Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

121–130 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#121
That's really a rather absurd statement. Improvement is always possible, it is about investment and time that delineates the percentage. If you are a security company, or concerned with security on an agent-state level, the sky is the exponential limit.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#122
post #58

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)

> The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry.

That's an excellent idea. I hope your country regulates the hell out of your nation's software industry. Meanwhile I'll buy a rake to help me gather all the money your economy will throw my way because somehow developing software in your nation became suddenly cost-prohibitive and your economy has no alternative to outsource it to nations unencumbered by regulation.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#123
post #58

Earlier quoted context omitted.

> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)

Not necessarily. It could also be done by allowing people to sue makers of insecure software or hardware.

> It could also be done by allowing people to sue makers of insecure software or hardware.

What about free/open source software? Should society punish those idiots who had the gaul to contribute their free time to a project that everyone can use free of charge?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#124

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

>IoT devices aren't secure because their customers don't demand security.

Apple offers the most secure devices, a tiny fraction of its consumer base demands security, or is even aware of how secure their products are.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#125

Earlier quoted context omitted.

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.

That's a great point made with a pretty suspect example. FDA very subject to regulatory capture.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#126
post #83
post #61

Earlier quoted context omitted.

Customers don't demand non-testicle exploding drugs because that's already the standard in the same way that customers don't demand software that doesn't wipe their disks at random intervals, because software already doesn't (careless usage of dd notwithstanding). If drugs started exploding testicles you can bet customers would start demanding they didn't (male customers at least). Just look at the Thalidomide incide…

I think consumers are a little more savvy than people in this thread are giving them credit for. Sure, nobody want exploding gonads, but most folks couldn't give a whit if some overseas teenager manages to sneak a look at the contents of their driveway. People just want a cheap camera to catch their neighbors letting the dog poop in their lawn, and if it means becoming part of a botnot, who cares. The market has spok…

Not just that but the customers informed enough to care can do it themselves. Most people on this site care about security, and most people on this site can set up their own home automation, servers, security camera, and/or speaker system. So the people buying these future botnet-nodes end up being the unsavvy inevitably.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#127

Earlier quoted context omitted.

This is worse. This leads to lawyers making the critical decisions instead of regulators and auditors. The latter group at least has some familiarity with the subject area.

No, judges and juries decide lawsuits. They have the benefit of being harder to bribe than regulators.

Only if you have money to get to court. Everybody else would be left depending on the good will of big companies. That's why courts should be the last resort, not the first. We need regulation, and if everything else fails the courts should be the way to go.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#128

Earlier quoted context omitted.

Not necessarily. It could also be done by allowing people to sue makers of insecure software or hardware.

> It could also be done by allowing people to sue makers of insecure software or hardware. What about free/open source software? Should society punish those idiots who had the gaul to contribute their free time to a project that everyone can use free of charge?

Cap it at the value paid for the product.

If it's given for nothing then that's what can be charged for it's failure, nothing.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#129
post #76
post #71

Earlier quoted context omitted.

What you are describing is an example of of customers demanding non-testicle exploding drugs as why we don't have them. When a drug causes problems, customers often end up suing the manufacturer/developer of said drug. If doctors prescribe said drugs after it becomes common knowledge that it could cause a problem, they also might be sued for malpractice. Are people sing IoT companies for poor security practices? If s…

nobody's ever sued me for leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation to do exactly that. why? well, gosh darn it, because it's the right thing to do! i think the drive to reduce every bit of human behavior to economic incentives backed by a government force structure is ultima…

>leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation

If there were millions of dollars to be made in the flaming dog shit Segway getaway business, I am positive many would succumb to the temptation.

So your comparison is unfair, it's easy for you to avoid such a behavior because you have no benefits. Not securing a device is a significant economic win for the manufacturer, as explained by the thread originator. You get a device that "just works" as opposed to one with complex key setup instructions that by necessity must default in the misconfigured state (else, you bet everybody is using the defaults).

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#130

Earlier quoted context omitted.

No, judges and juries decide lawsuits. They have the benefit of being harder to bribe than regulators.

Only if you have money to get to court. Everybody else would be left depending on the good will of big companies. That's why courts should be the last resort, not the first. We need regulation, and if everything else fails the courts should be the way to go.

Liability is generally a much better approach than specific regulation. Lawsuits happen after the fact and concern actual harm suffered by actual people. Damages are assigned based on this actual harm. That means that in liability system the price of bad behavior is approximately the harm it causes, which is exactly what you want. Liability doesn't require everyone to actually go to court, because almost all lawsuits or threats thereof are settled based on expectations shaped by previous cases that did go to court. Further, class action lawsuits allow large numbers of harmed people to be represented in a single action at no cost to themselves.

Regulation, on the other hand, is an ex ante affair. It involves some central planning authority, whether Congress or some administrative agency, trying to create rules that they believe will prevent future problems. The regulator will always get it wrong to some extent, often to a very large extent. Rules can be too specific, stifling innovations that would allow actors to achieve the same or better results with different methods. They can be too strict or too loose. The rule making process is also necessarily slow, so regulations tend to come too late and linger too long after technology has moved on. Finally, regulations are ultimately political, driven by what will translate into votes, not necessarily efficiency. If they represent a right-wing constituency, that will mean looser regulation; if a left-wing constituency, tighter regulation.

What's interesting about liability is that companies will buy insurance for it. The insurance companies will demand compliance with certain rules in order to be covered--essentially private regulations. But unlike government regulation, there are multiple competing insurance companies. The resulting market for insurance means that the market searches for the optimal balance between harm prevention and profitability. Insurance companies have a strong incentive to devise the rules that provide the optimum level of security for lowest cost possible.

Post reply on HN