3 ms·
This is huge and is a subject I feel strongly about- especially for defense software. Parts of the US Government are already sounding the alarm over this. see-
by decoyworker 7y ago
This is huge and is a subject I feel strongly about- especially for defense software.
Parts of the US Government are already sounding the alarm over this. see- https://innovation.defense.gov/software/ https://innovation.defense.gov/software/
Basically, we are too slow. The contract acquisition process and waterfall development moves at a glacial pace. I have some serious doubts we will ever adapt since it would require a restructuring of the way our defense industry operates.
- ak217 7y agoPart of the NSA's mission (which they have failed at, and an acknowledgment of that failure is conspicuously absent from this article by the NSA's general counsel) is to help secure domestic information infrastructure against attack. They are supposed to lead the way in developing security standards, scanning for vulnerabilities, advising businesses and local governments on how to protect themselves. In a perfect world, Project Zero would have been based at the NSA. Instead they have let the wiretapping crew take over everything.
- asdfman123 7y agoWouldn't it be possible to build the next generation of technology to be much less hackable? Right now we're all pretty dumb about cybersecurity, but if plays a major hand in shaping human events even stodgy Pentagon types might start taking things like air gaps and not writing your passwords out on a sticky note more seriously.
- SiempreViernes 7y agoThe tragedy of the mundane reality is that more cyber systems will be put out of commission by things like botched patch tuesdays and techs pulling the wrong cable because they were mislabelled than any hack.
- repolfx 7y agoIt's possible. People wouldn't like it. Mandate that all software - everywhere - is written in Java or Rust with no unsafe blocks (but, oops, you can't realistically do that in Rust). Make it illegal to use web apps to administer infrastructure. Desktop GUIs all the way (no XSS there ...). Then mandate that this infrastructure can't be administered from Windows, but only some locked down new OS that required iOS style code signing from top to bottom. Then forbid the use of passwords for authenticating to anything, no matter how trivial. Think many geeks would get excited about that? People write insecure software because they can't/won't accept the fact that they enjoy building software in ways that are very insecure. For a lot of coders you'll prise C out of their cold dead hands, and they'll continue making hackable IoT devices until you do.
- asdfman123 7y agoIt seems like then we should be doing all of that already for all military applications since we're considering hackability to be such a huge issue. People write insecure applications because of all the priorities they are given by management, security usually isn't even on the list. Perhaps we'll get to the point of real maturity and have security experts working in every department, and operations with real security. Maybe.