16 ms·
Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes th
by jhiska 9y ago
Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company.
We're going back to pen and paper. The extra safety makes the hassle worth it.
- mulmen 9y agoWhat makes you think pen and paper is secure?
- blattimwind 9y agoPen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read. However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.
- mulmen 9y agoWho gets keys to the cabinet? How do you know they haven't been duplicated? What if there is a fire? Do you keep a copy of the files somewhere? How do you control access to those?
- blattimwind 9y agoYou get literally the exact same set of problems with computers, plus all problems computers bring to the table for free.
- mulmen 9y agoYou're pretending pen and paper doesn't bring another set of problems of its own.
- blattimwind 9y agoNo, I'm just not exhaustively listing the advantages of computers, because (i) not what this thread is about (ii) by and large we're aware of them.
- hinkley 9y agoDid you let Richard Feynman into the building...
- viraptor 9y ago> Pen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read. On the other hand, also the bad part is that pen and paper require actual physical access to read ;)
- jhiska 9y agoBecause you can't easily get away with several million documents in your trenchcoat. A data breach would be catastrophic for us. We lose less money this way.
- mulmen 9y agoDo you? Can a business that runs on pen and paper compete in 2018? Have you included lost revenue due to inefficiency?
- birdman3131 9y agoYour assuming they did not sneak a small camera in.
- cookiecaper 9y agoPhysical security is not necessarily automatic, but it's much more straightforward than computer security. You don't have to worry about someone in Russia getting a hold of your pen and paper while you're sitting there with it in your room. I think that anyone who has worked professionally understands that it's a miracle we make it through life with the relatively limited quantity of exposures and accidents that we have. Things like Spectre/Meltdown usually don't get the notice of people who care to expose it publicly until they've been privately theorized, discussed, and practiced in some form for many years. Personally I believe that if Spectre had come out 10 years prior, the likely response from Linus et al would've been "How about instead of crippling useful CPU speed optimizations, we just don't let random people feed instructions to our CPUs." Obviously, with cloud computing underpinning so much critical profit/surveillance-- uh, I mean, infrastructure-- these days, that won't fly. (Meltdown is a different story since the CPU is supposed to be protecting that.) Computers are very complex systems designed by people. Work with more than 5 people and you quickly learn how much trust is warranted in complex systems designed by people (hint: very little). I absolutely believe that relying on the security properties of the physical world, particularly "this item cannot exist in more than one place at a time, nor can it be replicated and transmitted across the earth in under one second", is much more reliable than any computer security. Pen and paper is the only way to go for the truly paranoid.
- jacquesm 9y agoI would not at all be surprised if Spectre and Meltdown were already known at nation state level, they have a lot of resources to throw at problems like this. The fact that Google provides this service for free is an amazing counterbalance to that kind of power, the bugs don't magically disappear but at least the playing field has been leveled a bit.
- blattimwind 9y agoIt is my impression that analysis of side channels has been done and professionalized in the intelligence community for a long time before it became an important consideration in the general IT community.
- anarazel 9y agoThe big differentiator is how attacks can be scaled. Most people/companies aren't individually a worthy enough target to develop an attack against a reasonably protected system. But with a lot of these types of attacks one can compromise a large number of systems in a largely automated manner, without risking ones personal physical security.
- guy98238710 9y agoWhat prevents attackers from collecting photos of the papers with nearby phones, security cameras, or even a fleet of tiny drones?
- ahakki 9y agoCost
- guy98238710 9y agoSo it's possible and it's just a matter of optimization. Pens and typewriters leak data acoustically, so let's replace cameras with microphones to reduce costs. Tiny microphones with antennae can be mass produced cheaply and they are easily hidden. Delivery can be automated too, but it's much easier to embed the spy devices in common products people frequently buy.
- madez 9y agoIf you stay with a system that is as open as possible from the lowest levels of the hardware to the highest level of the software, and if you airgap, and audiogap, and RF-gap the system permanently until it ceases to exist, you are pretty fine. Also, more practically, two computers with different ISA and underlying hardware that compute the exact same high level semantics, that don't know each other but transparently share the necessary hardware (for example hardware random number generator), talking to the world through a simple electronic checker, that stops the system if both computers don't communicate exactly the same information bit by bit, is also pretty safe, even if you use backdoored computers. Just make sure both computers don't contain identical backdoors (which is not that difficult). High and sufficient security in computer systems is practically possible. We just don't work at it. Instead we work on JavaScript and WebAssembly and proprietary hardware and software.
- iforgotpassword 9y agoHah so basically not at all more involved than when we still assumed modern platforms are just safe and trustworthy. Phew.
- madez 9y agoAt least the second part, the system of the two computers and the checker, is compared to even the very simplest parts of a modern computer laughibly simple.
- jhiska 9y agoOr just use pen and paper. It's an easier tech for Joe Dilbert and easier for them to understand how to keep it secure.
- craftyguy 9y agoHonestly, not really. You'd be surprised how much valuable information people leave laying on their desks. Or loose-leaf in a backpack that is half zipped. Or in their pockets. Or on their car seat. The list goes on.
- comboy 9y agoComputer security has been ridiculous for quite some time. Your only chance is tons of layers and early detection that something's not OK. I'm really happy that everything that's happening is happening. Sad that things like Cloudbleed got so little attention outside HN-like circles. I'm happy because it's gonna have to change. Whole stack revisited. Eventually. These things speed it up. On the long run, the thing that holds most value, in my opinion, is information. Not physical things, not energy, information. Bitcoin is a big step in that direction but I don't just mean cryptocurrencies. If you can't keep your information secret the value is destroyed. I see two paths. One, we do a huge refactoring of how do we do computations. Super clear assumptions and provably building simple layers on top of that. I'd like that. The other one is that we keep this whole messy legacy. And security will become based on more and more layers and heuristics. Which would eventually become AIs competition. Brr. Just some random ponderings, I'm not a security expert.
- cookiecaper 9y ago> I'm happy because it's gonna have to change. Whole stack revisited. Eventually. I used to believe this kind of thing, but now I think you greatly underestimate human indifference and interest in effort conservation (uncharitably called "laziness"). Look at Intel's response to Spectre/Meltdown. Are they going back and redesigning their microarchitecture with new hardware-enforced safety rings [that actually enforce, lol] and new ways to block timing attacks without sacrificing performance? Seriously doubt it. From LKML it sounds like they're just going to hardware-accelerate IBRS/IBPB to make it faster to shut down branch prediction in risky situations and leave the rest of the shebang as-is. Even when the forecasted apocalyptic events occur, it's amazing how little anyone cares, or how little gets recognized. Surely there are people who've speculated (ha!) attacks like Spectre/Meltdown, given the knife's edge nature of hardware virtualization on x86, and advised against multi-tenancy. Surely there are people who have paid attention over the last ten years to the dozens of sandbox escape attacks that already exist without exploiting the microarchitecture! Are they getting their due? Is anyone asking why people didn't consider these possibilities or listen to the people who warned them? Nope, because they just don't want to hear that. It's all "Oh gee how could Intel have done this to us?!" when "How could you have acted like this was safe" is an at least equally valid question. TPMs, again, are another example of exactly the same thing. Major exploits in them are 100% routine by now. Does anyone care? Google is quietly working to remove them from their own machines but it doesn't seem like anyone is going to get any real headway outside of that. Do freedom advocates like RMS get their due? Nope, they just get told "Bugger off with your 'I told you so'." Have you ever spent months or years warning your bosses about something, only to have that thing happen, and watch them hand-wave it away and get extremely irritable after you mention that they had fair warning? Most semi-aware engineers probably have, because this happens constantly. Admitting, realizing, and honestly correcting our mistakes is just not a thing that people do, unless they feel substantial direct and personal pain that the brain decides greatly exceeds the forecasted effort expenditure to correct the issue. Such negative force cannot be applied over an industry at large unless there is a very specific and coordinated demand from the handful of people at the tippy-top, as in the case of Spectre/Meltdown, since in the age of cloud computing, those exploits fundamentally jeopardize the profitability of every major tech company.
- forapurpose 9y ago> We're going back to pen and paper. The extra safety makes the hassle worth it. I've read that, several years ago, parts of the Russian security establishment switched to mechanical typewriters.
- madez 9y agoYou might be talking about the following article: https://www.theguardian.com/world/2013/jul/11/russia-reverts-paper-nsa-leaks https://www.theguardian.com/world/2013/jul/11/russia-reverts... Even in Germany high officials hinted at using mechanical typewriters: https://www.theguardian.com/world/2014/jul/15/germany-typewriters-espionage-nsa-spying-surveillance https://www.theguardian.com/world/2014/jul/15/germany-typewr... Luckily, the politicians in Germany and Europe wake up. They want to build up European chip and hardware facilities to have the full chain in Europe. Also they plan to demand certification and customer visible labels. Finally! https://www.heise.de/newsticker/meldung/Prozessor-Luecken-Meltdown-und-Spectre-De-Maiziere-will-eigene-Schluesseltechnologien-staerken-3935037.html https://www.heise.de/newsticker/meldung/Prozessor-Luecken-Me...
- danieldk 9y agoLuckily, the politicians in Germany and Europe wake up. They want to build up European chip and hardware facilities to have the full chain in Europe. Also they plan to demand certification and customer visible labels. Finally! This is the same Thomas de Maizière that backed a law that allows German law enforcement agencies to order companies to insert back doors in their products: https://boingboing.net/2017/12/05/thomas-de-maiziere.html https://boingboing.net/2017/12/05/thomas-de-maiziere.html
- zby 9y ago"Luckily, the politicians in Germany and Europe wake up. They want to build up European chip and hardware facilities to have the full chain in Europe. Also they plan to demand certification and customer visible labels. Finally!" So far similar efforts by EU were rather underwhelming - but this one is probably the most important. I believe EU is the only global actor that can achieve the goal of creating reliable hardware and software. The still decentralized nature of EU means that no partner can afford any unilateral action (like backdoors) - and a conspiracy on the level of whole EU is impossible. And of course it needs to be Open Source.
- Decabytes 9y agoOr we could just get ME and PSP off of our chips like people have wanted for years. They have been major security and privacy risks ever since their inception.
- std_throwaway 9y agoSomehow this doesn't seem to be up for discussion.
- ams6110 9y agoPeople may have wanted but Enterprise customers like ME.
- katastic 9y agoIf you can afford to use pen-and-paper as an option, there's no way you're using your computers to their full (or even 10%) of their ability. People computing large amounts data don't have the luxury of hand calculations and the HUGE AMOUNT of errors that method entails. I have a client that has THREE levels of human validation of the SAME numbers (that the Dynamics NAV they're using could have calculated for free). Literally 1-2 full salaried persons worth of man-hours billed every year. Going backwards away from that, and using more humans, is even crazier. Their hours and errors would skyrocket.