Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

61–70 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#61

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

Customers don't demand non-testicle exploding drugs because that's already the standard in the same way that customers don't demand software that doesn't wipe their disks at random intervals, because software already doesn't (careless usage of dd notwithstanding).

If drugs started exploding testicles you can bet customers would start demanding they didn't (male customers at least). Just look at the Thalidomide incident, I've seen it in the news within the last decade and it happened nearly 60 years ago at this point.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#63

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

But how can a customer demand security? There is nothing that a customer can do to choose a more secure IoT device over a less secure one. Even if you look at known vulns, simply having vulns in the past is not necessarily reflective of current security posture. Beyond pentesting an app, how does a consumer act on their desire for a secure device?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#64

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

[deleted]

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#65
post #25

Earlier quoted context omitted.

The word Mickens uses is "interpretable", which financial infrastructure is, and ML models are not.

Financial IT is interpretable, maybe, but is the financial system itself? You have a lot of agents taking actions that you can't really interpret from outside - unless you say something vacuous like this person made this trade because they think it was good, at which point you may as well say this ai model made this decision because it thought it was good.

What does "the financial system" mean? Obviously there's a level you can address with that term where, just like with ML, interpretability becomes an open question. But on most every level that is genuinely comparable to the role an ML model plays in a software product, finance is plenty interpretable.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#66

Earlier quoted context omitted.

I think it's implicit in that proposal that the amount of software available would massively decrease. That's not necessarily a bad thing.

I think thats a ridiculous statement. Should we also limit how many books are written and who can write them? What is the difference?

If you buy a book and it turns out to be trash, is that negligence on the part of the author? Is your safety at risk because of it?

You could maybe argue that this is true for textbooks, but not much else.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#67

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

No. There are potential regulatory principles here that have nothing to do with the customer's demands. You sound like you are assuming a free-market, free-enterprise situation. That is not reality. There are hundreds of years of regulatory norms in other domains. https://en.wikipedia.org/wiki/Precautionary_principle

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#68
post #12
post #2

"Using case studies involving machine learning and other hastily-executed figments of Silicon Valley's imagination, I will explain why computer security (and larger notions of ethical computing) are difficult to achieve if developers insist on literally not questioning anything that they do since even brief introspection would reduce the frequency of git commits." For anyone who hasn't heard a James Mickens talk, do…

He's the guy who wrote the Slow Winter. He's hilarious. https://www.usenix.org/system/files/1309_14-17_mickens.pdf

It'd be more hilarious if he didn't reference real problems with no obvious solutions short of a painful dismantling of our heavily exploited societal constructs.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#69

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

Misapplications of ML are not demanded, they are sold. Demand is for clean solutions, not dirty ones that make new problems. The selling is where false confidence in broken solutions gets made. Greed is sitting at the root of institutional incompetence in most situations.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#70
post #47

Oh boy Mickens must really hate blockchains and uncensorable platforms like a̶s̶s̶a̶s̶s̶i̶n̶a̶t̶i̶o̶n̶ prediction markets

"Blockchains Are a Bad Idea: More Specifically, Blockchains Are a Very Bad Idea." https://www.youtube.com/watch?v=15RTC22Z2xI

eh that was a pretty bad lecture. Most of the technical problems he talked about are easily solvable.
Post reply on HN