3 ms·
[My comment on the blog post follows.] Great post. Dug is absolutely right in saying that our present difficulties in computer security lie not with brute-for
by JakeSc 15y ago
[My comment on the blog post follows.]
Great post.
Dug is absolutely right in saying that our present difficulties in computer security lie not with brute-force flooding of pipes (i.e., DDoS), but rather with targeted, strategic attacks on smaller subsets of systems (think Stux).
However, I would disagree with the statement “users are the new target”. Indeed, it is far easier to gain access to resources by attacking the users who control those resources. But I think it is far more damaging (and therefore lucrative to the adversaries) to attack infrastructure systems on a wide-scale. People may be the initial entry point of the attack, but I still think the greater target is technology behind our infrastructure.
Steve, you have addressed the very important point that much of our infrastructure (economic, transportation, military, …) is based on on solid systems operating securely and reliably. Let us call these critical systems. These are the ones that are vulnerable to crippling cyberattacks.
I posit that our infrastructure should not be based on these systems at all.
Any critical system should have no connection to the Internet. In fact, it should have no concept of the Internet. One might go so far as to say that any critical system should have no I/O with the rest of the world. (Recall that Stuxnet was thought to be propagated initially by USB.) This would help ensure that infrastructure-crippling cyberattacks do not propagate. Though preventing a system from communicating with the outside world will drastically reduce its value in controlling our infrastructure. This is the unfortunate nature of the security-versus-usability problem.
How do we secure ourselves? Let us hope that we will simply enjoy a “new spring”.