-known. So is rot13. rot13 is crap, disclosure or not. RSA is not as crap, disclosure or not.
- pfarnsworth 10y agoOf course you can standardize security. This means that the same authentication methods would be used across the industry, and the agents would be trained to not leak those details through social engineering, etc. It would mean that there would be standards with respect to what information tier 1 agents have vs tier 2 agents, etc, with proper separation of duties, so that poorly trained tier 1 agents wouldn't have the ability to be socially engineered. Your method of security through obscurity simply doesn't work because hackers will figure it out and exploit impedance mismatches between vendors.