4 ms·
My colleagues and I submitted a similar talk/paper for a different NCSC conference (but weren't accepted). I see that this talk by Bert Hubert covers mostly the
by nonrandomstring 2y ago
My colleagues and I submitted a similar talk/paper for a different
NCSC conference (but weren't accepted). I see that this talk by Bert
Hubert covers mostly the ground. so I am pleased, but worried about
what this take misses out.
Hubert is addressing much of the ground that lies between security and
resilience.
Our emphasis is on how mitigation lies in education and autonomous
systems over regulation. Not that regulation is wrong, just that it
doesn't work as a stick without a carrot. We also looked at timescales
and how so much is already too late because of the lag-time from
drafting to efficacy. And what I know from hanging out here on HN is
that technologists appear hostile to regulation, but giant companies
love it so long as they get to write the rules that give them more
monopoly power.
Where we went wrong I think is lack of political tact. Hubert stops
himself from even finishing off the remark about the quality of
Microsoft products. But I don't think the real problem can be ignored
for much longer. Instead, we went all-in and emphasised (as
previously here [0]) that "Big Tech is the cybersecurity problem"
(as Bruce Schniere recently echoed) because it pushes (in addition to
highly centralised single points of failure) an irresilient
"insecurity industry" that is based on protection not security.
Hubert's talk doesn't get to the key issue;
Security and protection are not the same thing.
Protection leads to dependency that ultimately erodes real security.
However "protection" is easy and profitable to sell. Real security is
not.
That is ths succinct way in which it must be put.
If the intel appraisal is accurate and we are entering a serious war
footing than we can have no more patience for the profitable but
dangerous "insecurity industry" that gives an appearance and
simulation of security, without the reality.
[0] https://techrights.org/o/2021/11/29/teaching-cybersecurity/ https://techrights.org/o/2021/11/29/teaching-cybersecurity/
- m3047 2y ago"Security" is not the same thing itself, it cleaves meaning: 1) Hypervigilance; which is unsustainable. 2) Carefree ease; which is what the champion Red Bull athlete achieves from constant practice and repetition. I thank Kelly Shortridge (https://kellyshortridge.com/blog/posts/ https://kellyshortridge.com/blog/posts/) for pointing out the cleavage.
- nonrandomstring 2y agoThese are interesting distinctions. I'm working on distinguishing a whole cluster of things that frequently get collaopsed into the same mushy confusion; security, safety, reliability, resilience, protection, sustainability... And there's also inner and outer security, which I think your remark addresses. Thanks for the link which I wasn't aware of.
- m3047 2y ago@nonramdonstring: The email address hr@... in your profile is broken. You're welcome to try the one in my profile.
- nonrandomstring 2y agoThankyou for telling me. I may have missed other coms, my apologies.
- m3047 2y agoIn spite of my typo in the parent, I really did send to hn@. I just checked the bounce to be sure.