5 ms·
Fake security is a big problem to those of us who are concerned with real security. Mischievous and dishonest use of "security" as an cover by policy bullies,
by nonrandomstring 3y ago
Fake security is a big problem to those of us who are concerned with
real security.
Mischievous and dishonest use of "security" as an cover by policy
bullies, profiteers and other gangsters is as much a threat as worms,
viruses, zero-days, phishing scams, data leaks all other kinds of
actual security problem.
Not least because it weakens rational expectations and evaluations of
security and substitutes blind trust in (obviously untrustworthy)
entities.
Sadly, It's a powerful lever because the average person knows so little
about computer security and is easily bamboozled by scare-mongers.
Indeed, many phishing and malware scams start with a pop-up saying;
"Security Risk! You must update now!"
It is a form of extremely dangerous disinformation. For companies like
Google to engage in it for profit is treacherous and reckless.
- exe34 3y agoYou have to realise when a large tech company says "security", they mean their security from your attempts to defend yourself. E.g. most of the locking down of devices isn't to make it harder for attackers who want your data (which would defeat their own objectives) but to keep things like DRM keys from you.
- nonrandomstring 3y agoAbsolutely right. This is what I called "Zero Sum Security" (your security is my insecurity), and written about here [0] and discussed with Bruce Schneier. It's a sure sign of an underlying toxic and abusive relationship. [0] https://techrights.org/o/2021/11/29/teaching-cybersecurity/ https://techrights.org/o/2021/11/29/teaching-cybersecurity/
- charcircuit 3y ago>they mean their security from your attempts to defend yourself No, they don't. They are protecting against malicous actors or at the most buggy software doing bad things on accident. >most of the locking down of devices isn't to make it harder for attackers who want your data Advances in this area definitely has been happening. The move to apps getting their own sandbox and having to be explicitly granted permission to access files outside the sandbox definitely helps against this. No longer can malware just read and upload all of one's browser history and malware. Even if an attacker got physical access to the device they would not be able to just dump what's stored either due to encryption. >to keep things like DRM keys from you This should be pretty self explanatory, but of the security of DRM keys is bad then attackers can dump unprotected versions of the content which is against what creators that have elected for DRM want to have happen with their works.
- exe34 3y agoIn the first and second part, you've simply defined the very bad actors who want your data as the good guys. On the third point, we are in agreement. They want to make sure that when content right hoarders want to remove the content from the service you've paid for and move it to another service you now have to pay for all over again, you can't just keep a copy of what you already paid for. That's what I meant, keeping the device secure against you, who paid for it.
- charcircuit 3y ago>you've simply defined the very bad actors who want your data as the good guys. I didn't do this. Can you explain your thinking?
- hulitu 3y ago> No, they don't. They are protecting against malicous actors or at the most buggy software doing bad things on accident. By sending all my data to Microsoft or Google so they can sell it on the open market ? They are not "protecting against malicous actors". They fix bugs when they are openly exploited in the wild (hello Apple). BTW, what happened to ProjectZero ? Never heard from them for a while.