Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

91–100 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#91
post #83
post #61

Earlier quoted context omitted.

Customers don't demand non-testicle exploding drugs because that's already the standard in the same way that customers don't demand software that doesn't wipe their disks at random intervals, because software already doesn't (careless usage of dd notwithstanding). If drugs started exploding testicles you can bet customers would start demanding they didn't (male customers at least). Just look at the Thalidomide incide…

I think consumers are a little more savvy than people in this thread are giving them credit for. Sure, nobody want exploding gonads, but most folks couldn't give a whit if some overseas teenager manages to sneak a look at the contents of their driveway. People just want a cheap camera to catch their neighbors letting the dog poop in their lawn, and if it means becoming part of a botnot, who cares. The market has spok…

Consumers are not savvy as a group. There is always an "eternal september", new suckers born every minute, that can be abused. Beyond that, there are plenty of ways that you can maintain consumer trust while abusing it at the same time. You can sell them products that hurt them in ways they don't understand, and you can control the media surrounding your product enough to ensure that they don't understand. Advertising has a basic purpose of making people aware of products, but it also serves to mislead them on the value of things, overstating the benefits and understating the costs.

This idea that people understand the total consequence of what they do with their money is so simplistic that it's stupid. Markets don't "speak" from a vaccuum, they demand what their constituents are convinced is valuable, regardless of the accuracy of valuation. Lies sell garbage all the time and the consumer isn't to blame for wanting it, the professional, skilled, psychology-wielding liars who sold them on it are.

Hypothetical example: pay for a bunk study that concludes eating apples prevents hair loss, benefit for decades, with negligible repercussions to your business when the lie is uncovered. I'd be skeptical if you claim you can't identify several real examples yourself.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#93

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

The answer is that the customers demand it.

I have to say that this even more of a non-answer than the motivations Michens offers.

Sure, customers want X because it's trendy and seems to provide some vague value. But the underlying answer is customers are willing buy the latest crap damn-the-consequences because these particular customers are buying products whose failure mode is going to cost society a lot but isn't going them all that much. IoT being a prime example. The Internet light bulbs knocking out hospitals or whatever - no one is holding anyone accountable and that's great for someone.

Software failures and security failures so far involve remarkably low costs to companies compared to costs to society. Liability provides some disincentive for dumping battery acid in a river (though that seems to be lessening, sadly) but liability for running or selling crappy software is the stuff that dreams are made of.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#94

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

Customers can't evaluate security of IoT devices and, furthermore, they can't even evaluate what the downside of an insecure device is. So my printer is insecure- what does that mean for me? How much should I care? At least with cars, you know what an unsafe car can do (kill you) and it still took Ralph Nader's book and citizen pressure to set up a federal agency to oversee car safety. Also, even when most people kno…

They can for some of them if you give them this pic from Brian Krebs:

https://krebsonsecurity.com/2012/10/the-scrap-value-of-a-hac...

Got through to a lot of them that way. They were more likely to practice better computer security or buy less "smart" products that don't need to be smart.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#95
This was comic genius. It was also equally insightful. What a wonderful speaker and a wonderful talk. Did anyone else catch the the Bob Ross painting references during the graphic of the number 4? That had me in stitches.

Thank you for posting this. This made my day.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#96
post #3

James Mickens is pure gold https://mickens.seas.harvard.edu/wisdom-james-mickens

Thanks for the link. This is hilarious! > This World Of Ours: Wherein it is revealed that 1024-bit keys cannot prevent people from sending their credit card numbers to Nigerian princes. (I think that 1025-bit keys might solve the problem, but nobody listens to my common-sense advice.)

My favourite lne from my favourite Usenix paper:

"YOU’RE STILL GONNA BE MOSSAD’ED UPON"

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#97
In the section of the talk "how do we pick the wights of the neural net" the speaker states:

"the error then is going to be difference between what the classification of the neural net outputs and what the classification or the oracle will be."

Could someone say what is an "oracle" in this context?

He says this at 10:31 in the talk.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#98

In the section of the talk "how do we pick the wights of the neural net" the speaker states: "the error then is going to be difference between what the classification of the neural net outputs and what the classification or the oracle will be." Could someone say what is an "oracle" in this context? He says this at 10:31 in the talk.

The oracle = magic box that always gives the correct answer.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#99

In the section of the talk "how do we pick the wights of the neural net" the speaker states: "the error then is going to be difference between what the classification of the neural net outputs and what the classification or the oracle will be." Could someone say what is an "oracle" in this context? He says this at 10:31 in the talk.

The oracle in this case is a piece of software that compares the neural net's outputs with pre-classified data.

A test oracle "magically" knows the truth, from the perspective of the system, is the idea. Sometimes oracles don't even exist but can be useful as a conceptual tool in deriving some other finding -- such as a proof by contradiction.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#100

Earlier quoted context omitted.

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.

I agree, this is a core reason we have a government.
Post reply on HN