4 ms·
Well I'm glad you're certain that none of the passengers on the train were using their phone for critical patient care or handling a time sensitive family issue
by badcppdev 3y ago
Well I'm glad you're certain that none of the passengers on the train were using their phone for critical patient care or handling a time sensitive family issue.
- Freak_NL 3y agoThe more reason to educate people on that front. Don't rely on your single piece of tech in your pocket to work all the time. Society ought to reacquire a bit of resilience on that front. Need to do critical patient care while commuting? Surely you will have made sure to bring a dumb phone with you as backup, if you are really that critical a resource (after all, your battery might be dead, someone might have stolen your fancy Iphone, etc.). Time sensitive family issue? What if you turned your phone off to read a book? Are you the asshole now? The train driver might have been stopped at a red signal in the Schipholtunnel; not much of a chance of getting a phone signal there. Is he now endangering people by depriving them of their umbilical uplink? What if the time sensitive family issue happened while you had your phone turned off for some intimate private time with your partner? How will you ever forgive yourself? The key takeaway here is to understand that there is no such thing as being available all the time. So don't expect it, and don't feel guilty about not providing it. There are all plenty more of those convoluted minimal chance scenarios you can come up with, but these hold true for anything people around you do.
- ethanbond 3y agoIt’s amazing what sort of weird opinions people will contort themselves into to make their antisocial behavior “okay.” Got robbed and murdered? And you only had a deadbolt on your door? Surely you couldn’t be such an idiot as to not have a dual layer steel security door, could you? Got in a car accident because someone pulled out in front of you? And you were going the speed limit?! What a buffoon. You’re insane to be traveling above 20mph on any roadway, because someone could pull out in front of you at any moment and if you’re smart like me, and not a total doofus, you’re always on your toes. Got food poisoning at a restaurant? Well if you were smart you’d have asked to see the expiration dates on all their ingredients and observed the kitchen’s methods VERY closely. Make sure you also visit each supplier to observe their hygiene practices, and of course each party who touches each product along the supply chain. Anything short of that is outright negligence on your part. I’d rather we don’t degrade ourselves into a low trust society due to some abstract desire for “resilience” and instead we just put people in jail to deter people from harming others without their permission.
- blagie 3y agoI think that's a false analogy. I don't have a clear sense on the ethics here, but the basic point is that we should be resilient to crises and broad cyberattacks. Cell towers _will_ sometimes go down, and rare events, such as nation-wide cyberattacks, _will_ eventually happen. Imagine if [adversary] spends time finding a zero-day in iOS, Android, Linux, Windows, and MacOS, and releases a worm which bricks every computer it gets on (e.g. overwrites every firmware with something maximally malicious). That's within the scope of capability of many world governments. What happens? Do people in hospitals die? Does out infrastructure collapse? Or do things keep ticking on, somehow? Tools like Chaos Monkey intentionally introduce more errors under normal operating circumstances in order to make systems more robust in extreme ones. This is a real-world analogy. For something like this on a train, it's a question of value systems. I can't bring myself to _have_ a value system which makes this okay for me to do something similar, but I can see rational value systems which would allow that (e.g. hedonistic utilitarianism). It's the trolly problem. All the examples you gave, in contrast, are just victim-blaming. There is no greater good. By my value system, though, what I would like to see are similar tests done planfully and intentionally. In the abstract, if a federal government took down the internet and cell phone networks for eight hours, or we had planned power blackouts, or similar, I'd be fully supportive. That would require organizations to build in the right types of resiliency. I understand that's fully impossible in the kinds of political systems we have. But in the right political system, I'd like to have a government which works to make us resilient to those kinds of extreme events.
- ethanbond 3y agoIt's not a false analogy at all. You just happen to care about cyber risk and resilience, so you think it's okay to accept a higher cost in pursuit of it. Here you go: * You need steel security doors because we should be resilient to crises and broad security threats. You don't know when there will be a major gang war, a neighbor with a psychotic break, a government breakdown, or a ground invasion. It's just better to have steel security doors because there are all sorts of real risks that they mitigate. * You need to drive slowly because some day someone will pull out in front of you, even by accident! Accidents like that happen hundreds or thousands of times per day, so it's frankly insane not to be prepared for it. * You need to check all your restaurant's ingredients because someone will forget to throw out the milk one day. We need to be resilient to this because it's certainly going to happen on occasion, and the right way to achieve resilience is to shift that burden onto end users, or at least to continually poison end users until they demand action from food regulators that we have a 100% foolproof system to prevent bad milk from ever making it into a restaurant meal. N.B. The comparison to Chaos Monkey is the false analogy. People run Chaos Monkey on their own infrastructure. And yes, if you run a tool like that on someone else's infrastructure without their permission, you're the asshole.
- valenceelectron 3y agoI'm a T1 diabetic and get my blood glucose values through my phone, bluetooth even. So disabling bluetooth as mitigation is not an option and the phone is crucial. The vendor doesn't support another or even a secondary device. How am I supposed to "reacquire a bit of resilience" here?
- Freak_NL 3y agoYour life should not depend on your phone working, because it will fail sometimes — it's consumer grade electronics, not a pacemaker or milspec ruggedized device with a minimal attack service (i.e., no Bluetooth, but a safer alternative). What do you do when your phone gets stolen or simply breaks? Complain loudly at the very least, and have a backup in place (but I'm sure you do).
- user_7832 3y ago(I'm also T1)When my phone (screen) broke, I contacted my hospital and got a separate device (reader), but it took a few weeks. Disabling phone access isn't okay or justifiable in public places. I'm not defending the existence of BT vulnerabilities but what the guy did on the train was dumb and antisocial.
- valenceelectron 3y agoPhones are ubiquitous in every country I've spent a reasonable amount of time so far. If my phone breaks I can just walk into a store and get a new one. The sensor will transfer its connection to the new phone within minutes. So that really is not that big of a deal. Some edgy liberation fighter DoS'ing my phone, however, is. Also note that there are people that have such sensors and insulin pumps connected in a feedback loop. I don't personally but this exists. There also exists a small open source scene around that topic. Examples are https://openaps.org/ https://openaps.org/ or https://nightscout.github.io/ https://nightscout.github.io/ > Your life should not depend on your phone working My life as diabetic depends on many, many variables. Theoretically, all it needs is an incorrectly labeled meal to do serious harm. Or the delivery guy transporting my insulin didn't maintain cooling. I can only do so much and still live a life without constant fear. While this may sound dangerous to you, this way of measuring your blood glucose is extremely liberating for diabetics. The alternative is just so much worse.