6 ms·
There are clearly worldwide problems with the hardware, software and protocols we use today. For months now there has been a massive new catastrophe every week.
by uniqueid 5y ago
There are clearly worldwide problems with the hardware, software and protocols we use today. For months now there has been a massive new catastrophe every week. We have an internet that has few mechanisms to identify bad actors and make them accountable, and hardware and software that allow careless or incompetent admins and users to leak sensitive data (perhaps an understatement, as it takes a gifted, motivated, experienced admin to stand any chance today). This industry should, but probably won't, rethink everything. Otherwise the world is in for an unimaginably bad problems as people begin to abuse the data from tens of thousands of these leaks and hacks.
- nix23 5y agoIt's not the Hardware not the Software and NOT the Protocols, it's the Human Factor, neglected systems, and often not even a try to use "best practices". The only way to change that is massive fines, there is no chance that a technical system can control human behavior...ATM at least, like Plane-crashes technically it's always human error. EDIT: Corrected Plan-crashes and told Mozilla to pay a 1 Million $ fine, because the auto-correct software did not work correctly ;)
- ajdegol 5y ago> like Plan-crashes technically it's always human error That's a $1M fine for misspelling "Plane". ;) Also, it's definitely the software. There's a wonderful talk by Alan Kay regarding this, but I cannot find it. It might be referenced in Jon Blow's talk: - https://www.youtube.com/watch?v=ZSRHeXYDLko https://www.youtube.com/watch?v=ZSRHeXYDLko
- uniqueid 5y agoI agree it could help to look at legal changes, such as 'massive fines'. That's closer to the 'rethink' we need. In regard to human error, I think we are approaching the point where it is useless to focus on individual hackers, companies, admins or users. To pick the most famous example of something we should rethink (not that it would address the hack in this news story): users on the web mainly read text, yet our browsers enable Javascript by default. To me it seems the ways we store and share data in IT are starting to fail. It's at the point where every interaction a regular person engages in (with banking, shopping, healthcare, social life, work, education, etc) has a real chance of becoming public. That's not sustainable.
- nix23 5y agoVery well said, i could not agree more.
- uberswe 5y agoThere is always a balance between convenience and security. Marketing tends to hate forcing 2FA as it hurts conversions for example. I think we can do a lot by thinking about only storing the data that is needed and for only the time that is needed. I think GDPR has been a first step in the right direction and it also adds fines for abusers.
- lbriner 5y agoThe hardware, software and protocols are written by humans so they are definitely part of the problem! Massive fines sounds like an easy win but it doesn't work in practice in the sae way that massive fines don't stop corporate polluters, don't stop medical negligence and don't stop crime in general. Are they useful? Only where it is clear where the responsbility lays. Take the VW emmissions scandal as an equivalent issue imho. Who gets a fine? VW? That isn't really fair if the decision was taken by an employee. The employees? They can't afford to pay a fine. All this would do is make it harder for disruptive startups who can't afford the potential fines. Sadly, I think like most things, it will take a whole raft of things including educating people, punishing people and companies, regulating who is allowed to produce and sign-off systems, have mandatory MOTs for software so they can't be left to languish and even potentially creating seprate WWWs for those who follow the rules and the general public can trust vs those who believe in complete liberty to do whatever they want and who cannot be exposed to the general public who won't understand the risks they are exposing themselves to.
- nix23 5y ago>The hardware, software and protocols are written by humans so they are definitely part of the problem! like Plane-crashes technically it's always human error >Take the VW emmissions scandal as an equivalent issue imho. That isn't really fair if the decision was taken by an employee That's a bad example, they got massive fines in the US, not so in germany (for obvious reasons), and yes it was for sure the engineer who took that decision and for sure not the management ;) A example for responsible storage of such data would be: If you want to store my highly private data (health records), you have to use a terminal to a government mainframe...you are not allowed to export, process or store it anywhere else.
- raxxorrax 5y ago> have mandatory MOTs for software What does MOTs mean? To be honest, I want in the net for special people that cannot be exposed to the general public.
- michaelt 5y ago
- danielheath 5y agoIt's reasonably well established that humans systematically underestimate low-probability, high-cost outcomes. Getting hacked is already pretty high-cost for most organizations. Given that, I think there's more to be gained by looking at the "low probability" side of things. Some historic examples of attacking the "low probability" side include building codes and speeding fines - both have pretty strong evidence for their efficacy. A comparable initiative for software might fine those found keeping data after they do not need it (like GDPR), or mandate that sensitive data is stored behind appropriate access controls (like PCI does).
- belatw 5y agoMassive fines to whom? In this case the taxpayers will bear the brunt of those fines. In other cases, the consumers.
- _trampeltier 5y agoThere is a person in charge for this. Just like to drive a companys car to fast. You have to pay by youself. Very simple.
- tjpnz 5y agoIt doesn't need to be that way. The procurement process used by governments to buy software is broken beyond repair anyway. Maybe this will bring some innovation into the space. For private companies in competitive industries I couldn't see this affecting consumers in a negative way. It may affect the bonuses of the overpaid but few would lose sleep over that.
- DyslexicAtheist 5y ago> Massive fines to whom? companies need to be held accountable for the garbage they create. peddling alpha/beta software to consumers or pushing code to production while they don't have a disclosure policy and rather purchase ransomware insurance than invest in quality-control must be forced with fines too big to ignore (make it 1% of annual global turnover _not_ profits) secondly we need to decriminalize hackers that take down vulnerable shit. instead create a business model that allows someone like brickerbot/janit0r to take dangerous devices offline if it is known to be unpatched for x-months still. similar what the feds did with patching of the recent MS exchange exploit but more bottom-up. finally criminalize all cryptocurrency so that they can no longer be converted to FIAT in any legal sort of way. want to use bitcoin? fine your only way to turn it into value is by buying a gift card that only is accepted by a corner shop in Uzbekistan. as another alternative that is also the other extreme, make banks adopt cryptocurrency (https://twitter.com/JoeUchill/status/1393697279941431300 https://twitter.com/JoeUchill/status/1393697279941431300) so it turns into a regulated white-market while outlawing the grey areas. taking these measures further, if you're getting pwned and do not disclose it within 1 week, or info surfaces that you paid ransom without disclosing it then your CEO and CISO bonk! go straight to jail. That would immediately put pressure into solving the boring security shit, like curating and maintaining a good quality SBOM, asset catalogue etc (... come to think of it, if inventory is missing in any org that processes PII, or you get hit by an OWASP top-10 then immediately jail time as well). it all starts and fails with holding people responsible for what they do and make it impossible to hide behind the name of a company. salaries can be adjusted to actual responsibility people carry in the company, no more blaming the intern. ^^ the reason why any of these measures will never happen is because those who would have to enforce it are themselves corrupt and totally dependent on the broken system in order to get cover and plausible deniability for their own crimes: https://www.newsweek.com/exclusive-inside-militarys-secret-undercover-army-1591881 https://www.newsweek.com/exclusive-inside-militarys-secret-u...
- sul_tasto 5y agoI think we need the equivalent of building codes and inspections.
- 2OEH8eoCRo0 5y agoIt's both but the humans have an excuse- they're human. We should know by now that given enough time humans fuck everything up. We should build things with this in mind. If we keep assuming humans are suddenly going to stop making mistakes then these things will never go away. I almost never blame the user or human, I blame the software.
- birracerveza 5y agoIf only there was a decentralized, secure, publicly available, encrypted way to store data and be able to share it with only the interested parties without having to rewrite proprietary systems from scratch with all the security issues that entails. Too bad blockchain and similar are only useful for Bitcoin, buying drugs and scamming people out of their money and that absolutely no developments are happening in the area, huh? In all seriousness, Web3 is coming and these problems are being solved. It will take time but we'll get there.
- dalbasal 5y ago>> Web3 is coming and these problems are being solved This has always been the case, and we've been consistently wrong about what "web3" is. IDk if you remember "semantic web," for example. These aren't easy problems to solve, and at this point, path dependency is a huge factor. The juiciest parts of the software industry are highly, if not totally dependent on proprietary & exclusive data. Even if blockchain-like technology was capable of being an everything data store, why would FB, Google, etc adopt it?
- nix23 5y agoI would love the concept to have my private data encrypted but still accessible from everywhere....until quantum computing kicks in...NEVER give data in more hands then it needs to be.
- onion2k 5y agoImagine a world where medical records are part of a blockchain. They're decentralized, secure, publicly available, encrypted, and only shared with interested parties. Now imagine someone finds a flaw in the software that a company uses to access the data in the blockchain. The 200K records "United Valor Solutions" has access to are read by an attacker and leaked on to the internet. How is the Web 3.0 version better? If someone can access the data in the blockchain then an attacker can use that same mechanism and the legitimate access credentials to exfiltrate data if it's not secure. There is no magic solution to this problem.
- bsder 5y ago> There are clearly worldwide problems with the hardware, software and protocols we use today. You can have the best protocol in the world, but it's useless if nobody uses it. These breaches aren't some amazing hacker. These breaches are outsourced, lowest bidder doing dumbshit stuff.
- qwerty456127 5y agoThe problem is we have everything recorded digitally, managed with software and hardware of needlessly inflated complexity, mostly running on the least reliable OS ever (Windows), always connected to the Internet. I would never allow any of my medical data to be digitized, but I have never been asked. I would never use an Internet-connected Windows PC to manage any critical machinery. I don't want my printer to order inks for itself. I would rather avoid modern libraries which add dozens megabytes of complexity to make trivial things look fancy. Oftentimes the optimal solution is not to add something (like another layer of encryption and automation) but to remove and make things simpler.
- est31 5y agoEven if it's not connected to the internet but runs on a completely and perfectly airgapped network, when your sensitive data fit on a single USB stick, it's extremely hard to protect them, simply because of logistics. In the pre-digital age you could maybe steal individual records, but stealing large mountains of papers would have alerted the security guards. Nowadays you can carry truckloads of data in your pocket.
- WanderPanda 5y agoBut lets also not forget that it is amazing that we can carry truckloads of data in our pockets nowadays :)
- qwerty456127 5y agoDon't forget there already is a new tape technology which lets you fit so much data you can hardly even imagine.
- AnIdiotOnTheNet 5y agoI object to your characterization of Windows as "the least reliable OS ever". What Windows is, is popular, and that's for a lot of reasons but one of them is that it is actually quite good at being a desktop PC OS, unlike some other operating systems I could mention. The same things that make it a good desktop (like say, not having to recompile software every two years to get it to run on the latest version) also make it slightly easier to trick users into running things they shouldn't, and of course allows less advanced users to have more control in the first place, which combined with its popularity lead to a large number of infections. Otherwise I agree with what you're saying, software (and hardware to a certain extent) is far more bloated and complicated than it needs to be.
- belorn 5y ago> few mechanisms to identify bad actors and make them accountable We have plenty of mechanism to track and identify actors, but the legal framework to make that work is not there. The major obstacle to get those in place is the billions evaluated industries built on the exist frameworks, and the enormous political power they have on the political system. Getting laws in place so we can have a safe internet that does not get exploited for commercial gain will be a bigger challenge then people had fighting tobacco companies on health issues. > hardware and software that allow careless or incompetent admins and users to leak sensitive data We have hardware and software that take responsibility for sensitive data, but that responsibility cost money. There does not exist any feedback loop or incentives for contract negotiators to manage data leaks to the point where leaks will not occur. There is however direct incentives to reduce costs, so hardware and software that can keep the initial costs down by putting the responsibility onto the user get a competitive advantage during contract negotiation. The industry can not fix this unless someone find a new profit center in preventing leaks. Laws and regulations could fix it, but then established commercial actors who currently has a competitive advantage by providing cheap hardware and software will fight those laws and regulators. As such, the challenge seems to be to either fight nail and tooth against money and power in order to get laws that solves the issue (like gdpr if it actually got enforced), or someone has to invent a profit center that happen to align with eliminating leaks and hacks. Maybe after nations has tried the concept of a citizen score, had a few internal wars, genocides, and media storms to really demonstrate the harm of the current system we might end up with enough international pressure worldwide to both have all the tracking and recording needing to correctly identify bad actors, but also the laws and regulations that prevents harm to innocents and enabling the commercial exploration of fellow human beings.
- raxxorrax 5y agoI don't think you can blame the net infrastructure. The problem is with utility IT. Probably also not the IT directly, as it is probably understaffed or underfunded or both. There is only one way to keep utilities safe on a public network and that would be extreme simplicity and a fitting network configuration. > We have an internet that has few mechanisms to identify bad actors and make them accountable That isn't the problem here and the advantage from this far outweighs the risks. > abuse the data from tens of thousands of these leaks and hacks. The data people share voluntarily also far outweighs stolen info. The reality is that nobody wants to spend anything on IT and that will bite you in the ass at a later time. It is not a technical problem alone.