Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

151–160 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#151

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

> The same causality can be observed in the ML world. Mickens

> asks why people are hooking ML systems whose operation

> isn't fully understood to important things like financial

> decisionmaking and criminal justice systems. The answer is

> that the customers demand it. ML is trendy and buzzworthy

But that's the same as with the testicle exploding argument: ML is nowadays called AI, can self-drive cars and beat humans at any task (like Jeopardy or Go). So people assume from their experience that it just works, even better than any human. Of course also a big mystery bubble is created around that both by Marketing people and ML practitioners (oh and IBM).

Being myself an engineer working on "normal" systems, I somehow feel pressed as well to do something fancier like ML - according to some survey already 40% of Engineers do that. But on the other hand I realize most of this stuff is, as already pointed out in the talk, just there to target ads or work on meaningless financial systems. I was recently listening to a talk of an AI expert person, using the AI for fraud detection in an online payment system. At the end of the talk somehow asked a really interesting question which was: so how do you connect that to your online system? He answered: we don't, it's just for compliance reporting. That's just stupid, I feel misguided. It's cool to do statistics on your data, simulations but calling that AI is incredibly misleading.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#152

Earlier quoted context omitted.

Only if you have money to get to court. Everybody else would be left depending on the good will of big companies. That's why courts should be the last resort, not the first. We need regulation, and if everything else fails the courts should be the way to go.

Liability is generally a much better approach than specific regulation. Lawsuits happen after the fact and concern actual harm suffered by actual people. Damages are assigned based on this actual harm. That means that in liability system the price of bad behavior is approximately the harm it causes, which is exactly what you want. Liability doesn't require everyone to actually go to court, because almost all lawsuits…

I agree that liability is probably the best approach and is long overdue for software. The problem is the standard for proving security nonfeasance? My thought is that if your product was found to have a security problem and you did not have a security audit performed by licensed security auditor then you are liable. But I'm not sure there are licensed security auditors in the way, for instance, a CPA is licensed. Over time, if a security issue is publicly reported (e.g. a CVE) and you haven't fixed it within a certain amount of time then you are also liable. The length of time a vendor must provide security updates to a product for free should probably be defined in law, e.g. 2 years.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#153

Earlier quoted context omitted.

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

Doctors would totally push cheap testicle-exploding drugs on their patients if there wasn't extensive regulation preventing them from doing that. They do push life-explodingly addictive and harmful painkillers on their patients, despite knowing the harm it does, because regulations don't prevent them from doing that. What would be the consequences of an FDA for IoT? Huge price increases, sudden workability of patents…

[deleted]

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#154

This was comic genius. It was also equally insightful. What a wonderful speaker and a wonderful talk. Did anyone else catch the the Bob Ross painting references during the graphic of the number 4? That had me in stitches. Thank you for posting this. This made my day.

Noticed this too. I recall one person in the audience laughing uproariously at it - probably the only person that got the reference.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#155
post #68
post #12

Earlier quoted context omitted.

He's the guy who wrote the Slow Winter. He's hilarious. https://www.usenix.org/system/files/1309_14-17_mickens.pdf

It'd be more hilarious if he didn't reference real problems with no obvious solutions short of a painful dismantling of our heavily exploited societal constructs.

You must be fun at parties.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#156
post #120

Seems well opinionated but I disagree. He's thinking too much in absolutes while in practice people care about relative security. Computer security has gotten a lot better,many organizations have acheived a security posture they are comfortable with. I think he's focusing strictly on application security,in reality you care about maintaining C.I.A. for the data. I don't care if the entire software stack is riddled wi…

I disagree with your disagree. Say we all lived 50 years ago and worked in ergonomics engineering instead of software engineering. People were fairly comfortable doing non-stressful work, which I guess was better than being pulled into meat grinders of The Jungle. However, there was this new science that was indicating a new problem of repetitive stress injuries. Over the next 20-ish years, we learned that these inju…

I am not against regulation,I think it's needed,especially on the 3rd party code audit side.

What makes software security practices different is thay 'computer security' is much more than how securely the code was written. A perfectly written software could be rendered useless by incorrect configuration or bad admin security practices. Heck,even the cpu could be come faulty and compromise security as you've seen with the latest intel bugs.

Yes,software security needs to improve by a lot,but look at the whole picture and include operational security,system and network design,risk assesment and proper threat modeling practices.

Good and easy example - yubikey. Google hasn't had anyone phished in over a year or so due to their yubikey enforcement. Even of software security or bad human practices were a problem the check and balance of yubikey prevented compromise of data security.

Next Gen AVs are so good,there are companies that haven't had single malware infection in 1y+. Insider threat is being accounted for too as a result of ML+behavioral analytics.

Modern security assumes the software is riddled with bugs. For example, if MS word starts powershell or the browser an unusual program like cmd.exe,modern endpoint solutions would block+alert. They assume browsers and document processors are filled with holes,so they account for post-exploit behavior and that actually works well.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#157
post #120

Seems well opinionated but I disagree. He's thinking too much in absolutes while in practice people care about relative security. Computer security has gotten a lot better,many organizations have acheived a security posture they are comfortable with. I think he's focusing strictly on application security,in reality you care about maintaining C.I.A. for the data. I don't care if the entire software stack is riddled wi…

I disagree with your disagree. Say we all lived 50 years ago and worked in ergonomics engineering instead of software engineering. People were fairly comfortable doing non-stressful work, which I guess was better than being pulled into meat grinders of The Jungle. However, there was this new science that was indicating a new problem of repetitive stress injuries. Over the next 20-ish years, we learned that these inju…

An 8yr old can write software and post it to github. An 8yr can't build a house or car from scratch (two things who's construction is regulated).

My point being software is harder and possibly impossible to regulate. Is all open source going to be banned unless it's been written by licensed certified programmers and gone through review by an appointed inspector? That seems untenable.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#158
post #58

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)

South Korea regulated their software security!

That's why even this decade, people were required to use Internet Explorer 6 with ActiveX enabled, to access online banking, because it was the only system the government considered secure enough. We're talking well after IE6 had become a distant memory in the rest of the world.

Are you sure you want governments to regulate software security?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#159

Earlier quoted context omitted.

...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.

That's a great point made with a pretty suspect example. FDA very subject to regulatory capture.

Regulatory capture is certainly an issue, but it doesn't mean that the FDA isn't better than not having a regulatory regime at all.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#160

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

Customers barely grasp identity theft with respect to bank accounts. Nobody understands the risks of a magic light switch.

We’re living in an era of laissez faire commerce in the US. The biggest, most influential retailer routinely ships counterfeit products and nobody really care.

That is a failure of the regulatory environment — economic forces aren’t powerful enough to deal with these issues. The kickback from government will be brutal and overreaching when it happens.

Post reply on HN