Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

131–140 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#131
post #120

Seems well opinionated but I disagree. He's thinking too much in absolutes while in practice people care about relative security. Computer security has gotten a lot better,many organizations have acheived a security posture they are comfortable with. I think he's focusing strictly on application security,in reality you care about maintaining C.I.A. for the data. I don't care if the entire software stack is riddled wi…

I disagree with your disagree.

Say we all lived 50 years ago and worked in ergonomics engineering instead of software engineering. People were fairly comfortable doing non-stressful work, which I guess was better than being pulled into meat grinders of The Jungle.

However, there was this new science that was indicating a new problem of repetitive stress injuries. Over the next 20-ish years, we learned that these injuries caused a ton of harm, so we started legislating protections against these types of stresses, when which resulted in increased productivity.

Now switch to today. What makes the lax of software security best practices so different from repetitive stress injuries 50 years ago?

Software engineering is feeling like it will follow the same path as every other engineering. First, we'll feel like we're gods. Then, we'll suffer losses. Finally, we'll be regulated.

Remember, every regulation is written in blood. Software will be no different.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#132

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

Another subtle point is that “operation poorly understood” could in fact be a desirable feature for a system that makes sensitive decisions s.a who’s taken to the black room on border crossings.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#133

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

if you consider how doctors are happy to prescribe drugs that are not ideal (understatement) for their patients' health for money from pharmaceutical companies, your argument falls apart. consider the opioid epidemic

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#135
post #118
post #91

Earlier quoted context omitted.

Consumers are not savvy as a group. There is always an "eternal september", new suckers born every minute, that can be abused. Beyond that, there are plenty of ways that you can maintain consumer trust while abusing it at the same time. You can sell them products that hurt them in ways they don't understand, and you can control the media surrounding your product enough to ensure that they don't understand. Advertisin…

I think you are missing a crucial point. I as a consumer really do not care in the least if someone hacks my device. Worst comes to worst I either do some sort of factory reset or just throw it out, I was probably looking to buy the shinier version anyways. Who cares? I really dont care if my tea kettle is part of some botnet. I cant even imagine a reason why I should care. I guess it sorta sucks for the people getti…

Outside of the fact important information can easily be stolen.

Personally I think the consumer should face financial liability when iot devices are used in massive attacks that create problems for others.

Just because you chose a shitty vendor with a shitty product doesn't mean the entire internet should suffer.

I am a fan of things like brickerbot and I hope that sort of thing continues aggressively.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#136

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

Doctors would totally push cheap testicle-exploding drugs on their patients if there wasn't extensive regulation preventing them from doing that.

They do push life-explodingly addictive and harmful painkillers on their patients, despite knowing the harm it does, because regulations don't prevent them from doing that.

What would be the consequences of an FDA for IoT? Huge price increases, sudden workability of patents as a means of protection, but more security and better products?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#137
post #118

Earlier quoted context omitted.

I think you are missing a crucial point. I as a consumer really do not care in the least if someone hacks my device. Worst comes to worst I either do some sort of factory reset or just throw it out, I was probably looking to buy the shinier version anyways. Who cares? I really dont care if my tea kettle is part of some botnet. I cant even imagine a reason why I should care. I guess it sorta sucks for the people getti…

Outside of the fact important information can easily be stolen. Personally I think the consumer should face financial liability when iot devices are used in massive attacks that create problems for others. Just because you chose a shitty vendor with a shitty product doesn't mean the entire internet should suffer. I am a fan of things like brickerbot and I hope that sort of thing continues aggressively.

How can you reasonably ask a consumer to evaluate the security of a product when many don’t have basic education? Also, many reputable companies that make “good products” have security breaches, so you can’t just rely on reputation.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#138

Earlier quoted context omitted.

Outside of the fact important information can easily be stolen. Personally I think the consumer should face financial liability when iot devices are used in massive attacks that create problems for others. Just because you chose a shitty vendor with a shitty product doesn't mean the entire internet should suffer. I am a fan of things like brickerbot and I hope that sort of thing continues aggressively.

How can you reasonably ask a consumer to evaluate the security of a product when many don’t have basic education? Also, many reputable companies that make “good products” have security breaches, so you can’t just rely on reputation.

Force the consumer to force manufacturers to make less shitty products. Until that happens I hope brickerbot type attacks continue to happen for the cheapo crap.

Sure good products can have a security flaw. But iot and home routers are complete garbage. The consumer should be held liable for being apart of massive disruption of the internet.

It's the equivalent of manslaughter, you might not have intended it. But in this case you didn't do anything to stop it and helped to cause millions in damage. I quite frankly don't care about their education. That's their responsibility. Just the same as you need to learn to drive.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#139

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

>Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expressing facets of a deeper, more fundamental reason: IoT devices aren't secure because their customers don't demand security.

Its not just price though. You cant just make the devices more expensive to be able to do proper security, the bottleneck in a lot of cases is the energy consumption. That doesnt really scale with more expensive hardware. If your device needs to run from a coin-cell for the next 10 years you will be cautious with how much security you can afford. Even worth off are energy harvesting products without even such a little battery.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#140
post #29

Fixing security is quite possible. Install a backdoor, go to jail for "exceeding authorized access". Fail to fix an security bug, get sued for negligence. Make it public policy that license contracts cannot override those responsibilities.

>Make it public policy that license contracts cannot override those responsibilities. This would be a disaster for open source. Who wants to write software for free if you can get sued for a bug?

If it helps clean up the npm ecosystem mess, would that really be a bad thing?
Post reply on HN