5 ms·
Tech has essentially created this problem. Can’t tech fix it?
by pakwa 5y ago
Tech has essentially created this problem. Can’t tech fix it?
- aikinai 5y agoConstruction has essentially created the problem of potholes. Can they fix it?
- rmbyrro 5y agoGood analogy. Question here is: can they fix potholes faster than new ones show up? Seems answer is no for tech. And construction, these days.
- arunc 5y agoIt takes an expert to know that there's vulnerability. Whereas construction engineer can "see" the pothole and so they can fix it. Software engineer has to "know from exploits" that there's a vulnerability so they can fix it. It's not far away when OS are written in memory safe languages like Rust.
- pjmlp 5y agoYou mean far away like 1961? https://en.m.wikipedia.org/wiki/Burroughs_large_systems https://en.m.wikipedia.org/wiki/Burroughs_large_systems Nowadays still being sold to governments that care about security. https://itupdate.com.au/page/unisys-clearpath-mcp-unsurpassed-security https://itupdate.com.au/page/unisys-clearpath-mcp-unsurpasse... https://www.unisys.com/ms/client-education/course-catalog/clearpath-mcp https://www.unisys.com/ms/client-education/course-catalog/cl... Or maybe 1983? https://en.m.wikipedia.org/wiki/Rational_R1000 https://en.m.wikipedia.org/wiki/Rational_R1000 Maybe 1982, https://news.ycombinator.com/item?id=22375449 https://news.ycombinator.com/item?id=22375449 Plenty of examples (those are a tiny snippet) on how safe OSes should be written, until there is liability the easiest way will always win.
- rmbyrro 5y agoIt's more complex to find security bugs, yes, but I think the analogy stands. In order for a construction engineer to "see" a pothole, they need to actually know where the pothole is and physically go there. When you have millions of kilometers of paving across a continental-sized country, like the US or China, for example, this is unfeasible. "Seeing" a pothole isn't so simple as it might give you a first impression...
- nomel 5y agoI think the answer is probably an astounding yes for both, if you think of the trend of vulnerabilities/units of software generated. The move to a large majority of software being run in a sandboxed environment has drastically reduced this sort of thing.
- daniel_reetz 5y ago"The invention of the ship was also the invention of the shipwreck" ― Paul Virilio
- pjmlp 5y agoThey surely do, because if I can prove the pothole broke my car, I can sue them, or have my insurance take legal action. Eventually this will be standard in software as well.
- jtsiskin 5y agoNot to sound like a broken record but…. This was yet another memory management bug that would have been prevented if using a memory safe language
- a1a106ed5 5y agoOn a brighter note, apple is currently in the process of converting almost all iMessage components to Swift for this reason. I'm sure it is taking many engineering hours, and image parsers/open source libraries like this are the most difficult to convert.
- zionic 5y agoLet’s hope they make swift work of it
- deleted 5y ago[deleted]
- lenkite 5y agoIs there a link that mentions this ? The bug was in the ImageIO/Core Graphics layer so are they re-writing all Core Graphics components in Swift ?
- smoldesu 5y agoYeah, something tells me that they're not going to be rewriting an image decoder to have a runtime...
- mensetmanusman 5y ago1000 FTEs thwart the world’s nation state hackers?
- saagarjha 5y agoJust one component, the one that parses incoming messages. The problem here is that it parsed the message and decided to pass it to ImageIO, which is written in C++.
- npteljes 5y agoNope, it can't. As long as you use tech, it's a risk management situation, and a cat and mouse game.
- louwrentius 5y agoAs long as people aren't put in jail for faulty software, it will never be fixed. Remember Diginotar? Who knows how many lives were affected in Iran...
- thret 5y agoSurgeons aren't put in jail for faulty surgery. Wanting this for software is a bit draconian.
- louwrentius 5y agoSurgeons can be held accountable and can lose their license at least. That has never happened to software developers.
- cnst 5y agoI think we have vastly different standards on what's reasonable and prudent between software developers and surgeons!