4 ms·
I hate to be negative, but I've been working in the security industry for several decades now and... the article reads to me like a collection of condescending
by f- 10y ago
I hate to be negative, but I've been working in the security industry for several decades now and... the article reads to me like a collection of condescending platitudes that attribute malicious intent or extreme incompetence to just about any person other than the author. Jumping back and forth between Snowden, PDF attachments, and C memory safety does not help.
The online world is not particularly horrible; we overwhelmingly use it by choice, not out of necessity, and the benefits far outstrip the risks. Sure, it's also far from being great, and the genuine difficulty of designing complex systems in a secure way plays a role in this (heck, between all the interested parties, we can't even really define what "secure" means in practical terms). But it's not because everybody else is dumb.
While I generally hate analogies like this, I think there are quite a few parallels between the online world and the physical realm, where we seldom settle on absolute security. You have a $10 door lock that can be opened with a paperclip, protecting probably in excess of $5,000 in electronics within your home. In that realm, we are far better accustomed to the trade-offs, in part because we have more intuitive data about what can go wrong. We also take a more dim view of a burglar than of a hacker, which makes us assign the blame a bit differently.
In any case, with online security in particular, there some paths forward, including fairly plausible incremental strategies (better UX in the browsers and operating systems, better developer guidance, better mitigations, a culture of fuzzing and other security testing as a part of QA, etc). There are also some ambitious revolutionary dreams ("New everything! In Rust!") that may actually pan out if enough people get behind them. But I'm not sure what this article is hoping to achieve.
- deleted 10y ago[deleted]
- jacquesm 10y ago> we can't even really define what "secure" means in practical terms I'd suggest a very practical approach here: A system is only secure if the value required to break it is higher than the value that can be obtained by breaking it.
- 0xdeadbeefbabe 10y agoWe can't even really define what value means in practical terms. Edit: Bank account information is valuable, but it's also one account number change away from being valueless.
- kordless 10y agoWe chose not to define what value means in practical terms, with Internet infrastructure. That is to say, we allow unlimited access to compute resources using conditionals, which themselves may or may not be valuable, or secure. By turning the golem on its head, and making compute resources use value to return value, we will eliminate this problem. That won't be easy and it won't happen immediately, but it will happen.
- gnopgnip 10y agoThe value of protected information is quantifiable. You can assign an average dollar value to a credit card number, SSN, or other information. There is automated software like solarwinds risk intelligence that can find this information on your network to help you either remove it or ensure it is not on unpatched servers.
- specialist 10y agoI'm amazed things aren't worse, that they work at all. Analogies to the real world are useful, mostly for expectation management. I know a few things about election integrity. Private voting, public counting. We can have all the laws, rules, procedures, transparency, accountability and so forth we want, to better prevent chichanery. But what makes it work (when it does) is buy-in, common culture, a shared suspension of disbelief. That this thing is important and worth preserving. Cliche: locks keep honest people honest. What keeps us (mostly) safe and secure is people's strong preference to simply being honest, to get along with others. Cheaters, cons, freeloaders are exploiting an evolutionary hack: people's innate sociability (trustfulness). To me, the greatest benefit of these security algorithms, crytpo, blockchains, etc. is to help us identify and mitigate the cheaters and freeloaders.
- mstade 10y ago> The online world is not particularly horrible; we overwhelmingly use it by choice, not out of necessity, and the benefits far outstrip the risks. Maybe this was true 20 years ago, but it increasingly is not. For example, there are many shops and other institutions in Sweden that no longer accept cash – only debit/credit cards or other forms of online payment. Whether you like it or not, dealing with the online world is often not a choice, and if it was there's a good chance it was made for you.
- MaxfordAndSons 10y ago> the article reads to me like a collection of condescending platitudes that attribute malicious intent or extreme incompetence to just about any person other than the author. She absolutely attributes extreme incompetence to herself several times. Like, multiple paragraph length anecdotes.