9 ms·
Computer Security Is a Political Struggle
- ThinkBeat 2y agoIs there a trustworthy source for this claim¹ the post makes? It does not conform to what I see today, nor the plans I see for the future when it comes to governments use of software. ¹ "" Thankfully the political systems of Europe have started to wise-up and stand-up to US BigTech hostility and have mandated that all software used for public services, government and state apparatus must be Libre open source code that is auditable, verifiable and under control of the people. ""
- TZubiri 2y agoDon't get me wrong this is some schizo shit, but I agree with the sentiment, and it in itself is a source for the claim. What would you expect a double blind trial measuring political bits in cybersecurity atoms?
- ThePowerOfFuet 2y ago>some schizo shit Please don't smear those with mental illness like this.
- krageon 2y agoIt is not true, source: I work for an institution that would be impacted by such a ruling. There are requirements for sovereignty, but as usual people play fast and loose with the concept. Governments are not more competent than anyone else.
- harry_ord 2y agoThe statement is so vague it can't be true anyway. What's Europe? The continent, the EU or one of the organisations that EU membership often come with?
- krageon 2y agoI actually know what I'm talking about. You're free to disagree and "just ask questions", but I don't want to engage with tedium.
- PaulHoule 2y agoWhen the German open source enthusiasts and penny pinchers legislate government employees using open source office software the employee's union fights back.
- j-pb 2y agoCould you cite your sources? The only thing that I could find was that VerDi has a very good stance being PRO open-source software, and ANTI encryption and chat backdoors: ver.di setzt sich ein für die Nutzung und Förderung von Open-Source-Software durch den deutschen Staat, indem er in Verwaltung, Behörden und staatlichen Organisationen so weitgehend wie möglich Open-Source-Software nutzt. Zudem soll die Entwicklung von Open-Source-Software finanziell und institutionell langfristig gefördert werden. Dies gilt ebenso für die benötigte Hardware-Infrastruktur. Wenn der Staat Software programmiert oder in Auftrag gibt, muss diese Open Source sein. Dadurch macht der Staat sich unabhängig von einzelnen Anbietern und langfristig werden Kosten gespart, da weniger Gebühren für Lizenzen anfallen. https://www.verdi.de/ueber-uns/bundeskongress-2023/berichte/++co++4f0a162e-5923-11ee-a88e-001a4a16012a https://www.verdi.de/ueber-uns/bundeskongress-2023/berichte/...
- jeffbee 2y agoI've been hearing this claim half my life. Slashdot used to have a daily story of how "Germany switches to Linux" and it always turned out to be that Linux got installed on one server in the bureau of steam-cleaning municipal dumpsters in a village nobody had heard of before.
- MSFT_Edging 2y ago> We are struggling with a broken model of "security" and the emergence of a global insecurity industry. I have a take that isn't too close to the focus of this article, but there is a big underlying point. There are known vulnerabilities in consumer and enterprise tech that are purposefully not closed in order to maintain a tactical advantage. Consider the tech used to break into phones, Pegasus. This is a highly visible peak of an iceberg in an otherwise massive industry of finding and weaponizing vulnerabilities that can have real world consequence, see WannaCry. This is both hugely political, and not political at all. It's almost a guarantee that a nation-state with cyber resources will use said resources to find a tactical advantage and constantly lob attacks back and forth. Each side will loudly exclaim "Look they're hacking us!" while staying quiet on their own attacks. You can set your watch to it. Basically any government is spending vast resources to find vulnerabilities and keep them open, which makes everyone less safe. Coupled with the constant war on encryption, gov sponsored "Cyber" is a money pit for hawks that wish to start trouble.
- JumpCrisscross 2y ago> almost a guarantee that a nation-state with cyber resources will use said resources to find a tactical advantage and constantly lob attacks back and forth Guns versus butter. There is probably a rational amount of cyber insecurity, given writing secure software comes with tradeoffs. (Nothing that comes with tradeoffs optimises to zero or infinity.) Perhaps being able to run insecure software is a form of peace dividend. Doesn’t cover intentional security holes. But we don’t have evidence that is a prevalent problem.
- arminiusreturns 2y agoActually we do have evidence it is a prevalent problem. A few data points ok, but we have repeated data points (at foundational pivot points) supporting it. (example: NIST infiltration and manipulation of encryption standards. Vault 7. etc).
- JumpCrisscross 2y ago> few data points ok, but we have repeated data points This is no evidence it’s a prevalent problem. It’s absolutely a problem. But I’m unconvinced we’re e.g. at a material military disadvantage or at economic risk as a result of it.
- oneplane 2y agoThis article is fundamentally missing the point of why computer security is incomplete: even if we wanted to, we are currently not able to make useful systems that are also secure to the degree that the current user base is still able to use it. We don't need to "work on keeping it insecure", the entire industry produces bad software just fine, no active planning required. Hanlon's razor applies, even if there are a double digit set of examples where a backdoor (or similar) was added. Especially when you consider that next to the backdoor the front door is wide open anyway.
- fpoling 2y agoWe are perfectly capable of producing reasonably secure systems, but the present situation made that not cost-effective. It is strictly cheaper to apply security as an after-thought or even ignore the issue completely and just pay off the penalties later.
- Veserv 2y agoWhat do you mean by reasonably secure system? Secure against commercially motivated attackers issuing profitable attacks that, these days, routinely payout 10-50 M$? Such security would need to be adequate to protect against 10 M$ budgets, or teams with a resource budget of 10-30 skilled people for a year (10-30 person-years). If that is not the minimum standard, then I do not see how it can be claimed to be a reasonably secure system if commonplace, expected threats with incentive to execute indefinitely are not stopped. If that is the standard, what do you mean by capable of producing such systems? Do you mean that large commercial software developers (i.e. Google, Microsoft, Amazon, etc.) have the existing knowledge and capability to develop and deploy such systems without fundamentally throwing out and redesigning their systems from scratch? If so, then that is untrue. If you merely mean that there exists or has existed such capability somewhere and that it could be reinvented or relearned with appropriate incentives, then that is true. However, that would require fundamentally redesigning basically every commercial software system and has a time horizon of years to decades even with the incentives properly aligned and having a iron will to reject insecure software systems despite the complaints by their producers which has not worked so far.
- dosinga 2y agoThe struggle of hacker against hacker is a what struggle?
- Buttons840 2y agoWe need strong legal protections for security researchers. "Red teams" should be protected so long as they responsibly report their findings and they should be given the benefit of the doubt. Security researchers should even be allowed to test the security of systems without permission. This is a matter of national security, and personal security. Why can't I personally test the security of my bank? Why can't I ask an organization I trust to test the security of my bank? Currently we threaten to jail security researches if they go so far as to press F12 and inspect the HTML source of a webpage. The personal data of half the nation is leaked twice a month. Companies have no financial incentive to build secure systems. Despite all this, we will be surprised when our critical infrastructure goes down and wonder "what more could we have done?" We sacrifice national security for the convenience of companies. Companies don't want researchers reporting the poor security of their systems. We allow companies to tightly control how their systems are tested, while also holding that companies are not liable for the security of their systems. When it comes to corporate security, they can have their cake and eat it too--they have authority over their systems but are not responsible / liable for their systems.
- hypeatei 2y agoGerman courts/laws seem to be very hostile to anyone exposing security flaws. I remember a story posted here where someone found a hard coded SQL connection string in decompiled code, connected to the server with it, and notified the company. Then, the company took the person to court (claiming something nonsensical about circumventing security) and the courts agreed. There was even people on HN siding with the courts that decompiling code and finding the key is circumventing their security which is madness.
- Joker_vD 2y ago> Why can't I personally test the security of my bank? For the same reason your bank can't test how well you store your PIN and secret phrase, I imagine. It's not in the contract between you and the bank, and the general law doesn't allow for it ("I was not trying to burgle that house, Your Honour, I was testing its security" — "That's a nice joke, mister, so I won't you hold in contempt of the court. Still, guilty, five years"). > Why can't I ask an organization I trust to test the security of my bank? For the same reason the bank can't ask an organization it trusts to test how well you store your PIN and secret phrase, I imagine: it's not in the contract. And good luck trying to find a bank that would agree to let you inspect their security.
- dash2 2y agoAfter reading half of this long, dramatic screed, I realised I had not been told a single new fact. I’ll skip the second half.
- nonrandomstring 2y agoCouldn't help but delve into your genuinely interesting take on revising social science theories to explain the rise of populism and decline of trust, including ideas from Robert Putnam who I've recently been reading for a study on the subject of "social capital". It felt odd that as a social scientist you fell short of the patience to read what a fellow scientist has to tell you about the lens through which you see the world - namely computers, solely on the basis that it disappointed your thirst for "new facts". Spoiler: FWIW, in the second half he elopes the scullery maid and challenges his arch rival to a duel...
- petermcneeley 2y ago>"The sooner we stop pretending these are technical problems and start speaking the truth about the fundamental political problems..." The problem is that cyberspace was designed to be apolitical [0]. Power abhors a vacuum and as such the traditional powers (gov/corp) once again reign supreme even in cyberspace. [0] https://www.eff.org/cyberspace-independence https://www.eff.org/cyberspace-independence
- jmull 2y agoThis kind of apocalyptic manifesto concerns me on two fronts... One, it makes me worry about the mental health of the author. They are clearly really not having a good time living in our reality, and I hope they can find a way to relieve the suffering. Two, I hope no one else gets caught up in it. There are a lot of strong words and claims but nothing remotely actionable. It's pushing pure panic/fear/angst. cloudstrike is just a company that is strong on sales/marketing but weak on tech, who found a market that requires you to be strong on both. I don't think there's anything wrong with such companies existing, but it seems clear they should never be in a position to break everything. The fix could be the market, regulatory, and/or technical. There are tradeoffs, so we probably need to work through the arguments of different approaches and different combinations of approaches.
- quohort 2y ago> One, it makes me worry about the mental health of the author. They are clearly really not having a good time living in our reality, and I hope they can find a way to relieve the suffering. > Two, I hope no one else gets caught up in it. There are a lot of strong words and claims but nothing remotely actionable. It's pushing pure panic/fear/angst. This made me laugh, it comes off as so condescending. Don't worry about my "mental health". The purpose of life is not to just be content all the time, it's to overcome suffering and achieve some level of self-actualization. If we are on the verge of the apocalypse, It should feel apocalyptic. The question is of how urgent the apocalypse really is (taken with a grain of salt to make room for the unknown) and what can be usefully done. > cloudstrike is just a company that is strong on sales/marketing but weak on tech, who found a market that requires you to be strong on both. I don't think there's anything wrong with such companies existing, but it seems clear they should never be in a position to break everything. I do think there is something wrong "fixing" security by just outsourcing your problems to some other company to monitor. Real security is about one's own operating practices and standards. Companies like cloudstrike don't necessarily increase security, they increase fragility because they act as a central point of failure. > The fix could be the market, regulatory, and/or technical. There are tradeoffs, so we probably need to work through the arguments of different approaches and different combinations of approaches. The author suggests that the problems are more systematic. I would say the fix is cultural: we have a flawed culture of outsourcing security to the market, regulators, or technology.
- Chiba-City 2y agoGreat article. Read all of it twice. Don't fixate on one or two sentences. I once worked in Fed Govt IT system. Remember the 2015 OPM (Office of Personnel Management) data breach? If not, read up on that (use a search engine). Over 22 million government personnel records were released into the wild. The Wikipedia article "blames China," but some folks told me that multiple agency personnel and multiple agency contractors had simply put everyday Fed Govt OPM spreadsheets on everyday Web sites to make them easy to share. "Experts" rarely grasp the everyday 1. incompetence, 2. indifference, 3. recklessness and 4. even corruption pervasive across and thriving in all our "elite institutions." We need to take Robert Salow's Productivity Paradox (look it up) very seriously. All the incentives line up for "experts" to sell more things and sell newer things. But we are often (always?) selling bandaids for the previous bandaids, while users (customers) are swallowing birds to catch the spiders to catch the flies. Solved problems cease being problems. That's sadly bad for the IT business.
- djyaz1200 2y ago[flagged]
- arrosenberg 2y agoIt's a bit more challenging when the attacks are coming from hostile nation-states that covertly or overtly support the crimes.
- djyaz1200 2y agoI get that it's easy to suggest solutions but hard to implement them. I just don't see how the security situation gets better without escalating the response. Does anyone else? How does this get better?
- arrosenberg 2y agoI don't see any group dominating the internet in the way Britain/the US have dominated the seas (eliminating most piracy). The only solution is to reach a détente with peer adversaries that everyone can live with, then jointly enforce it on smaller adversary states.
- wswope 2y agoNote to self: impersonate djyaz1200 when launching cyberattacks under the new world order.
- djyaz1200 2y agoYes, correctly identifying the perpetrators would be very challenging.
- ToucanLoucan 2y ago> Some group shut down over 50% of car dealers in America in June/July. That's warfare. You're not entirely wrong but also "Someone broke half the car dealers IT backends, this is WAR" is possibly the most American statement I have ever heard, holy cow. I CAN'T CONSUME PRODUCTS! TO WARRRR
- mikewarot 2y ago>We can't look to history for guidance. Sure we can. When's the last time a defective toaster took down a major power grid? Never. Because we don't place all of our trust in every appliance plugged in everywhere. We haven't done anything like that in more than a century. Equivalent mechanisms exist for computing. They can be made equally easy to use. We simply lack the will to upgrade everything and are willing to band-aid everything forever instead.
- proMETHeus69 2y agoFire is technology. It can be used well to serve us or can be used to destroy us. Consider the current phase of tech as early humans with fire sometimes accidentally (or on purpose) burning down their environment yet at the same time making food more accessible. We must create the fireplace, boiler, forge of technology and rules to produce and consume it safely or else we will continue to be burned as a human race. I am optimistic we will wrangle this problem how we did thousands of years ago for fire. Baby steps.