3 ms·
> If you are not involved directly with any of that professionally, it is better to treat it the way non-developer treat the OS. Assume it will work as intended
by nenad 4y ago
> If you are not involved directly with any of that professionally, it is better to treat it the way non-developer treat the OS. Assume it will work as intended because loads of highly trained professionals take care of it. Added benefit ehen it comes to aviation: strict and sensible regulation (the MAX disaster notwithstanding).
Allow me to chime in and respectfully disagree with this sentiment and the metaphor.
As the saying goes - the aviation (just as the automotive) industry saves lives (as in "advances security") one accident at the time. It would make sense that close calls like this Austin near mass casualty event should contribute to the future safety as well. In that context, it's absolutely legitimate to be suspicious and ask safety-related questions, including in a HN comment or in real life - instead of shutting someone down.
Speaking of the developer-OS metaphor - any non-rookie developer should be aware of not only the security and vulnerability of one's own software but also of the security and vulnerability of the underlying OS, infrastructure and even hardware. The number of building blocks gets larger by the day and nearly each building block is becoming increasingly complex. Yes, there are professionals working on each those blocks yet there are new CVEs and associated attacks all the time (incl. ransomware). If we add 0-days into consideration (a.k.a. "the unknown unknowns" in the software context) IMHO we should be able to conclude that the used developer-OS metaphor is not helpful.
The older and more experienced we all become, the more should we be cognizant of the potential risks (not only in our particular industry niche) and we should welcome and consider a normal, widely accepted practice to challenge the status quo and pose questions that should overall increase the number of brains and eyeballs on the problem and (unknown) unknowns - be it vulnerabilities or security risks, especially to our bare lives.
- hef19898 4y agoAnd what makes anybody think this incident will not be properly reviewed, analyzed and suitable mitigation actions identified? And why do people on HN always think they know it better than the actual experts in this field, while just expectung users of their products, I just asse in most cases that is some piece of software, to worry about the details at all?
- Xcelerate 4y ago> And why do people on HN always think they know it better than the actual experts in this field When the experts in the field have successfully prevented all accidents and near misses, maybe HN commenters will stop providing their input. There is such a thing as tunnel vision in a field you have been in too long.