5 ms·
The web seriously sucks. One thing I admire, at least in theory, about Xbox 360 games or iOS apps is the limited access a specific program can run. https://www
by hellbanner 9y ago
The web seriously sucks. One thing I admire, at least in theory, about Xbox 360 games or iOS apps is the limited access a specific program can run.
https://www.youtube.com/watch?v=CiqioE1zGCw https://www.youtube.com/watch?v=CiqioE1zGCw talks about this
Why is the overwhelming majority of networked software still not secure, despite all effort to the contrary? Why is it almost certain to get exploited so long as attackers can craft its inputs? Why is it the case that no amount of effort seems enough to fix software that must speak certain protocols?
The answer to these questions is that for many protocols and services currently in use on the Internet, the problem of recognizing and validating their "good", expected inputs from bad ones is either not well-posed or is undecidable (i.e., no algorithm can exist to solve it in the general case), which means that their implementations cannot even be comprehensively tested, let alone automatically checked for weaknesses or correctness. The designers' desire for more functionality has made these protocols effectively unsecurable.
In this talk we'll draw a direct connection between this ubiquitous insecurity and basic computer science concepts of Turing completeness and theory of languages. We will show how well-meant protocol designs are doomed to their implementations becoming clusters of 0day, and will show where to look for these 0day. We will also discuss simple principles of how to avoid designing such protocols.
EDIT: Sandstorm was looking to fix user permissions for individual programs on computers (they went defunct/bankrupt/no-longer-developing last I heard).
What I'm looking for is a user-facing, user-friendly structure that A) Does only what the user wants to do eg. load site B) Explicitly does NOTHING else eg run javascripts for cryptocurrency.
How could this work? Maybe your SecureBrowser*tm would only run Javascripts that have their hashes, and the hash of all the simultaneous Javascripts running on that page, approved by a network. Your client frequently checks this blockchain (why not) to download the latest approved scripts.
- crooked-v 9y ago> What I'm looking for is a user-facing, user-friendly structure that A) Does only what the user wants to do eg. load site B) Explicitly does NOTHING else eg run javascripts for cryptocurrency. https://chrome.google.com/webstore/detail/umatrix/ogfcmafjalglgifnmanfmnieipoejdcf?hl=en https://chrome.google.com/webstore/detail/umatrix/ogfcmafjal...
- hellbanner 9y agoWish there was open-source browser that did this, with SecureBrowser*tm concept in my above post to automate this. This is a step in the right direction and does satisfy the 2 basic requirements I listed for more security, thanks for sharing!
- JetSpiegel 9y ago> Wish there was open-source browser uBlock works on Firefox too. Can't get more open shots than that.
- hellbanner 9y agohttps://www.ublock.org/ https://www.ublock.org/ for anyone interested
- kentonv 9y ago> EDIT: Sandstorm was looking to fix user permissions for individual programs on computers (they went defunct/bankrupt/no-longer-developing last I heard). I'm still developing, just not full-time.
- brailsafe 9y agoNice job on that house you have there. Looks like you might even be able to play Warcraft 3 over LAN without spending the entire party trying to get it set up.
- brailsafe 9y agoEdit: Though irrelevant to the thread, this is not intended to be backhanded. Check out the house. It's pretty cool.
- hellbanner 9y agoI'm glad to hear this! Thank you for working on Sandstorm.
- rmrfrmrf 9y ago1) The system you’re describing wouldn’t have prevented this. 2) Just use NoScript if you’re that paranoid.
- hellbanner 9y agoWhy would it not have prevented this? If my browser only ran approved Javascripts, it wouldn't be mining coins.
- KGIII 9y agoWhen you get a spare half hour to figure it out well enough, add the uMatrix extension to your browser. It is like an old-school software firewall, except it is for your browser. There is a learning curve, but it's fine once you get up to speed. It's a bit like NoScript, but on steroids.
- mercer 9y agoSeconded! I find uMatrix terribly unintuitive, but once I figured it out it's my most crucial Chrome extension other than uBlock (and Hacker News Enhancement Suite, perhaps).
- pcwalton 9y agoThe Web with a gatekeeper isn't the Web anymore. If you want a curated walled garden, App Stores are readily available and have tons of content.
- _Codemonkeyism 9y agoBecause C.
- jlarocco 9y ago> Why is the overwhelming majority of networked software still not secure, despite all effort to the contrary? Why is it almost certain to get exploited so long as attackers can craft its inputs? Why is it the case that no amount of effort seems enough to fix software that must speak certain protocols? That's interesting, but I'm not sure it's relevant here because downloading and executing arbitrary code without understanding what it does is a fundamentally insecure thing to do. Unfortunately, the same technology is used by Facebook, Google, etc. to track people around the internet, so it's unlikely to get "fixed" any time soon.
- pocketsquare2 9y ago> In this talk we'll draw a direct connection between this ubiquitous insecurity and basic computer science concepts of Turing completeness and theory of languages. We will show how well-meant protocol designs are doomed to their implementations becoming clusters of 0day, and will show where to look for these 0day. We will also discuss simple principles of how to avoid designing such protocols. Sounds like you want the next-gen version of what https://en.wikipedia.org/wiki/Project_Xanadu https://en.wikipedia.org/wiki/Project_Xanadu was supposed to be. Unfortunately while you were discussing the above with like-minded peers other people were shipping things that users (not designers, users) want. The latter always trumps the former. I agree with you philosophically - how could you not - but how do you have your cake and eat it, too, in this regard? Xanadu was impossible enough, and expecting to have all its trappings with the best parts of TimBL seems like the recipe for a classic Borges tragicomic short story.
- cocktailpeanuts 9y ago> Why is the overwhelming majority of networked software still not secure, despite all effort to the contrary? Why is it almost certain to get exploited so long as attackers can craft its inputs? Why is it the case that no amount of effort seems enough to fix software that must speak certain protocols? This is a super naive view of the world. Nowadays most hacking incidents are based on social engineering, meaning it's not the technology that's weak, it's humans who are the least secure. Yes that includes you and me. So NO, your solution won't fix anything. Believing that a technical solution can fix everything is the most dangerous thing because in reality it will never be safe but you just have a false sense of safety, which is how most hacks happen--most hacks are carried out by taking advantage of this mentality that everything is safe enough, which in reality isn't. You will probably believe that the system you designed is super safe because it only lets people do what they said they wanted to do, but as I said, most hacking incidents are social engineering, so someone will definitely take advantage of this and attack you where you least expect it.
- hellbanner 9y agoSocial engineering is responsible for in part or entirety many hacks. I'm not arguing that technical solutions will "fix everything". Technical stability is on aspect of secure systems. The video is arguing: why should a doorbell have the ability to set your house on fire? (Metaphorically). Heartbleed was an issue of exactly this "The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software" Architecturally, this should never have been possible. http://www.pl-enthusiast.net/2014/07/01/how-did-heartbleed-remain-undiscovered-and-what-should-we-do-about-it/ http://www.pl-enthusiast.net/2014/07/01/how-did-heartbleed-r... http://heartbleed.com/ http://heartbleed.com/ Obviously attackers are going to look for the weakest point, but your agument sounds like "social engineering should happen, so don't bother locking your doors at all".
- cocktailpeanuts 9y agoNo i was only arguing it's not as easy as you think. Just like your solution you suggested can easily be hacked, any technological solution a human being comes up with is vulnerable to hacks. The only thing I was criticizing was you seem to think it's easy to simply create a secure system. It's not. That's why there are tons of smart people in security but hacks still happen.
- deleted 9y ago[deleted]
- pdkl95 9y ago> "The Science of Insecurity" The langsec approach of using formal recognizers that validate the validity of input before processing it in any way (stop creating weird machines!), and designing network protocols that are actually decidable without solving the halting problem (network input must be no more complex than deterministic context-free) should be considered the bare minimum for all network-associated software. It won't solve all security problems, but we should at least be handling the problems we know how to solve. Anything less should be considered severely unprofessional, and at least civilly negligent. > The web seriously sucks. Dan Geer discussed his terrifying visions of the future in a recent keynote[1][2]. The suck extends far beyond the web; "Cybersecurity and the future of humanity are conjoined". He gives many examples that demonstrate just how bad the suck is, and how ill-prepared the world is for these looming problems - at any level of society. > The cumulative effect of the curves for computing, storage, and bandwidth is this: in 1986 you could fill the world's total storage using the world's total bandwidth in two days. Today, it would probably take nine months of the world's total bandwidth to fill the world's total storage, but because of replication, synchronization, and sensor-driven autonomy, it is no longer really possible to know how much data there is. Decision making that depends or depended on knowing how much data there is is over. > The execution space on the web today is that the client is the server's server, its bondsman if not concubine. You intake Remote Procedure Calls (RPCs) from everywhere and everyone. You are supposed to believe that trust is transitive but that risk is not. That is what Javascript does. What is the solution? > To be deadly serious about cybersecurity requires that --EITHER-- we damp down the rate of change, slowing it enough to give prediction operational validity --OR-- we purposely increase unpredictability so that the opposition's targeting exercise grows too hard for them to do. In the former, we give up many and various sorts of progress. In the latter, we give up many and various sorts of freedom as it would be the machines then in charge, not us. Either way, the conjoining is irreversible. I'm wondering how bad this will get before the masses declare a Butlerian Jihad. I personally know a handful of people that already use a revolt against technology as their primary political belief. [1] https://www.youtube.com/watch?v=hcIiD4UUDE8 https://www.youtube.com/watch?v=hcIiD4UUDE8 [2] http://geer.tinho.net/geer.rapid7.14ix17.txt http://geer.tinho.net/geer.rapid7.14ix17.txt
- pdkl95 9y ago