5 ms·
That's a very insightful take. When you say "apathy of users" are you speaking of "higher level" users like CIOs and network admins or just the end users / aver
by drvdevd 10y ago
That's a very insightful take. When you say "apathy of users" are you speaking of "higher level" users like CIOs and network admins or just the end users / average users in the network or both?
It may be a truism or cliché but it seems correct from my perspective as a "devops type": security is a losing game in favor of attackers due to asymmetry between attack and defense.
Perhaps automation will change that? :)
- nickpsecurity 10y ago"When you say "apathy of users" are you speaking of "higher level" users like CIOs and network admins or just the end users / average users in the network or both?" All of them. There were secure computers far back as Burroughs, which was successful. http://www.smecc.org/The%20Architecture%20%20of%20the%20Burroughs%20B-5000.htm http://www.smecc.org/The%20Architecture%20%20of%20the%20Burr... The drivers of most of the computing industry were more features and speed at lowest cost. Quality or security meant less of that. Tradeoff began there. By about 80's, we mostly knew how to secure computers from specs down to CPU. Market demand was so non-existent almost nobody was producing them. Per one of INFOSEC's inventors, Roger Schell, there was some demand by CIO's (?!) but they believed IT industry intentionally left bugs in products to sell them fixes & would never sell them bulletproof stuff. So, maybe they weren't dumb. ;) By 90's, DOD's Computer Security Initiative that promised to only buy secure products for certain stuff plus TCSEC critera for building them led to a number being on market. Almost nobody in DOD or regular market bought them. Rinse repeat with only a few niches doing higher assurance with high unit price due to low volume: safety-critical like aerospace, a few companies selling to military, TEMPEST industry, HSM vendors, and some smartcards. Smartcards being exception to low volume & high price. Even most on that list have been lowering amount of assurance & increasing risky features due to market demand. Now, let's look at user side. Vast majority of time users get to choose between a secure/private or insecure/surveillance-oriented product they will choose the latter. Just look at whose dominating in messaging, storage, thin clients, remote access, calenders, document formats, etc. Almost got an exception in browsers with Chrome, based on OP Web Browser that was secure, but they watered down security because they knew demand-side wanted blazing fast over kind of fast but secure. There's now privacy-oriented, easy-to-use apps for various things on smartphones for $1-10. Desktop stuff free or even $5 a month on critical functions that are still easy to use. Almost nobody uses these even when they get a lot of press. So, it seems demand for actual security is almost non-existent even when it gets main function done, performs acceptably, is plug-and-play, and is inexpensive to free. I mean, if they don't care at that point, what can you do? I think it's a fatal flaw of human nature in the way people's minds make tradeoffs. Now, I encourage people to instead get into established companies in senior roles or do startups where the product is good, people use the heck out of it, it stays competitive, and you just bake security into it. Or just avoid INFOSEC altogether for something not set up to fail. :) "Perhaps automation will change that? :)" I had some hopes for that. There were tools like 001 Toolkit by Hamilton, various 4GL's, logic programming, and so on that basically let you specify the problem where the tool would do everything else. One could do something like that which embeds good security into it. Opa language does that for web apps as an example. Additionally, the automated analysis tools for code with or without annotations are getting really good. They're at a point where users almost does no work. They also get almost no adoption even by companies that "care about quality." ;) Anyway, machine learning that studied tons of annotated codebases to learn what annotations go with what code patterns might result in tools that correctly annotate new code & just run in background of build process. There's potential there but manual effort will still be required due to false positives/negatives. And new domain logic. So, there's some brainstorming on that.
- petra 10y agoThe problem with selling for consumers is simple: it's hard to achieve credibility. On the one hand, anti-virus software , that we all bought, sucked. So we don't have much trust in security vendors. On the other, after hearing about the crazy stuff hackers do, like stuxnet or the more trivial daily privacy news, make people think the task is impossible. And even what's possible - it's hard to quantify benefits. Combine that with network effects , the marketing power of free apps and default apps, and the complexity of it all - it's natural that most users don't the time/money to spend on this.
- nickpsecurity 10y ago"The problem with selling for consumers is simple: it's hard to achieve credibility. " I probably need to think on that angle more for the consumer side.