3 ms·
If the devices I care about are secure (laptop, phone etc) then I shouldn't have to care about other devices, whether they're on my home network or not. I'm in
by superflyguy 8y ago
If the devices I care about are secure (laptop, phone etc) then I shouldn't have to care about other devices, whether they're on my home network or not.
I'm in no way a security/network export and I'm sure the people who came up with the current specs were smart people doing their best but it always seems a bit shit to me. I can send death packets to any device even if I'm not attached to the network and they're just honoured? Really? Was all this stuff created in a time when nobody actually considered bad people?
- TeMPOraL 8y ago> Was all this stuff created in a time when nobody actually considered bad people? Yes. The Internet was designed in times where the primary worries were a) nuclear attacks causing major disruptions in the infrastructure, and b) pranksters. You can see that in the design of protocols, which assume all actors are participating in good faith. A lot of pieces of the Internet we still use were created for research community, where the default assumption was that everyone is acting benevolent (and if someone wasn't, they could be found and punished quickly through out-of-band means). I don't think anyone back then could ever imagine the amount of clueless, careless and evil people the commercialization of the Internet would bring to the network. Tangentially, this is also why we're stuck with programming in environments subpar compared to what we had in the 70s. The level of control people had over their OS and software also implied total lack of security.
- pdonis 8y agoThe Internet was originally designed in such times. But all of these IoT devices that accept unauthenticated commands from anywhere were not.
- TeMPOraL 8y agoI assumed GP asked about the network itself. Sure, IoT devices are created today. But they follow defaults (which are insecure), because IoT vendors are cheap.
- superflyguy 8y agoYes, the network itself primarily and the way devices connect over it. Perhaps we'd need to start over? When I'm at work people get shouty if you just bring a laptop in and plug it into the network. "If they find out you'll get in trouble". Why wouldn't they find out? And why aren't devices whitelisted so you simply connect without prior approval?
- TeMPOraL 8y ago> Perhaps we'd need to start over? Maybe. But if we do, I'd love if there were allowances in the new design for creating isles where everything flies, and security is very low. I have two reasons for that: One, security is - to some extent - mutually exclusive with capabilities. When everything is sandboxed and end-to-end encrypted, I can't inspect what a piece of software is doing, and I can't write code to make that piece of software do what I want. This flexibility is needed to make one's workflow efficient, and one's problems solvable (at least without waiting for someone else to solve them). Two, hardening security has the distinct tendency for enabling vendor overreach and lock-in. The same techniques that secure your data from evil third parties can be used to secure "your" programs from you.