Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

141–150 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#141

Earlier quoted context omitted.

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

Doctors would totally push cheap testicle-exploding drugs on their patients if there wasn't extensive regulation preventing them from doing that. They do push life-explodingly addictive and harmful painkillers on their patients, despite knowing the harm it does, because regulations don't prevent them from doing that. What would be the consequences of an FDA for IoT? Huge price increases, sudden workability of patents…

[deleted]

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#142
post #58

Earlier quoted context omitted.

> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)

> The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. That's an excellent idea. I hope your country regulates the hell out of your nation's software industry. Meanwhile I'll buy a rake to help me gather all the money your economy will throw my way because somehow developing…

You don't understand. We should have a global government, and then regulate software all over the world at the same time

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#143

Earlier quoted context omitted.

How can you reasonably ask a consumer to evaluate the security of a product when many don’t have basic education? Also, many reputable companies that make “good products” have security breaches, so you can’t just rely on reputation.

Force the consumer to force manufacturers to make less shitty products. Until that happens I hope brickerbot type attacks continue to happen for the cheapo crap. Sure good products can have a security flaw. But iot and home routers are complete garbage. The consumer should be held liable for being apart of massive disruption of the internet. It's the equivalent of manslaughter, you might not have intended it. But in…

The way the consumer would force manufacturers to do this is by passing laws that would make manufacturers liable.

They would do this because of information asymmetry and the collective action problem. At the point of purchase, consumers don't have the information to make a choice, and they don't have the ability to will an alternative into existence so they can choose it. Improvement in collective outcomes is often hard to achieve purely through market means, which is why we don't rely on markets to solve all these problems.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#144

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

Doctors have done that - and pharma firms would and have done worse.

The reason they dont is because there are regulations and trials which have to be passed before you can go forward.

And those are things which people on HN regularly criticize - pointing out that life saving drugs would be on the market faster if these regulations were not so "onerous".

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#145
post #118
post #91

Earlier quoted context omitted.

Consumers are not savvy as a group. There is always an "eternal september", new suckers born every minute, that can be abused. Beyond that, there are plenty of ways that you can maintain consumer trust while abusing it at the same time. You can sell them products that hurt them in ways they don't understand, and you can control the media surrounding your product enough to ensure that they don't understand. Advertisin…

I think you are missing a crucial point. I as a consumer really do not care in the least if someone hacks my device. Worst comes to worst I either do some sort of factory reset or just throw it out, I was probably looking to buy the shinier version anyways. Who cares? I really dont care if my tea kettle is part of some botnet. I cant even imagine a reason why I should care. I guess it sorta sucks for the people getti…

yup- the "consumer" is not a source of moral force. Its an approximation of whatever purchase decisions people make.

So consumers would of course be happy if you made plastic straws - look at how many get sold!

Now if you told people they would not have plastics, and everything would cost 5x more because we dont have a cheap packaging option, OR tell people that they couldnt transport liquids anymore because we dont have bottles - well you can imagine those customers and consumers would be upset.

The economy is not moral.

Morality is laws and regulations which impose restrictions on the system to make it

fair Environmentally friendly less exploitive etc.

We try and let the market resolve as much of this on its own, so that we can have market efficiency without tying it up with regulations.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#146
post #76
post #71

Earlier quoted context omitted.

What you are describing is an example of of customers demanding non-testicle exploding drugs as why we don't have them. When a drug causes problems, customers often end up suing the manufacturer/developer of said drug. If doctors prescribe said drugs after it becomes common knowledge that it could cause a problem, they also might be sued for malpractice. Are people sing IoT companies for poor security practices? If s…

nobody's ever sued me for leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation to do exactly that. why? well, gosh darn it, because it's the right thing to do! i think the drive to reduce every bit of human behavior to economic incentives backed by a government force structure is ultima…

How much money do you earn by leaving flaming bags of dog poop? Can you get rich that way?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#147
post #76

Earlier quoted context omitted.

nobody's ever sued me for leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation to do exactly that. why? well, gosh darn it, because it's the right thing to do! i think the drive to reduce every bit of human behavior to economic incentives backed by a government force structure is ultima…

If you’re trying to explain the behaviour of unusually, upstanding moral people sure. If you’re trying to deal with anything larger than a small and highly committed group no. > there are three classes of humans 1) those who will throw the rock at you with the mob 2) those who will not throw the rock and avert their eyes 3) those who will speak out against throwing the rocks > the ratio is probably 90:9:1

I’d be a little more optimistic and put the ratio at more like 9:90:1.

We don’t typically go around continually throwing actual rocks at each other, so it is possible to make progress on these issues.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#148

Earlier quoted context omitted.

If you’re trying to explain the behaviour of unusually, upstanding moral people sure. If you’re trying to deal with anything larger than a small and highly committed group no. > there are three classes of humans 1) those who will throw the rock at you with the mob 2) those who will not throw the rock and avert their eyes 3) those who will speak out against throwing the rocks > the ratio is probably 90:9:1

I’d be a little more optimistic and put the ratio at more like 9:90:1. We don’t typically go around continually throwing actual rocks at each other, so it is possible to make progress on these issues.

https://www.politico.com/blogs/media/2015/03/new-york-times-...

The author of the tweet quoted was speaking metaphorically based on his own experience. Virtually no one supported him publicly when he needed it.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#149

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

> IoT devices aren't secure because their customers don't demand security.

Customers cannot evaluate security, just like in cars and many other technologies.

Vendors need to be held accountable and fined by 3rd parties.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#150
post #29

Fixing security is quite possible. Install a backdoor, go to jail for "exceeding authorized access". Fail to fix an security bug, get sued for negligence. Make it public policy that license contracts cannot override those responsibilities.

>Make it public policy that license contracts cannot override those responsibilities. This would be a disaster for open source. Who wants to write software for free if you can get sued for a bug?

Quite the opposite. If you give a product for free you cannot be fined for it, obviously.

Yet, open source can be vetted, and people can be paid to review and vet software.

Debian developers review software before uploading it end often do additional work on hardening it.

The distribution then freezes to ensure maturity, let people discover vulnerabilities and backport fixes.

https://www.cip-project.org/ builds from Debian and goes even further by supporting releases for decades.

Post reply on HN