3 ms·
That depends. How well-equipped do you think your average person with a smartphone (or pocket computer) is to manage and secure a server? This is not a snarky
by Kalium 4y ago
That depends. How well-equipped do you think your average person with a smartphone (or pocket computer) is to manage and secure a server?
This is not a snarky comment. The thing in your pocket can, today, be convinced to act as a webserver and host your website. It just comes with all the downsides of having to host, administer, manage, and secure a website.
- prox 4y agoWell that’s the problem to solve innit? Make hosting, administering, managing and securing easy as pie.
- Kalium 4y agoThat's a wonderful goal! In practice, you can either have a secured computer or one that offers useful services over a network. Through decades of sincere effort and many billions of dollars of investment, it has turned out that you cannot make hosting, administering, managing and securing easy as pie and still have something that can do all the things users would like it to do as a server. We can't even reliably do this for non-server computers. It's worth considering that sometimes our desires are in tension with another in ways that are not readily resolved.
- lmm 4y agoIs there actually a meaningful difference in how vulnerable these consumer computers are when acting as a server versus when not? Like, sure, being a server means that anyone who wants to send an exploit to them can - but realistically anyone who wants to send an exploit to them has dozens of vectors available already (SMS, pushed posts from dozens of social networks, website ads, ...)
- Kalium 4y agoThe answer is: no and yes. No, in that you're completely correct that network positioning and exposure does not inherently increase the vulnerability a computer has. It does not introduce new flaws. Yes, in that it's not just about vulnerability. A computer turned off may be in theory vulnerable, but in practice not exposed. Exploits happen when vulnerabilities meet opportunities. The more a computer is exposed, the greater the opportunity for exploitation. Making something publicly available, such as it offering up a website, is a pretty dramatic way to increase its exposure. As you might imagine, trying to perform useful work with data coming in over a network provides many more chances to try to exploit something than silently dropping all inbound connections. In extreme cases, you get things like the numerous worms of the 2000s. It is precisely because of this excellent point you have made that modern networks are designed with layers of security. That there are other vectors is a concern you wisely and rightfully point to, but each vector is concerning and the ease with which any given one can be guarded or exploited is considered. tl;dr: There's a substantial and very meaningful difference.
- lmm 4y ago> Making something publicly available, such as it offering up a website, is a pretty dramatic way to increase its exposure. As you might imagine, trying to perform useful work with data coming in over a network provides many more chances to try to exploit something than silently dropping all inbound connections. Sure; what matters is, roughly, the extent to which the computer is doing something complex based on data sent by an attacker. The thing is that these days people's pocket computers do so much complex work with user-submitted data, compared to low-level protocol parsing which mostly hasn't changed for decades, that I struggle to believe adding the latter would actually increase attack surface that much. Back in the '90s, where the main way to send data from computer A to computer B was for computer A to open a socket connection to computer B, that thinking made sense, but today almost everyone is consuming a firehose of data from random strangers via, well, almost every app on their phone and every website they visit.
- rambambram 4y agoCompletely true! No snark taken. My problem is mostly that the thing in my pocket runs Android or iOS, but I'm working on that problem. > How well-equipped do you think your average person with a smartphone (or pocket computer) ... Average people were pretty handy with computers and internet, even before the smartphone entered the scene and made it even more handy for even more people. So that would be the challenge in bringing some 'personal mobile server' to life.
- Kalium 4y agoAt this point your average person does a poor job of securing their home non-server. So while people might be pretty handy with their computers in some ways, I think it's reasonable to consider that they're very much not handy at all in some pretty important ones. Home computers are frequently unpatched, poorly maintained, and malware-riddled. I don't think turning them into servers is likely to improve this situation much.