6 ms·
Reminds me of Steve Ballmer touting Windows XP as the "Most secure operating system ever" - on the day it was released. Claims that a code is unbreakable or ha
by 4ensic 8y ago
Reminds me of Steve Ballmer touting Windows XP as the "Most secure operating system ever" - on the day it was released. Claims that a code is unbreakable or hacker proof are big red flags.
- rhokstar 8y agoVery, very true! By proclaiming "Can’t Be Hacked" is an invite to the world.
- dmarlow 8y agoCorrect. Also claiming that it's mildly secure is also inviting hackers. Damned if you do, damned if you don't.
- deleted 8y ago[deleted]
- dormento 8y ago"Our very strength incites challenge. Challenge incites conflict. And conflict breeds catastrophe."
- close04 8y agoThere must be something in between right? Like... "secure"? Claiming "hacker-proof" isn't just an invitation, it's a challenge. Nothing triggers people like telling them something is %-proof. The mathematical proof might be 100% solid and hacker proof. The implementation will probably never be.
- fuklief 8y ago> The mathematical proof might be 100% solid and hacker proof. The implementation will probably never be. I agree, I see a few ways that it could go wrong: - Code is proven correct against the specification, but specification is wrong/buggy - source code is correct/secure, but compiler is overzealous and botch the securities guarantees.
- gargravarr 8y ago- someone just outright botches the implementation. Heartbleed wound up in OpenSSL for years before anyone noticed.
- gargravarr 8y agoOracle Unbreakable* Linux *for certain definitions of 'unbreakable'
- Datenstrom 8y agoThis will be very good for the code. Attacking it will only make it stronger.
- baal80spam 8y agoWasn't it pretty secure at the time, though?
- EthanHeilman 8y agoPretty secure compared to what? It had some security features that windows 95/98 didn't have so in comparison to windows 98 it was more secure. However windows XP had a large number of critical vulnerabilities and weaknesses. A holiday sweater is more bullet resistant than a thin t-shirt, but no one would say a holiday sweater is "pretty bullet proof".
- fpgaminer 8y agoCase in point: https://en.wikipedia.org/wiki/Blaster_(computer_worm) https://en.wikipedia.org/wiki/Blaster_(computer_worm) That virus was running around the internet for years; kept alive by the "most secure operating system ever". In the immortal words of the virus: "billy gates why do you make this possible ? Stop making money and fix your software!!"
- taborj 8y agoAgreed. I would posit that it can't possibly be "hacker-proof" if it hasn't been released into the wild and put in front "hackers."
- xxxdarrenxxx 8y agoOne could make the argument though that as CEO at the time, even if he'd knew flaws, how could he from his position advertise "insecure but it looks nice!". Do you think he would keep his job? Elon Musk is a good example what happens when a CEO is making solo statements.
- miloignis 8y agoTo be fair, formally proving that it contains no buffer overruns, timing differences, or memory access differences does make it immune to many/most of the standard hacking vulnerabilities.
- bcaa7f3a8bbc 8y agoFirst, the title of the article is typically from Quanta Magazine, which often uses editorialized clickbait titles to popularize scientific topics. Today, even Nature Communications seem to do it occasionally. If these claims are not directly from the official project, I don't see any red-flag here, it's an legitimate research project on formal verification. On second thought, I think deliberately releasing a PR advertisement which claims a system is "unbreakable" can be a good way to receive free security audits. So perhaps EverCrypt as a free and open source project who understands this point, the developers deliberately allowed Quanta Magazine to use this title, and so far, it has successfully received the attention of at least 5 HN users...