3 ms·
This is a horribly wrong take. The premise that nobody understands these tech issues at the level needed to address them is not even close to true. In fact, thi
by Hippocrates 6y ago
This is a horribly wrong take. The premise that nobody understands these tech issues at the level needed to address them is not even close to true. In fact, this sounds like an argument one of the luddites in congress would make rather than a tech journalist.
- almost_usual 6y agoThe argument is no one knows the exact details of the whole system. That is obviously true, the only experts at these companies are the engineers who write code. There are still details they don’t understand. An expert would have to be the collective knowledge of every engineer that worked at the org and there would still be missing detail and ‘bugs’. This is literally why the security industry exists, bugs are inevitable. I don’t think the argument is ‘crazy’, it’s accurate when speaking about data protections. To assert your data is safe is to assert there are no security issues with your software. The only way of asserting this is to either encrypt everything or not store it at all. These companies will never do that so we end up with these complex arguments in Congress justifying it’s ‘safe’.
- _jal 6y agoThe implicit argument is that one must wholly comprehend the exact details of a company's systems in order to meaningfully control them. This is obviously false reductio ad absurdum given the existence of managers doing exactly that right now. CEOs are not testifying to congress about exploiting side channels in hypervisor memory management. On one level, they're offering industry viewpoints on policy issues; on another, they're actors in a political game.
- almost_usual 6y ago> This is obviously false reductio ad absurdum given the existence of managers doing exactly that right now. Managers don’t know the details of any system unless they wrote it when they were an engineer (and it hasn’t been modified). They are trusting their engineers’ interpretation of the system, which is a game of telephone up the management chain. > CEOs are not testifying to congress about exploiting side channels in hypervisor memory management. On one level, they're offering industry viewpoints on policy issues; on another, they're actors in a political game. The largest account takeover incident recently was an unsophisticated social engineering attack executed by a 17 year old. I’d argue most system and data vulnerabilities aren’t sophisticated or complicated yet companies like the idea of this because it makes them seem more improbable. Vulnerabilities happen because security guarantees and understanding cost time and time is limited when shipping a product faster than a competitor. In reality if Congress wants an expert they need to have a team of engineers at the company performing audits and code reviews.
- nixpulvis 6y agoLuddites were mostly concerned with the protection of their livelihoods from the powers of larger producers of equipment at the time. I think we as a society could learn a lot about our situation by looking closer at Ludditism