4 ms·
> Countless computers secured by full time professionals have been hacked. And yet, the black hats who breach such systems often have an attitude like "Wow, su
by ythl 10y ago
> Countless computers secured by full time professionals have been hacked.
And yet, the black hats who breach such systems often have an attitude like "Wow, such a reputable organization has such sorry security. They deserve what I did to them".
Computer security is a black hole that will consume ever increasing amounts of money, memory, and cpu cycles, forever. What a waste.
- anf 10y ago> Computer security is a black hole that will consume ever increasing amounts of money, memory, and cpu cycles, forever. What a waste. That is defeatist and false. Computer security done intelligently can raise the cost of an attack above the value of what is being protected.
- cmdrfred 10y agoI agree, a well spent security dollar might make an attack cost $100 more for the assailant. It's classic attrition warfare[0]. [0]https://en.wikipedia.org/wiki/Attrition_warfare https://en.wikipedia.org/wiki/Attrition_warfare
- Spooky23 10y agoNo way. Computer security is like a tax whose returns diminish rapidly. Once you start prioritizing it with money on security vs product/system engineering, security starts turning into a money monster that delivers nothing. I've seen it happen time and time again. The asymmetric nature of raising the cost for an attacker is a red herring. You can pat yourself on the back that you've supposedly made it 100x more expensive to attack you, but one operational fuckup pops that fantasy bubble at any time.
- dom0 10y agoI have to agree here. Security in itself is highly asymmetrical, because any single flaw can prove fatal, even with the latest and greatest defense-in-depth techniques. Not to forget the many, many instances where security systems actively harmed / enabled attacks.
- mike_hock 10y agoSecurity is a black hole because it gets ignored at the design stage, it gets ignored during development, and then suddenly when in production, people try to secure their systems and, surprise, it doesn't work. Security isn't some orthogonal concern that can be developed or managed independently.
- elihu 10y agoIt doesn't have to be that way. Certain approaches like "hire a bunch of consultants" or "buy more security products" or "hire smarter people and tell them to be really careful" aren't going to fix the fundamental problems. I see two main issues, one technical and one economic. The technical problem is that we should be ruthlessly eradicating undefined behavior at all levels of our hardware and software stacks, and to the extent possible constructing applications out of building blocks that are very difficult to misuse. Among other things, this means not writing software in C or C++, which is a hard sell to a lot of people (especially if they're writing operating systems). The economic problem is that it's nearly impossible for a customer to know whether a product is secure or not. If secure products are more expensive to produce than insecure products and customers are not willing to pay more for secure products, the result is that insecure products will be more successful. (See George Ackerloff, The Market for Lemons.)