3 ms·
Now we have cyber domain where this is definitely not true.
by aj3 5y ago
Now we have cyber domain where this is definitely not true.
- Kinrany 5y agoIt's clearly true: it's cheaper to prevent vulnerabilities than to find and exploit them.
- khafra 5y ago"Defense vs Offense" is underspecified for this disagreement. Considering "defense" as the developers writing an application, and "offense" as the reverse engineers attempting to exploit it, defense may still be cheaper in some scenarios. If you consider "defense" as an organization attempting to provide a service securely, and "offense" as all the security threats they are exposed to, it seems hard to argue that the defensive side has any sort of advantage over all of the attackers.
- paulryanrogers 5y agoDoes this assume a stable and relatively slow rate of change? Because at some scales I imagine preventing vulnerabilities could be equally difficult.
- topher_t 5y agoIs it cheaper to find and prevent ALL vulnerabilities than to find and exploit ONE?
- outworlder 5y agoNot sure. Let's say we have fortifications. People are needed to man them. This is understood by everyone. Entry points are checked, etc. Compare with 'cyber' systems. How many people are adding features, working on bugs and the like, versus how many are even looking into security vulnerabilities? Translating to the physical domain, it would be as if we were building a fort, then moving almost everyone to build extensions or new forts, with a handful responsible for the security of all fortresses - and the paths in between them! In the dark. The fact that most systems are not immediately "owned" speaks volumes on how difficult this is to accomplish. Barring zero days, the main way one gets compromised is by making mistakes (not patching, leaving systems unsecured, etc). That is, there's a door that's open and unguarded...