4 ms·
I'm convinced that it's impossible to prevent anyone that can physically tamper with a system from having full privileges on that system, as a result of physics
by Denvercoder9 4y ago
I'm convinced that it's impossible to prevent anyone that can physically tamper with a system from having full privileges on that system, as a result of physics. The only way to truly protect information is to make use of quantum effects, and we've only just started doing that in labs. Everything else is just making it harder.
So, if you make things harder and someone comes along that invests more effort to overcome, can you really call that a vulnerability? It'd be a real vulnerability if with this access to a user terminal they could elevate permissions on the satellites, but that hasn't been shown (yet?).
- akira2501 4y ago> can you really call that a vulnerability? Yes. Just because executing the attack doesn't seem to get you anything particularly valuable doesn't make it "not a vulnerability." We're not personally insulting it, we're just describing reality.
- xaduha 4y ago> Everything else is just making it harder. If it's hard enough that only state actors can potentially do it, then what does it matter in real life that it's theoretically vulnerable?
- czx4f4bd 4y agoYes. Vulnerabilities exist with respect to a system's expected functionality and must be understood and weighed against other requirements to determine the system's security model. Even if you think the expected functionality is stupid or impossible, that doesn't change the fact that the system has a particular expectation that it doesn't meet and a mechanism by which that expectation can be violated, i.e. a vulnerability. To put it another way, consider physical locks, which must inherently be able to resist direct physical tampering by an adversary. Under your definition, no flaw in a lock could be considered a vulnerability since any lock can eventually be cracked. The problem is that this doesn't provide us any useful insight, it just makes the word "vulnerability" useless. It's already well-known that any lock can eventually be cracked, but tradeoffs still have to be made in deciding which lock to use for a certain situation.
- josephcsible 4y agoNo lock is expected to be able to keep an adversary out indefinitely, since that's known to be completely impossible. They're expected to delay an adversary by a given amount of time, e.g., 2 hours for a UL class 3 vault door lock, and a vulnerability is if there's a way for an adversary to bypass one faster than that. The problem with a security model that relies on people never being able to root devices they possess is that it is expecting the impossible.
- bri3d 4y ago> So, if you make things harder and someone comes along that invests more effort to overcome, can you really call that a vulnerability? Yes? This is defense in depth. Anything that bypasses a defense is still a vulnerability, even if your backup defenses protect you. Defending physical hardware is indeed a theoretical impossibility as on paper, it will always be possible to make a perfect electrical clone of the original hardware and then modify it to suit. However, reality is different, and mitigations against physical access have become much more effective in recent years (iPhone anti-jailbreaking and the Xbox One come to mind as fairly successful). So, this is a vulnerability indeed, just not a high severity one. One layer of the defenses are bypassed, but the remaining defenses remain.
- deleted 4y ago[deleted]
- TickleSteve 4y agoAbsolutely, defence in depth is how real systems are designed, dont know why you're being downvoted. https://en.wikipedia.org/wiki/Defense_in_depth_(computing) https://en.wikipedia.org/wiki/Defense_in_depth_(computing) For the same reason, security-by-obscurity is also a valid (though not sufficient) tactic for one of those layers (which also surprises people). Its about delay and demotivation to slow down your attackers.