3 ms·
While serious, this should come as no surprise to anyone who has had the "pleasure" of using a government IT system. The OPM hack a few years ago demonstrated t
by verberant 6y ago
While serious, this should come as no surprise to anyone who has had the "pleasure" of using a government IT system. The OPM hack a few years ago demonstrated this and the current SolarWinds crisis just reminds us of it.
You could liken the security issue to climate change – our entire global economy appears to depend on consumption, which appears to be accelerating climate change. But are we going to actually change anything significantly to address the problem? Uh no, not now, maybe later. Most people barely understand the problem and, even if they care, are powerless to change it. Furthermore, we are now completely reliant on the status-quo and seemingly incapable of imagining a different world. In the same manner, these software systems which now underlie every part of our day-to-day lives are taken as a given. They are now simply too convenient and ingrained in our lives to ever go away.
How do we overcome the inertia of change? Most likely, from what I can see, we will simply change our expectations – it is impossible to build a completely secure software system, so we should instead change how we use it/what we expect it to do.
We also feel pressure to constantly modernize the infrastructure without having a parallel discussion about the security impact of these innovations. As we get further and further from the bare metal with newer and more convenient abstractions, our engineers understand less and less about the realities of the systems they are constructing. And, arguably, as software becomes easier for users to use, they too lose sight of what the system is actually doing and how something can go wrong.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- tw25460241 6y ago> our entire global economy appears to depend on consumption I'm puzzled by this statement. For there to be consumption there must be production, i.e., supply and demand, which is the economy, not some separate dependent thing.
- oska 6y agoThe existence of a mutli-trillion dollar advertising industry means you shouldn't be puzzled. The grandparent comment is talking about pushed consumption, i.e. that our economies are based on constantly pushing up consumption, not having it simply be based upon natural, unforced demand. Not to mention things like built-in obsolescence, designed to be thrown away, etc, etc.
- tw25460241 6y ago> our economies are based on constantly pushing up consumption, not having it simply be based upon natural, unforced demand. Setting aside the appeal to nature fallacy, there's nothing special about the market process in "our economies". Of course suppliers want to increase profits, and one way is to increase the quantity supplied -- but that takes willing consumers. If consumers prefer a cheaper thing now with a shorter life span, or to pay for something with their attention instead of their money, is the "problem" that the market process gives people what they want, or that their preferences should be substituted with your own?
- oska 6y ago> the market process gives people what they want It doesn't. Advertising heavily manipulates and subverts people's 'desires'. That was my point. And just as an aside, discounting points by citing various dubious 'fallacies' is poor discursive etiquette.
- webmaven 6y ago> How do we overcome the inertia of change? Most likely, from what I can see, we will simply change our expectations – it is impossible to build a completely secure software system, so we should instead change how we use it/what we expect it to do. Hardening systems further would hopefully make breaches more difficult and less common, but never prevent them entirely, therefore we should instead start focusing security efforts on limiting the blast-radius of potential damage a breach can cause, resilience of organizations in the face of breaches, and mitigation and recovery from breaches. There is probably a need/niche for a security equivalent to Netflix's Chaos Monkey that randomly breaches your own systems in order to encourage/enforce that resilience, mitigation and recovery.
- rmrfstar 6y ago> We also feel pressure to constantly modernize the infrastructure without having a parallel discussion about the security impact of these innovations. We also have PE firms, like the ones that controlled Solar Wind, dictating the level of security investment and dumping their positions when the bill for their negligence comes due. PE wizz-kids call that "optionality". They love optionality. Congress should listen to Dan Geer and adopt product liability for closed-source software. They should also do something about PE control over the economy, they are doing serious damage.