12 ms·
Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake
by nullderef 2y ago
Breaking the email system so that it's not sent is the cherry on top. With companies as big as Google who have developed so many products, "security" feels fake. If every line of code is a possible vulnerability, with millions it's just inevitable. It feels like the only way is to keep things simple (e.g., deprecate the recorder site), but even then.
- robin_reala 2y agoUnfortunately with the number of users Google has, any deprecation will be met with cries of pain / I-rely-on-the-spacebar-to-heat-up-my-computer. See https://killedbygoogle.com/ https://killedbygoogle.com/.
- ramon156 2y agoSide note, what is that reference from? Searching "i rely on the spacebar to heat up my computer" directs me back to this comment (6 mins ago).
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- cfreksen 2y agoIt is a reference to the following XKCD comic: https://xkcd.com/1172/ https://xkcd.com/1172/
- deleted 2y ago[deleted]
- mjgant 2y agohttps://xkcd.com/1172/ https://xkcd.com/1172/
- klabb3 2y agohttps://xkcd.com/1172/ https://xkcd.com/1172/
- deleted 2y ago[deleted]
- croisillon 2y agoyou're one of today's lucky 10,000
- Y_Y 2y agohttps://xkcd.com/1053/ https://xkcd.com/1053/
- aeonik 2y agoThey really aren't shy about massive breaking changes. I'm still upset about Google Reader. https://killedbygoogle.com/ https://killedbygoogle.com/
- highcountess 2y ago[dead]
- Y_Y 2y agoMany of us are still upset about Reader. It definitely felt like a watershed moment between the old cool Google who sent pizzas to hackers and had clean fast web design and weren't evil. I'd be so glad now to give up on Google and all its enshittified shit. I could give up things that are still super useful and I get value from every day: YouTube, Gmail, Play Services, Drive, Maps. But I don't think I could give them all up at once. I've been trying to migrate to Proton and OpenStreetMap and some kind of real Linux phone etc, I don't even mind if I have to fiddle around before everything works. The trouble is that the claws are in, but they're not in me. Remember when Google proudly didn't advertise themselves? They got to critical mass through word of mouth, from having a compellingly better product. Now what they have is network effects and locking. They used to appeal to developers and techies because and that ended up making the services better for everyone. Now like all the other tech giants they have PHB's optimizing for the next millisecond of attention and Microdollar of ad revenue from a lowest-common-denominator victim. Google is so big that it's a significant part of life for a significant proportion of the world. When Google is shit it moves the needle on net human suffering. I think the UN should be focussing on prevent war and trying to salvage our environment, but if they aren't going to do that then it might be rational to just form a worldwide consumer group to take on megacorps.
- jfengel 2y agoI didn't use Reader. What was so special about it? Iirc it was an RSS aggregator, which sounds pretty simple to replace. Nobody has an open source equivalent?
- myrion 2y ago
- hkwerf 2y agoYou're essentially suggesting a Drake equation [1] equivalent for the number of security vulnerabilities based on NLoC. What other factors would be part of this equation? [1] https://en.wikipedia.org/wiki/Drake_equation https://en.wikipedia.org/wiki/Drake_equation
- maximus-decimus 2y agoHow close to the Balmer peak the programmer was when he wrote the code.
- bobnamob 2y agoCorrelated or inversely correlated?
- CSMastermind 2y agoLanguage or framework definitely plays a role (isn't that what the Rust people are so excited about). Maybe say like the materials/tools used. There's definitely some measure of complexity. I still like simple cyclomatic but I know there are better ones out there that try to capture the cognitive load of understanding the code. The attack surface of the system is definitely important. The more ways that more people have to interface with the code, the more likely it is that there will be a mistake. Security practices need to be captured in some way (maybe a factor that gets applied). If you have vulnerability scanning enabled that's going to catch some percentage of bugs. So will static analysis, code reviews, etc.
- zwnow 2y agoThe point is: security is fake. No app is truly secure. You can spend millions on app security and all it takes to breach that is one slip up of a human user.
- TheDong 2y agoI'd take away "security is complicated and multi-faceted", not "fake". It's not a black and white of "an app is truly secure" or "an app is truly insecure", but rather a continuum from "secure enough in practice for this threat model and purpose" to "an insecure mess". Like, plenty of websites and apps have launched, existed for years, and then shutdown without a single security incident. In those cases, surely the app was secure, right? At least secure enough? Signal so far has been "secure enough in practice" for most people, while iMessage has in practice been "secure enough if you're a normal person, but with serious security issues for anyone who might be subject to serious targeted attacks" Say more about what you mean by "no app is truly secure"? Especially in the context of signal?
- zwnow 2y agoIm just saying that all it takes is one employee to click onto the wrong URL to breach your apps security. I am not talking about the app itself. You can have all the security implemented the world has to offer and yet you cant get rid of human errors.
- TheDong 2y agoI'm totally not understanding what you're saying then. > Im just saying that all it takes is one employee to click onto the wrong URL to breach your apps security Pretend I'm a signal employee. What link can I click that breaches the app's security? They don't store unencrypted data, pushing source code changes requires review, releases are signed and a single employee can't compromise the release process, so I'm missing how one employee being compromised could lead to the signal app breaching signal's security. Also, in practice, how often are apps compromised from a phishing attack? I don't even really see news reports on that, so I'm curious if you're operating off like a specific case or something.
- rpigab 2y agoThat's probably another reason why Google kills so many products that are successful, but not successful enough for Google's whole system to justify keeping them alive and secure.
- echelon 2y ago100%. Every product not a part of the core mission is attack surface area, ongoing maintenance to ensure it works with the rest of Google services and infra, and drag on the rest of the team and velocity. The part that sucks for consumers is that they often kill things that people like. I wish they had a better way of doing this. Bravo to brutecat for this excellent discovery, productionization, and writeup.
- zoklet-enjoyer 2y agoThey could spin these products off into separate companies and cut the integration with the rest of the Google ecosystem.
- echelon 2y agoProbably way too much effort. The apps aren't built for generic infra, but rather Google's internal weirdware. It wouldn't be possible to run it anywhere else without a rewrite.
- throwaway2037 2y agoI agree, and I like this term "internal weirdware". Real question: Why don't we see more start-ups try to clone old terminated Google services with a freemium model?
- scarface_74 2y agoPeople don’t want to pay for things.
- vladms 2y agoI would challenge you to give me examples where security feels "real" and how does that help. Most software products rely on very complex software stacks, and if you trust 100% all the libraries and the OS you use I would say it's a wrong mindset. There were bugs even in the processor (meltdown). Security is a continuous battle and you never know if you won, only (sometimes) if you loose.
- tialaramex 2y agoYou can tell security is real the same way as lots of other things, reality doesn't give a fuck. Like how you can tell the difference between man's laws (e.g. "The Offside Rule" or "Constitutional Rights") and Mother Nature's laws (e.g. Thermodynamics). Try it, kick the ball even though the rule says you mustn't - if you get lucky the referee doesn't notice and play continues. But if you try to make a system more ordered without expending energy it does not work. Reality doesn't give a fuck. When I breeze through your login process with the wrong credentials that's because your security was fake, if it was real that would break because it didn't know who I was, so if some bug lets me past login I don't somehow successfully log in as me, I'm logging in as nobody at all which is clearly nonsense. This is "Make Invalid States Unrepresentable" at scale, and it's difficult to do, but not impossible.