3 ms·
It's a good idea! I like where your head is at. Apollo and other historic moonshot programs were fundamentally striving to match some set of fixed natural forc
by Kalium 3y ago
It's a good idea! I like where your head is at.
Apollo and other historic moonshot programs were fundamentally striving to match some set of fixed natural forces with human ingenuity. The conditions to be met and overcome were measurable and knowable. They were natural-world challenges, bristling with natural-world problems. Vacuum, radiation, lunar regolith. The sound barrier, the Polio virus, and more.
Unfortunately, this is in sharp contrast to the challenges of security. Information security is an adversarial, human-centered enterprise. The forces with which we contend, armed with human ingenuity, are themselves armed with the same. It becomes a question of resources and economics. Even the cryptography on which so much relies is ultimately a question of how much breaking it is worth. If we are willing to spend enough, we can probably make it too expensive to successfully attack a system.
Plus, we know that the weakest leak in any system is generally the humans involved.
With all this in mind, we cannot possibly expect to build systems with zero vulnerabilities. It's not a moonshotable goal. What we can do - and what a mature security program will help you do - is plan for detecting, containing, mitigating, and recovering from attacks.
- Veserv 3y agoThose are the talking points of the people who got us into this mess who have been systemically incapable of deploying or even developing secure systems. There is no absolutely reason to listen to the liars who have repeatedly promised secure systems while being utterly incapable of doing so for literal decades. The task is not impossible, the commercial vendors like Cisco, Google, Microsoft, Amazon, Apple, etc. are just incompetent at security and are trying to poison the well by claiming that it is impossible just because they can not do it. If you want to know what actual high security development looks like you can just look to Orange Book Level A1 certified systems and Common Criteria EAL 6/7 certified systems. Systems designed for high security with formal specifications, robust documentation, exhaustive testing, thorough review, spotless penetration testing by well-funded intelligence agencies, formal proofs of correctness, and proven deployment in high criticality settings. The Common Criteria SKPP literally required the NSA to fail a multi-month penetration test while having the full source code, internal documentation, and formal specification. These commercial vendors believe protecting against state actors is literally impossible even though it has already been demonstrated in front of their faces for decades. Nothing they say about security is useful because they know nothing about what is needed to make systems that are actually secure.
- Kalium 3y agoHigh security development practices will, as you wisely say, go a very long way. That is not quite the same as some kind of zero-vulnerability "secure" system, however. No system involving humans is, or ever can be, perfectly secure. At best you can make it uneconomic to attack the computerized parts of the system through networks. You've touched on a number of ways to do this, which are known and understood in the commercial world as both feasible and expensive. This is why Common Criteria has a spectrum of evaluation levels... and even EAL7 does not offer any kind of guarantee of zero vulnerabilities. Meanwhile, adversaries can and will investigate if their goals can be achieved through human attacks or disruption. There's no need to devote extensive resources to breaking into a system if a carefully placed bomb can produce the same goal, after all. As you say, this task is by no means impossible. How to go about it is well understood. It's merely very expensive.
- Veserv 3y agoQuibbling about how "perfectly secure" is impossible is a complete red herring. Yeah, using known techniques cryptography is not perfectly secure, it will just take billions of times longer than the age of universe and billions of times more energy than exists in the entire universe to break it. It is a distinction without meaning. Making the computerized parts of a system go from 1 M$ to defeat to 10 G$ to defeat while employing human-error resistant design makes attacking the globally-addressable endpoint go from a cost of doing business to grossly uneconomical. It makes the cheapest, easiest, and most accessible way to attack into a nearly impossible wall and they have to look elsewhere to much less scalable vectors. You do not get the necessary 1,000,000% increase in security from 10% or even 100% improvements here or there. And you most certainly do not get it by listening to the people who are not even within a factor of 1,000x of knowing how to do it right.