Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

101–110 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#101
post #76
post #71

Earlier quoted context omitted.

What you are describing is an example of of customers demanding non-testicle exploding drugs as why we don't have them. When a drug causes problems, customers often end up suing the manufacturer/developer of said drug. If doctors prescribe said drugs after it becomes common knowledge that it could cause a problem, they also might be sued for malpractice. Are people sing IoT companies for poor security practices? If s…

nobody's ever sued me for leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation to do exactly that. why? well, gosh darn it, because it's the right thing to do! i think the drive to reduce every bit of human behavior to economic incentives backed by a government force structure is ultima…

Good but me and I'm sure many other people will happily leave flaming of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly if nobody ever sued me.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#102
post #101
post #76

Earlier quoted context omitted.

nobody's ever sued me for leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation to do exactly that. why? well, gosh darn it, because it's the right thing to do! i think the drive to reduce every bit of human behavior to economic incentives backed by a government force structure is ultima…

Good but me and I'm sure many other people will happily leave flaming of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly if nobody ever sued me.

[deleted]

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#103
post #58

Earlier quoted context omitted.

> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)

Not necessarily. It could also be done by allowing people to sue makers of insecure software or hardware.

This is worse. This leads to lawyers making the critical decisions instead of regulators and auditors. The latter group at least has some familiarity with the subject area.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#104

Earlier quoted context omitted.

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.

We have FTC/FCC and EU/GDPR

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#105

Earlier quoted context omitted.

Customers can't evaluate security of IoT devices and, furthermore, they can't even evaluate what the downside of an insecure device is. So my printer is insecure- what does that mean for me? How much should I care? At least with cars, you know what an unsafe car can do (kill you) and it still took Ralph Nader's book and citizen pressure to set up a federal agency to oversee car safety. Also, even when most people kno…

They can for some of them if you give them this pic from Brian Krebs: https://krebsonsecurity.com/2012/10/the-scrap-value-of-a-hac... Got through to a lot of them that way. They were more likely to practice better computer security or buy less "smart" products that don't need to be smart.

That pic made my eyes glaze over. It's a good concept, poor execution.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#106

Earlier quoted context omitted.

Not necessarily. It could also be done by allowing people to sue makers of insecure software or hardware.

This is worse. This leads to lawyers making the critical decisions instead of regulators and auditors. The latter group at least has some familiarity with the subject area.

No, judges and juries decide lawsuits. They have the benefit of being harder to bribe than regulators.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#107

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

I'm not sure that companies responding to obvious market failures isn't the companies' fault. We're not some geoup of mindless automatans max/mining for profit (that's the purview of the ML at discussion here). Selling shoddy, dangerous wares should come with consequences.

>We're not some geoup of mindless automatans max/mining for profit

Haven’t spent much time around investment bankers huh?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#108

Earlier quoted context omitted.

But how can a customer demand security? There is nothing that a customer can do to choose a more secure IoT device over a less secure one. Even if you look at known vulns, simply having vulns in the past is not necessarily reflective of current security posture. Beyond pentesting an app, how does a consumer act on their desire for a secure device?

There's been security evaluations of products where evaluators do both checklist stuff and try to hack the product. Consumers could buy the stuff that gets cleared through those processes. For instance, there's products on the market like INTEGRITY-178B and LynxSecure designed specifically for securely partitioning systems. They have networking stacks available, too. On occasion, a company would make things like rout…

OK so now you have one good security certification and a dozen BS phony ones, and plenty of international drop ship / amazon fba sellers happy to counterfeit the legit certification. Now what?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#109
post #29

Fixing security is quite possible. Install a backdoor, go to jail for "exceeding authorized access". Fail to fix an security bug, get sued for negligence. Make it public policy that license contracts cannot override those responsibilities.

Start a marketplace and only accept listings for products certified to meet certain minimum security standards. Publish extremely clear and accessible guidance on the requirements and how to achieve them for certification. Gradually increase the requirements at a pace that the industry can keep up with. Advertise heavily on news reports of high profile security incidents.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#110

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

Here is the most classic and widely cited paper ever on market failure when customers can't tell what's good and what's a lemon: The Market for "Lemons": Quality Uncertainty and the Market Mechanism https://www.sas.upenn.edu/~hfang/teaching/socialinsurance/re... It's strikingly prescient that Akerlof mentions 'group insurance' as another market that is rife for failure due to a slightly different mechanism. Here we a…

That paper is interesting because it proved that the used car market doesn't exist. A proof of a false result is not a good proof.
Post reply on HN