5 ms·
Listening to this on cspan was...frustrating. These are people who only learned what the terms "network" and "line of code" mean a few months ago, using them a
by blhack 14y ago
Listening to this on cspan was...frustrating.
These are people who only learned what the terms "network" and "line of code" mean a few months ago, using them as if they are an authority on the topic.
And to hear some of this nonsense, about China being "an organized crime syndicate", or all the negativity about Russia.
Or about how they're doing all of this because they need to protect citizens from "cyber threats". FFS, guys, no. Look at the complete disaster of security that is the TSA. You're telling us that you're the ones that are going to protect us? Your understanding of what you're talking about is so limited that it took shutting down wikipedia, reddit, and countless other websites for a day to keep you from completely breaking the DNS a couple of months ago.
I think we're doing fine protecting ourselves from "cyber threats", guys, thanks.
[And yes, of course I realize that the "we're doing it for you!" is just nonsense.]
- tptacek 14y agoI know what a network is and I know what a line of code is. The underlying concern being addressed here is not invalid. We are not doing "just fine" protecting ourselves from "cyber threats". In fact, I don't know a single credible person working in software security who believes that. If anything, things in 2012 are far worse than they were in 2001: more critical systems than ever are networked, either directly to the Internet, to open GSM networks, or to proprietary RF. Those that aren't are virtually always one hop away from someone using completely vulnerable clientside software. Organized hacking syndicates in China are also not a made-up problem. I probably share your confidence in the Administration's ability to address the problem top-down, but comments like yours actually subtract value from the discussion. Any debate where you lead the opposition to things like CISPA dies immediately, because you've chosen to attack a totally valid premise instead of the specific arguments this bill or Obama's makes.
- PaperclipTaken 14y agoI think that to give the responsibility of security to the government is a fallacy, not only because the government is very capable of abusing the power and screwing up in a huge way, but also because it will make private companies less likely to take the appropriate measures to protect themselves. Defending yourself from an attack is almost always easier than being the attacker. You just have to know what type of technology you are working with and the inherent security holes in that technology. You don't need to blow millions of dollars on security unless you are already a company worth several hundred million dollars. And the other problem is that there will always be skillful hackers, and these hackers will always have the means and the knowledge to hide from the government, even if the government has access to a much greater percentage of information going through the internet. If the government has fancier tools to access things like email, hackers will be more careful/liberal with their use of encryption. I believe that this bill is going to work a lot like DRM. It's going to put hackers and civilians alike in a more uncomfortable position, except that the hackers are going to figure out how to work around it fast enough that its hardly going to make a difference, and the techno-ignorant (for lack of a better term) civilians will just have to deal with it.
- wglb 14y ago> Defending yourself from an attack is almost always easier than being the attacker. How do you figure that?
- Retric 14y agoIf you actually dig into things hacking has directly caused surprisingly little actual economic harm. The proactive and reactive response tends to be expensive, but in economic terms good old fashion fraud is still way more damaging. As to attacks by nation states, we are actually willing to respond with nukes if things cross a somewhat vague threshold and they are so unprotected as you suggest.
- tptacek 14y agoLike I said upthread: this was mostly true in 2001, when the power grid wasn't exposed to network attackers.