3 ms·
Which is why I added the "marginal cost of duplication" part. I understand that security via obscurity has been practically the only thing that's been happening
by sigkill 13y ago
Which is why I added the "marginal cost of duplication" part. I understand that security via obscurity has been practically the only thing that's been happening. Hell, a simple talk to our own parents (mine're 50+, somewhat tech inclined but nothing deeper than the basic word editing, and web browsing) in relation to this reveals that they think "you shouldn't tell your secret to the whole internet", little realizing that publishing it will actually help you plug the holes.
The problem is, as long as it was a physical object it was all fine, sort of atleast. You could put anti tamper mechanism (like safes with relockers) that would destroy the core technology/secret if someone tries to pry it apart. But with computer code and mathematics, it's guaranteed that the attacker/pryer is able to make millions of duplicates at zero extra cost. So if approach #564 doesn't work, all he has to do is cp ../downloads/file ../project/reverseengineer/ and boom he has another copy to work with.
The only thing holding an intruder out of a system is the solidity of the mathematical concept that system is based on. And now that the intruder knows that there's a break, and that he potentially will gain a lot by discovering it, he can continue unhindered.
Obviously I'm preaching to the choir, but if you've encountered such people you should give this analogy. In the real world, the guy needs to buy your widget each time he fails to reverse-engineer the anti-intrusion mechanism, but if he were able to make a 100% replica copy of the widget and work on that copy he could try everything. So if he fails once, he'll just make another copy and try a new approach at opening your widget. He knows it's broken, and there's no real extra "cost" associated with duplicating the widget to try again, there's literally no stopping him until he gives up.
Another thing that crossed my mind was this. The manufacturers would want to keep this knowledge (i.e. that the exploit exists) secret, but ~~if~~ when he discovers the backdoor, do you want to be considered responsible for your car being stolen instead of the manufacturer for the manufacturer's mistake? Would you not prefer that the manufacturer calls you and recalls your car to the garage and replace it with a better part? It's a shame because Bentleys, Porsches, and Audis are NOT cheap. You're paying for the name, and at times like this, when the name comes under fire they should do something and stand by their customers instead of against them.