4 ms·
It seems that with current methodology that the attack surfaces simply continue to grow at a faster rate than defensive measures can keep up. Is there any hope
by TTPrograms 12y ago
It seems that with current methodology that the attack surfaces simply continue to grow at a faster rate than defensive measures can keep up. Is there any hope of competing?
My gut instinct is that the path to robust security lies in building systems with languages that enable proving statements about security (ex prove that this thread can't access data outside of its sandbox etc.). Human programmers are simply too fallible (myself included!). I've heard of some research being done in this area with regards to OS kernels.
Do people believe that these sorts of approaches will have a major impact? Or will computer systems security always be an arms race?
- higherpurpose 12y agoThat's because we're trying to "smartify" everything and with each new category of product getting smartified we are repeating the same old mistakes we did with PCs. We need solid security design thinking for each product we create and we need to think about security consequences for every new feature we add. Also, we need to ensure that the products can be easily updated (in a cryptographic secure way) for at least 80 percent of the product's life cycle. Right now most manufacturers are using the "Sell it and forget it" model in regards to security updates for their products. If the companies don't treat security seriously by themselves, then there should be laws forcing them to do it and agencies auditing them for it. After all, all of these smart products are our "cyber infrastructure", and the government seems to be bragging a lot about wanting to protect that (even though I know it's just using that as an excuse to increase its surveillance powers). Also, it's one thing if your coffee maker gets hacked, but we're going on a dangerous path of smartifying cars (and probably even trains and planes in the future) even to the engine level, which means you could literally be assassinated over the Internet in the near future.