7 ms·
> assuming that a breach is inevitable or has already occurred Sometimes I get the vibe that all our systems are already breached by multiple state actors, and
by mikedilger 6y ago
> assuming that a breach is inevitable or has already occurred
Sometimes I get the vibe that all our systems are already breached by multiple state actors, and I imagine them having their little digital wars inside obscure chips on our motherboards and none of us being the wiser.
- mPReDiToR 6y agoI used to be very careful about my information and privacy. Now it's impossible without living your life in such a way that you go nuts. Now I try to raise awareness and move people around me in the right direction. If governments continue to listen to the lobbies, and these lobbies are funded by big business, governments will only make laws that favour business interests over citizens' interests. We have to make people want change.
- unixhero 6y agoThis is the only sane way. / The only way to stay sane.
- DyslexicAtheist 6y agosame here. aside from the technical challenge the cognitive overhead of maintaining compartmentalization is huge[1]. Real spies have access to professionals helping to deal with the psychological issues that arise from compartmentalization. > Now I try to raise awareness and move people around me in the right direction. would be interesting to hear what you would consider the right direction? Is it via a better threat model (a technical solution) or changing the routine/behavior e.g. reducing from screen time, etc? how I "solved" it is perhaps not compatible with the mainstream today. especially with people younger than me who have never experienced live before the mobile phone or Internet. E.g. I quit social media altogether and simply not carry a phone when I go out and on the technical front everything is minimalist set-up (which is only useful for a die-hard SW engineer with enough passion to justify all the yak-shaving) [1] https://web.archive.org/web/20190219142403/https://books.google.hr/books?id=OuDLDAAAQBAJ&pg=PT854&lpg=PT854&dq=mental+health+risk+from+covert+undercover+operation&source=bl&ots=lWZrCDQIGj&sig=RxRJa5Tpw-3Y3qb5TBsgr71A-k4&hl=en&sa=X&ved=0ahUKEwi_kO_wjLnXAhVC_qQKHccBDGMQ6AEIOTAC#v=onepage&q=mental%20health%20risk%20from%20covert%20undercover%20operation&f=false https://web.archive.org/web/20190219142403/https://books.goo...
- OneLeggedCat 6y ago> Now I try to raise awareness and move people around me in the right direction For me, that is far more impossible than "very careful about my information and privacy."
- ggggtez 6y agoYes, but probably not in your computer. I'm sure that there are daily attempts to breach into government networks around the world.
- boomboomsubban 6y agoThough it's unlikely multiple state actors are actively targeting your computer, that doesn't mean they aren't fighting over breaching it or that you shouldn't assume a breach has occurred.
- prvc 6y agoIf the marginal cost of doing so is effectively zero, why not?
- deepstack 6y agoExactly. Instead of putting backdoor in only the computer going to China, why not just install back door in ALL the chips. Cheaper too. At this point, it won't surprise if all the computer has a hard ware level backdoor such as spectr/meldown. Not to mention encryption backdoor. Even state level player doesn't have the resources to take all that out. Remember when Snowden leak came out, Russian gov switched all internal memo to typewriters that shall give you an idea.
- mikedilger 6y agoAnd all phones have a modem, a closed source chip that likely provides numerous ways to get into your phone. Ira Hunt (CIA chief technology officer) said in 2014 something like "we like the fitbit because it doesn't have a ... it doesn't ... well I can't say but we like the fitbit."
- Fnoord 6y agoThere is the cost of getting caught, and having their zero day no longer being NOBUS.
- 6y ago
- pyinstallwoes 6y agoPretty much guaranteed between microcode hacks, spectre through browser, and supply chain attack vectors. How do you design a system that assumes everything in a stack is compromised?
- ransom1538 6y agoStart burning. Destroy all private data, don't store logs, only identify by hashed data. Keep your user's data on your user's devices.
- pyinstallwoes 6y agoIsn't hashed data based on belief of cryptographic security? I know there's cryptographic hashes and non-cryptographic but given a sophisticated enough state-actor it seems they'd find how to find a key collision. Is there a hashing mechanism/or similar technique that wouldn't be at risk to hash-collision attacks?
- DethNinja 6y agoUse casino dice to generate the entropy, don’t trust the hardware. This is how I handle C-level authority keys in my company. Security is mostly about reducing the feasibility of the attack, there is no way to make your systems 100% secure but you can design it in a way that your 500k USD worth of system requires attacker to spend 5 million USD to breach it.
- pyinstallwoes 6y agoIf you had to have a unique address for every atom in the solar system (I avoided the Universe), what technique would you use? Still hash and casino dice for each one? I'm pretty serious with this question given contemplation of designing a future-inclusive Operating System.
- DethNinja 6y ago
- ganoushoreilly 6y agoWhile I can't speak to all our systems being breached, I can tell you that priority targets are often cohabitated with multiple actors. I've seen networks destroyed because warring factions within the same country of origin were fighting each other as much as they were working on compromising the target. It's crazy how all of it plays out. Both in Govt. World, and Public security world. You see it all.
- birdyrooster 6y agoLike this one time these hackers by the handles Acid Burn and Zero Cool breached a local television station and were using the tape robot to fight for control over what was being broadcast. That tape robot was never the same.
- ganoushoreilly 6y agoHack the Planet!
- thesuperbigfrog 6y agoWhoa. That puts the Tron movies in a whole new light.