4 ms·
Security is not "magical," no. In fact it's barely even a "property of software." Instead it's a property of a system. Some of the elements of this system are s
by sirclueless 10y ago
Security is not "magical," no. In fact it's barely even a "property of software." Instead it's a property of a system. Some of the elements of this system are software. We can perhaps make some guarantees about the properties of this software, but these alone do not make the system secure (systems that are provably secure end-to-end are vanishingly rare, if they exist at all). Part of the system is configuration and data. What cryptographic keys and other systems do you trust, and how do you guarantee that trust? Part of the system is human process -- when a customer calls support, does someone give up private information or allow passwords to be reset? If the government knocks on the door of your cloud hosting provider, will they cooperate freely? When your linux distro announces a security issue to a trusted list ahead of a public announcement, do you have someone on that list ready to respond to the issue before your server is hit by a 0-day?
There's a lot that goes into making a secure system. And there is considerable economy of scale -- a large company can afford to have 24/7 monitoring and issue escalation processes. You cannot.
- zAy0LfpBZLC8mAC 10y ago> We can perhaps make some guarantees about the properties of this software, but these alone do not make the system secure (systems that are provably secure end-to-end are vanishingly rare, if they exist at all). Which applies equally to gmail. > If the government knocks on the door of your cloud hosting provider, will they cooperate freely? Which applies equally to gmail. > When your linux distro announces a security issue to a trusted list ahead of a public announcement, do you have someone on that list ready to respond to the issue before your server is hit by a 0-day? Which can be automated. > There's a lot that goes into making a secure system. And there is considerable economy of scale -- a large company can afford to have 24/7 monitoring and issue escalation processes. You cannot. And you don't need to. If you don't need to do this with your email client, you also don't need to do this with your email server. Also, there is also a major economy of scale to compromising google instead of your personal email server. No, of course, there is no "perfect security" (whatever that is). And that's true for both gmail and self-hosting. But it is perfectly possible to write an email server that's very unlikely to be exploited surprisingly into remote code execution as a single developer.