Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

51–60 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#51

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

>IoT devices aren't secure because their customers don't demand security.

This is hard for me to agree with, because as a consumer literally ALL THE TIME I notice small things product designers do because they know better but that I am sure none of their customers noticed, or read about in reviews or something.

Producers often know better and do the right thing just because they're the experts, and even though nobody demands it.

It's just that IoT security is not something that these experts can do.

To use a recent cupcake analogy, it's as though every single bakery in the entire world that sold cupcakes, sold ones that to the few people who actually have good taste (which includes you and me) actually tastes like shit. Why do the bakers only sell cupcakes that taste like shit? Because nobody demands cupcakes that don't taste like shit? No, because if the bakers knew how to then at least some of them would be selling good cupcakes. It's because a good cupcake recipe doesn't exist anywhere on the planet. Anybody who is making a cupcake is making a shit cupcake. This is the state of iot security: the experts are shit at it. You and I notice.

If the experts figured it out then bakeries would follow. What, you don't think anyone who goes through the trouble of manufacturing and boxing a product bothers to Google "how to make a secure IoT device" and read what they find? Of course they do. What they find is "hahaha whatever."

It's as though if you Googled "best cupcake recipe" all of the top hits said "I don't know mix some flour and butter and bake for a while, put some frosting on it. Whatever, it's a cupcake."

Here is the link: https://www.google.com/search?q=how+to+make+a+secure+iot+dev...

Do you see a single useable recipe there? I don't. All I see is "I don't know, mix some flour and butter and bake it? Put frosting on it. Beats me."

An actual cupcake requires milk, sugar, baking powder, eggs, and an actual recipe. Maybe some vanilla essence. These aren't even listed.

If the state of the art is shit, blame the state of the art.

A secure IoT device is like a watermelon soufflé. You're on your own.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#52
post #29

Fixing security is quite possible. Install a backdoor, go to jail for "exceeding authorized access". Fail to fix an security bug, get sued for negligence. Make it public policy that license contracts cannot override those responsibilities.

In the not too distant future: all security vulnerabilities are resolved by updating the documentation to include mention of a previously omitted feature.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#53

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

Customers can't evaluate security of IoT devices and, furthermore, they can't even evaluate what the downside of an insecure device is. So my printer is insecure- what does that mean for me? How much should I care?

At least with cars, you know what an unsafe car can do (kill you) and it still took Ralph Nader's book and citizen pressure to set up a federal agency to oversee car safety. Also, even when most people know that seatbelts are a good idea, we still have seatbelt laws because they mean fewer people die.

https://en.m.wikipedia.org/wiki/Unsafe_at_Any_Speed?wprov=sf...

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#54

Earlier quoted context omitted.

>Make it public policy that license contracts cannot override those responsibilities. This would be a disaster for open source. Who wants to write software for free if you can get sued for a bug?

I think it's implicit in that proposal that the amount of software available would massively decrease. That's not necessarily a bad thing.

I think thats a ridiculous statement. Should we also limit how many books are written and who can write them?

What is the difference?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#55
post #22

Earlier quoted context omitted.

This guy looks like the one who wrote those satire magazine-style articles.

He is that guy. Mickens is a legend.

But how can we be sure? Maybe there are two people with the same name who look exactly alike with the same writing style. If we put them all on the blockchain, do they have the same hash?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#56

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

Customers can't evaluate security of IoT devices and, furthermore, they can't even evaluate what the downside of an insecure device is. So my printer is insecure- what does that mean for me? How much should I care? At least with cars, you know what an unsafe car can do (kill you) and it still took Ralph Nader's book and citizen pressure to set up a federal agency to oversee car safety. Also, even when most people kno…

Maybe they shouldn't have those devices then.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#57

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

[deleted]

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#58

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

> They are instead classic examples of market failure.

The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry.

(The software engineering industry is, I would argue, drastically under-regulated.)

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#59

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

Here is the most classic and widely cited paper ever on market failure when customers can't tell what's good and what's a lemon:

The Market for "Lemons": Quality Uncertainty and the Market Mechanism

https://www.sas.upenn.edu/~hfang/teaching/socialinsurance/re...

It's strikingly prescient that Akerlof mentions 'group insurance' as another market that is rife for failure due to a slightly different mechanism. Here we are 50 years later failing to understand this economic lesson.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#60

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.
Post reply on HN