4 ms·
Software security can be thought of as operating on a cost/benefit model. To produce secure software means making attackers spend more resources on penetrating
by viktorcode 5y ago
Software security can be thought of as operating on a cost/benefit model. To produce secure software means making attackers spend more resources on penetrating defences than the value they get from successful attack. And it works well for mass market, because the vast majority of attacks are non-targeted attempts to fish for financial credentials, taking over the devices for use in a botnet etc.
For state attacker the model breaks. The value of a target can be very high. And the available resources - financial, technical, other - are there to fill the budget.
- datavirtue 5y agoI can exchange pgp keys with someone and send encrypted messages back and forth. No amount of funding or resources will ever be able to expose those messages. This is math. You sound like you are defending Apple for exposing journalists and activists when Apple, in fact, explicitly allowed remote code execution by untrusted actors. They way you put it, these people fired up a quantum computer and broke the users password hash. What they actually did is the equivalent of an activex control owning a machine in a drive-by attack.
- viktorcode 5y agoWhat you describe is an ideal Alice / Bob situation, setting just a single protected surface. In real world it's getting far more complex: what OS your PGP client is running on? On what hardware? Is anything else running on the same device that may break out of its sandbox and inject the code in another process? And so on. > when Apple, in fact, explicitly allowed remote code execution by untrusted actors Can you please elaborate what do you mean by that?
- NikolaeVarius 5y ago>I can exchange pgp keys with someone and send encrypted messages back and forth. No amount of funding or resources will ever be able to expose those messages You have no goddamn clue if this is correct or not. Your keys may be compromised, your computer might have spyware on it, your messaging client might be backdoored.