4 ms·
When will people, especially the tech illiterate ever learn that security via obscurity doesn't really work when you've got marginal cost of duplication. [Of co
by sigkill 13y ago
When will people, especially the tech illiterate ever learn that security via obscurity doesn't really work when you've got marginal cost of duplication. [Of course, it's a bad idea for even tangibles but in the electronic world it's a totally broken concept]
- bdg 13y agoThis theme has been around for decades and only underlines the inability of decision makers to make rational decisions on things they lack a fundamental understanding of. I suppose the lesson here is: honor and honesty gets you in hot water when you deal with people who have lots of money. Better to make the devices in your garage and sell them to criminals. I'm sure this paper isn't the thing holding criminals back from making them anyway... anyone who's looked at their key-fobs knows they aren't exactly high security RSA encrypted signals. ( http://hackaday.com/2010/07/13/key-fob-programming/ http://hackaday.com/2010/07/13/key-fob-programming/ )
- sigkill 13y agoWhich is why I added the "marginal cost of duplication" part. I understand that security via obscurity has been practically the only thing that's been happening. Hell, a simple talk to our own parents (mine're 50+, somewhat tech inclined but nothing deeper than the basic word editing, and web browsing) in relation to this reveals that they think "you shouldn't tell your secret to the whole internet", little realizing that publishing it will actually help you plug the holes. The problem is, as long as it was a physical object it was all fine, sort of atleast. You could put anti tamper mechanism (like safes with relockers) that would destroy the core technology/secret if someone tries to pry it apart. But with computer code and mathematics, it's guaranteed that the attacker/pryer is able to make millions of duplicates at zero extra cost. So if approach #564 doesn't work, all he has to do is cp ../downloads/file ../project/reverseengineer/ and boom he has another copy to work with. The only thing holding an intruder out of a system is the solidity of the mathematical concept that system is based on. And now that the intruder knows that there's a break, and that he potentially will gain a lot by discovering it, he can continue unhindered. Obviously I'm preaching to the choir, but if you've encountered such people you should give this analogy. In the real world, the guy needs to buy your widget each time he fails to reverse-engineer the anti-intrusion mechanism, but if he were able to make a 100% replica copy of the widget and work on that copy he could try everything. So if he fails once, he'll just make another copy and try a new approach at opening your widget. He knows it's broken, and there's no real extra "cost" associated with duplicating the widget to try again, there's literally no stopping him until he gives up. Another thing that crossed my mind was this. The manufacturers would want to keep this knowledge (i.e. that the exploit exists) secret, but ~~if~~ when he discovers the backdoor, do you want to be considered responsible for your car being stolen instead of the manufacturer for the manufacturer's mistake? Would you not prefer that the manufacturer calls you and recalls your car to the garage and replace it with a better part? It's a shame because Bentleys, Porsches, and Audis are NOT cheap. You're paying for the name, and at times like this, when the name comes under fire they should do something and stand by their customers instead of against them.
- venomsnake 13y agoActually it is even worse. It also damages brands much more. From what is known for the hack it requires some very direct access to the car. So we transform "Researchers are able to unlock Ford car given they have few hours to bruteforce and a laptop an a secluded place" to "Research that is so dangerous, the court outlawed it"