4 ms·
Exactly. Threat modelling is a thing outside IT secutiry too. Youtube channel "MentourPilot" [0] has some excellent examples of how civil aviation was built to
by nousermane 5y ago
Exactly. Threat modelling is a thing outside IT secutiry too.
Youtube channel "MentourPilot" [0] has some excellent examples of how civil aviation was built to withstand "small fuckups": with "Swiss cheese" model. [1]
[0] https://www.youtube.com/c/MentourPilotaviation/videos https://www.youtube.com/c/MentourPilotaviation/videos
[1] https://en.wikipedia.org/wiki/Swiss_cheese_model https://en.wikipedia.org/wiki/Swiss_cheese_model
- dcow 5y agoI think most of the quibbling is over the semantics of “one small fuckup”. It’s in quotes for two reasons 1) because the comment I was responding to worded it that way it and 2) I’m deliberatly calling that characterization bullshit: one _truly_ small fuckup obviously doesn't leave you vulnerable to ransomware. Systems need to be able to withstand of small things, have redundancies, engineers build in tolerances, yada yada.. of course! Were talking about *things that leave your entire business in the hands of ransom ware criminals* or *things that kill people* or *things that crash planes* or *things that cause bridges to collapse*. Those things can’t be tolerated by definition because they are fatal failures. That’s my point. We would not tolerate companies that build bridges that collapsed all the time and keep letting them build bridges so why should we tolerate companies that get hacked repetitively by ransomeware groups? Insurers are running because it’s not good business to insure these risks. Sounds like the market is working just fine.