Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
121–130 of 184 posts
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#122I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…
> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)
That's an excellent idea. I hope your country regulates the hell out of your nation's software industry. Meanwhile I'll buy a rake to help me gather all the money your economy will throw my way because somehow developing software in your nation became suddenly cost-prohibitive and your economy has no alternative to outsource it to nations unencumbered by regulation.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#123Earlier quoted context omitted.
> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)
Not necessarily. It could also be done by allowing people to sue makers of insecure software or hardware.
What about free/open source software? Should society punish those idiots who had the gaul to contribute their free time to a project that everyone can use free of charge?
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#124I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…
Apple offers the most secure devices, a tiny fraction of its consumer base demands security, or is even aware of how secure their products are.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#125Earlier quoted context omitted.
This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…
...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#126Earlier quoted context omitted.
Customers don't demand non-testicle exploding drugs because that's already the standard in the same way that customers don't demand software that doesn't wipe their disks at random intervals, because software already doesn't (careless usage of dd notwithstanding). If drugs started exploding testicles you can bet customers would start demanding they didn't (male customers at least). Just look at the Thalidomide incide…
I think consumers are a little more savvy than people in this thread are giving them credit for. Sure, nobody want exploding gonads, but most folks couldn't give a whit if some overseas teenager manages to sneak a look at the contents of their driveway. People just want a cheap camera to catch their neighbors letting the dog poop in their lawn, and if it means becoming part of a botnot, who cares. The market has spok…
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#127Earlier quoted context omitted.
This is worse. This leads to lawyers making the critical decisions instead of regulators and auditors. The latter group at least has some familiarity with the subject area.
No, judges and juries decide lawsuits. They have the benefit of being harder to bribe than regulators.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#128Earlier quoted context omitted.
Not necessarily. It could also be done by allowing people to sue makers of insecure software or hardware.
> It could also be done by allowing people to sue makers of insecure software or hardware. What about free/open source software? Should society punish those idiots who had the gaul to contribute their free time to a project that everyone can use free of charge?
If it's given for nothing then that's what can be charged for it's failure, nothing.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#129Earlier quoted context omitted.
What you are describing is an example of of customers demanding non-testicle exploding drugs as why we don't have them. When a drug causes problems, customers often end up suing the manufacturer/developer of said drug. If doctors prescribe said drugs after it becomes common knowledge that it could cause a problem, they also might be sued for malpractice. Are people sing IoT companies for poor security practices? If s…
nobody's ever sued me for leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation to do exactly that. why? well, gosh darn it, because it's the right thing to do! i think the drive to reduce every bit of human behavior to economic incentives backed by a government force structure is ultima…
If there were millions of dollars to be made in the flaming dog shit Segway getaway business, I am positive many would succumb to the temptation.
So your comparison is unfair, it's easy for you to avoid such a behavior because you have no benefits. Not securing a device is a significant economic win for the manufacturer, as explained by the thread originator. You get a device that "just works" as opposed to one with complex key setup instructions that by necessity must default in the misconfigured state (else, you bet everybody is using the defaults).
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#130Earlier quoted context omitted.
No, judges and juries decide lawsuits. They have the benefit of being harder to bribe than regulators.
Only if you have money to get to court. Everybody else would be left depending on the good will of big companies. That's why courts should be the last resort, not the first. We need regulation, and if everything else fails the courts should be the way to go.
Regulation, on the other hand, is an ex ante affair. It involves some central planning authority, whether Congress or some administrative agency, trying to create rules that they believe will prevent future problems. The regulator will always get it wrong to some extent, often to a very large extent. Rules can be too specific, stifling innovations that would allow actors to achieve the same or better results with different methods. They can be too strict or too loose. The rule making process is also necessarily slow, so regulations tend to come too late and linger too long after technology has moved on. Finally, regulations are ultimately political, driven by what will translate into votes, not necessarily efficiency. If they represent a right-wing constituency, that will mean looser regulation; if a left-wing constituency, tighter regulation.
What's interesting about liability is that companies will buy insurance for it. The insurance companies will demand compliance with certain rules in order to be covered--essentially private regulations. But unlike government regulation, there are multiple competing insurance companies. The resulting market for insurance means that the market searches for the optimal balance between harm prevention and profitability. Insurance companies have a strong incentive to devise the rules that provide the optimum level of security for lowest cost possible.