7 ms·
I’ve been thinking about this topic thru the lens of moral philosophy lately. A lot of the “big lists of controls” security approaches correspond to duty ethic
by sharkbot 2y ago
I’ve been thinking about this topic thru the lens of moral philosophy lately.
A lot of the “big lists of controls” security approaches correspond to duty ethics: following and upholding rules is the path to ethical behaviour. IT applies this control, manages exceptions, tracks compliance, and enforces adherence. Why? It’s the rule.
Contrast with consequentialism (the outcome is key) or virtue ethics (exercising and aligning with virtuous characteristics), where rule following isn’t the main focus. I’ve been part of (heck, I’ve started) lots of debates about the value of some arbitrary control that seemed out of touch with reality, but framed my perspective on virtues (efficiency, convenience) or outcomes (faster launch, lower overhead). That disconnect in ethical perspectives made most of those discussions a waste of time.
A lot of security debates are specific instances of general ethical situations; threat models instead of trolley problems.
- xxpor 2y agoSecurities laws are written in terms of duty ethics ("fiduciary duty", "duty of due care", etc). That's all anyone at the top would care about.
- immibis 2y agoIt quickly turns into: what can I get away with, while claiming I performed the duty?
- xxpor 2y agoAgreed!
- immibis 2y agoIt gets worse than that: it rewards people who try to break the law as much as possible without getting caught, while people who follow it are punished. That's true of most laws, but the system punishes law breakers to make it better to follow the law overall. When the law is vague and subjective, the people who get the most reward are the ones who are willing to see how far they can push it.
- jiggawatts 2y agoI work at medium to large government orgs as a consultant and it’s entertaining watching beginners coming in from small private industries using - as you put it - consequentialism and virtue ethics to fight against an enterprise that admits only duty ethics: checklists, approvals, and exemptions. My current favourite one is the mandatory use of Web Application Firewalls (WAFs). They’re digital snake oil sold to organisations that have had “Must use WAF” on their checklists for two decades and will never take them off that list. Most WAF I’ve seen or deployed are doing nothing other then burning money to heat the data centre air because they’re generally left them in “audit only mode”, sending logs to a destination accessed by no-one. This is because if a WAF enforces its rules it’ll break most web apps outright, and it’s an expensive exercise to tune them… and maintain this tuning to avoid 403 errors after every software update or new feature. So no-one volunteers for this responsibility which would be a virtuous ethical behaviour in an org where that’s not rewarded. This means that recently I spun up a tiny web server that costs $200/mo with a $500/mo WAF in front of it that does nothing just so a checkbox can be ticked.
- tryauuum 2y agocan it even be considered a firewall if it's running in an "audit only mode"?
- TeMPOraL 2y ago(Corporate IT sec answer): it says "firewall" in the name, so yes.
- jiggawatts 2y agoThis is the correct answer! Every corporation over a certain size has a rule that everything needs a firewall in front of it… even if the something is a cloud service that only listens on port 443.
- lll-o-lll 2y agoSo WAF. Bad? I don’t know enough about it. If it’s just a way to inject custom rules that need to be written and maintained, the value seems low or negative. I had hoped you got a bunch of packages that protected against (or at least detected) common classes of attacks. Or at least gave you tools in order to react to an attack?
- treflop 2y agoI don't think this is limited to security. I have friends who are very scary drivers but insist on backseat driving and telling you about best driving practices, and coworkers who are insistent on implementing excessive procedures at work but constantly are the ones breaking things. I think following rules gives some people a sense of peace in a chaotic and unpredictable world. And I can't stand them.
- CSSer 2y agoDo you mean the rules or the people? I don’t mean to sound facetious.
- deleted 2y ago[deleted]
- treflop 2y agoA little of both. I understand getting a warm fuzzy feeling that you did the right things, but if you don't achieve your goal, what's the point? But let me clarify -- OP mentioned a contrast between consequentialism and virtual ethics and I think you can be "too much" consequentialism too. I'm wouldn't call myself a rule follower but I also follow rules 99% of the time too. It does create a sense of order and and predictability and I value that. There is a right balance where you do follow rules but you also know when to break them. What I can't really stand are rigid people -- diehard rule followers or diehard "no one can tell me what to do." I find working with rigid people hard because you have to work around their "buttons."
- awesome_dude 2y agoOften the reason that they know all of these rules is because they are constantly being bitten/yelled it for breaking them Speaking as someone who is constantly trying to keep good procedures in the team because of all the footguns I have collected over time
- DyslexicAtheist 2y agoI recall a grugq podcast several months back in which they compared it to a "chastity pledge", wish I had the exact episode.