3 ms·
I will second this "security as a tax is well worth it" mindset, I'm a programmer, and like to think I'm security savvy, but I CANNOT babysit my non-tech-savvy
by ConcernedCoder 6y ago
I will second this "security as a tax is well worth it" mindset, I'm a programmer, and like to think I'm security savvy, but I CANNOT babysit my non-tech-savvy wife 24/7 and having her on iphone / macbook is a weight off my shoulders as far as appstore security, as married assets are shared assets and the "weakest link" plays in the security arena...
- _fullpint 6y agoI’m a programmer and having taken graduate classes in Security Analytics and have a hard time convincing myself that I’m security savvy. It’s such a cat and mouse game that has massive jumps in acceleration when it comes to ‘novel’ ways attackers create new exploits. Having Apple taking it seriously even for people like me is a huge win.
- blackflame7000 6y agoNo matter how much you learn, you will still never know what you don’t know. A zero day is by definition something you don’t know and therefore we recognize that there is some futility in trying to defend against everything that ever was and all that ever will be
- _fullpint 6y agoThere's a decent case for using anomaly detection in an attempt to solve some zero day attacks. The idea of not knowing what you don't know, can be used in such scenarios. I 'know' what looks right, and I won't allow for anything that doesn't look right. That doesn't solve all problems, but can certainly cut down on a large amount of them. What I did see a lot of though in a lot of the case studies/readings/etc, was seemingly anytime advancements were made in one area, closing off particular patterns or styles of exploitation. The energy and resources often would switch to another domain, and there's a mad scramble to solve it. Just my two-cents, and a bit off topic.
- blackflame7000 6y ago> I 'know' what looks right, and I won't allow for anything that doesn't look right. The way I view it, it's sort of like when a player glitches themselves outside of the boundaries of the level in a video game and are able to bypass all the battles the game has in store for them and walk directly to the objective. Anomaly detection only works if they are playing inside the realm of the system but if something manages to break out of the sandbox then detection can be bypassed because it was never a condition thought possible and therefore not checked for. For Example, you can have code to detect abnormal requests http requests, but if there is a vulnerability in a webserver's memory management of reading bytes from a socket then it allows the attacker to "breakout" of the system before you can detect it. Now you might be saying well we can detect when they breach memory but it just creates another cat and mouse game at a different level. This all assumes there are no bugs in the anomaly detection systems themselves
- junon 6y agoApple takes it more seriously than the Windows teams do, sure. That's not to say Apple is perfect. Their "root"/"" login bypass zero-day was absolutely unacceptable, even compared with Microsoft's problems. Other than that, I'd trust an Apple device over a windows device any day of the week.