5 ms·
If something is broken in the default installation, you'll notice quickly during acceptance testing and can go and fix it (for example by re-enabling insecure p
by Athas 4y ago
If something is broken in the default installation, you'll notice quickly during acceptance testing and can go and fix it (for example by re-enabling insecure protocols).
If something is unexpectedly insecure, you will probably not notice until it's too late.
I think the admittedly annoying security people are right in this instance.
- froh 4y agostill how do you give the user the option to say "I know what I'm doing." I get that access to an unknown site with unknown content with a dated cipher should _by default_ break. By default! I do not get that I cant't access a well known site any longer because that site that I don't control just doesn't update their cipher. In that latter case I need to and want to be able to override the default recommendation of the gurus --- without having to rebuild my client!
- Athas 4y ago> still how do you give the user the option to say "I know what I'm doing." You make configuration available. Most of these disabled-by-default protocols can be enabled by a user who really knows what they are doing (and isn't just saying so). A few might have been outright removed from the code base. In that case, you really need to know what you are doing, but you can still bring them back by installing a custom patch or downgrading the program in question. I think it is a good idea to create friction along pathways that are probably mistakes. The people who really need to go down that path will put in whatever effort is necessary, while people who are motivated by the path of least resistance will be nudged in a safe direction.
- speeder 4y agoWell... I had some serious issue where security-related breaking changes sent a whole business down for days, with severe lost revenue, without any way to go around it, because the software that needed the insecure old algorithm was government-provided and mandatory for transactions... It is not like you can go and tell your government you won't pay your taxes because their tax system doesn't work on newest OS version because it is outdated... Or rather, you can, and then the government will happily shoot you.
- t-3 4y agoWhy should the default support your insecure needs? You builing a custom port is much better than every FreeBSD getting insecure defaults.
- citrin_ru 4y agoSecurity expert love to discuss ciphers but how commonly old ciphers are exploited by threat actors in real world? I heard cryptographic weakness are sometimes used to break tivoization/DRM but I don't consider people who do this threat actors - an owner should be free to run any software on own hardware. And an attack on device you hold in hands is completely different than say an attack on remote FreeBSD server.
- Genbox 4y agoI'm one of those security experts. I've broken more cryptosystems than I can count through security & code reviews. You would be surprised how many vendors have no idea on how cryptographic primitives work or when/how to use it. This is exactly what we mean when we say "don't roll your own crypto". There is a communications problem within all of this. If I break a cryptosystem, I do not have permission by either party (customer/employer) to go and write a blog post about it. All in the name of "protecting our users". The same goes for my colleagues around the world, as such it gets very little attention. As for threat actors misusing it, there is a value/effort calculation in their world where it is often easier to access content through other means. Crypto is hard - for everyone, even threat actors - so you won't often see them trying to tackle it.