3 ms·
This article is fundamentally missing the point of why computer security is incomplete: even if we wanted to, we are currently not able to make useful systems t
by oneplane 2y ago
This article is fundamentally missing the point of why computer security is incomplete: even if we wanted to, we are currently not able to make useful systems that are also secure to the degree that the current user base is still able to use it.
We don't need to "work on keeping it insecure", the entire industry produces bad software just fine, no active planning required. Hanlon's razor applies, even if there are a double digit set of examples where a backdoor (or similar) was added. Especially when you consider that next to the backdoor the front door is wide open anyway.
- fpoling 2y agoWe are perfectly capable of producing reasonably secure systems, but the present situation made that not cost-effective. It is strictly cheaper to apply security as an after-thought or even ignore the issue completely and just pay off the penalties later.
- Veserv 2y agoWhat do you mean by reasonably secure system? Secure against commercially motivated attackers issuing profitable attacks that, these days, routinely payout 10-50 M$? Such security would need to be adequate to protect against 10 M$ budgets, or teams with a resource budget of 10-30 skilled people for a year (10-30 person-years). If that is not the minimum standard, then I do not see how it can be claimed to be a reasonably secure system if commonplace, expected threats with incentive to execute indefinitely are not stopped. If that is the standard, what do you mean by capable of producing such systems? Do you mean that large commercial software developers (i.e. Google, Microsoft, Amazon, etc.) have the existing knowledge and capability to develop and deploy such systems without fundamentally throwing out and redesigning their systems from scratch? If so, then that is untrue. If you merely mean that there exists or has existed such capability somewhere and that it could be reinvented or relearned with appropriate incentives, then that is true. However, that would require fundamentally redesigning basically every commercial software system and has a time horizon of years to decades even with the incentives properly aligned and having a iron will to reject insecure software systems despite the complaints by their producers which has not worked so far.
- fpoling 2y agoAccess cards for satellite TV or SIM cards are great examples of reasonably secure systems. Surely probably for 1M$ one can hack single card, but it will be wildly unprofitable. Which demonstrates that with the right insensitive industry can develop secure stuff. And the card development took like 10 years. And it was a highly non-trivial job as it required to develop entirely new hardware. With software it must be easier. The big IT companies most likely are incapable of doing that as the security was never a hard requirement for them from the very start so it is not in their DNA and at this point they are themselves are security liability. Smaller companies on the other hand should be capable of producing software withing the right legal framework that only state actors can hack. EDIT: case in point is Google trying to prevent double-free bugs in Chromium using smart-pointers. What was originally planned to be one-year efforts took like 3 years and counting just because Google cannot afford a few percent point performance regression and various teams working on Chromium do not prioritize the relevant non-performance bugs.
- rstuart4133 2y ago> even if we wanted to, we are currently not able to make useful systems that are also secure to the degree that the current user base is still able to use it. I disagree. We have computer systems now that are secure which the vast majority of people have no trouble using: phones and tablets. They are so secure band-aids like CrowdStrike and similar anti virus measures aren't needed on them. We've known for decades that desktops, such as Windows, MacOS and the majority of Linux use a broken security model. We know why it is broken: you can't trust the owner of the device, be that joe citizen or a corporate. Joe citizen will be socially engineered into installing something the modifies the OS, turning it into malware that can't be repaired. The corporate will buy something like CrowdStrike, which is essentially the same trick in a different guise: con the owner into installing something that makes the attacker money. A absolute precondition for an OS guaranteeing it is secure is it can't modified by a third party, and that includes the user. Yet we persist in providing OS's that do allow the user to modify them, and then pretend papering over that with things like anti-virus programs fixes the problem. We've also know for decades secret proprietary code that is so secret it comes with a licence that bans you from attempting to pull it apart and looking for vulnerabilities (via a licence banning you from reverse engineering), is pure poison for security. I need to have 100% faith Juniper does not have a backdoor, or and Microsoft is not still allowing MD5 signed certs in critical parts of it's infrastructure. Despite all that it's true that here we are in 2024, still using things that are insecure by design, and still buying hidden proprietary code from vendors that have included backdoor passwords in their products in the past. I'm not sure it is a political problem, but it sure isn't a "we don't know how to do better" problem. We do.