Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

161–170 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#161

Earlier quoted context omitted.

...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.

That's a great point made with a pretty suspect example. FDA very subject to regulatory capture.

The cost of the FDA is that the process is slower.

The benefit is that medicine is effective and measurably safe. It’s obviously necessary, and the supplement industry shows why.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#162

Earlier quoted context omitted.

How can you reasonably ask a consumer to evaluate the security of a product when many don’t have basic education? Also, many reputable companies that make “good products” have security breaches, so you can’t just rely on reputation.

Force the consumer to force manufacturers to make less shitty products. Until that happens I hope brickerbot type attacks continue to happen for the cheapo crap. Sure good products can have a security flaw. But iot and home routers are complete garbage. The consumer should be held liable for being apart of massive disruption of the internet. It's the equivalent of manslaughter, you might not have intended it. But in…

Why make millions liable where a few hundred bad actors can be trivially dealt with.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#163
post #118
post #91

Earlier quoted context omitted.

Consumers are not savvy as a group. There is always an "eternal september", new suckers born every minute, that can be abused. Beyond that, there are plenty of ways that you can maintain consumer trust while abusing it at the same time. You can sell them products that hurt them in ways they don't understand, and you can control the media surrounding your product enough to ensure that they don't understand. Advertisin…

I think you are missing a crucial point. I as a consumer really do not care in the least if someone hacks my device. Worst comes to worst I either do some sort of factory reset or just throw it out, I was probably looking to buy the shinier version anyways. Who cares? I really dont care if my tea kettle is part of some botnet. I cant even imagine a reason why I should care. I guess it sorta sucks for the people getti…

[deleted]

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#164
post #118

Earlier quoted context omitted.

I think you are missing a crucial point. I as a consumer really do not care in the least if someone hacks my device. Worst comes to worst I either do some sort of factory reset or just throw it out, I was probably looking to buy the shinier version anyways. Who cares? I really dont care if my tea kettle is part of some botnet. I cant even imagine a reason why I should care. I guess it sorta sucks for the people getti…

yup- the "consumer" is not a source of moral force. Its an approximation of whatever purchase decisions people make. So consumers would of course be happy if you made plastic straws - look at how many get sold! Now if you told people they would not have plastics, and everything would cost 5x more because we dont have a cheap packaging option, OR tell people that they couldnt transport liquids anymore because we dont…

Consumers are happy about plastic straws because it was conveniently (for the producer of straws) not communicated to them how manufacture of plastic straws is irresponsible and creates external costs to the environment at no cost to the producer.

You can't honestly believe it's both okay to mislead people in commerce and okay to put the onus of good judgement on them.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#165
post #118
post #91

Earlier quoted context omitted.

Consumers are not savvy as a group. There is always an "eternal september", new suckers born every minute, that can be abused. Beyond that, there are plenty of ways that you can maintain consumer trust while abusing it at the same time. You can sell them products that hurt them in ways they don't understand, and you can control the media surrounding your product enough to ensure that they don't understand. Advertisin…

I think you are missing a crucial point. I as a consumer really do not care in the least if someone hacks my device. Worst comes to worst I either do some sort of factory reset or just throw it out, I was probably looking to buy the shinier version anyways. Who cares? I really dont care if my tea kettle is part of some botnet. I cant even imagine a reason why I should care. I guess it sorta sucks for the people getti…

Would you similarly not care if drug dealers sold drugs in your driveway, Viagra sellers sent spam from your email, and so on? I think you're being disingenuous.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#166

Earlier quoted context omitted.

...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.

That's a great point made with a pretty suspect example. FDA very subject to regulatory capture.

Regulatory capture is certainly an important problem, but the pre-FDA record suggests strongly that the FDA we have is much better than not having one. But I would certainly not suggest that there is not a real problem with regulatory capture, just that the current situation in tech security (no FDA equivalent) is worse.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#167

Earlier quoted context omitted.

I disagree with your disagree. Say we all lived 50 years ago and worked in ergonomics engineering instead of software engineering. People were fairly comfortable doing non-stressful work, which I guess was better than being pulled into meat grinders of The Jungle. However, there was this new science that was indicating a new problem of repetitive stress injuries. Over the next 20-ish years, we learned that these inju…

An 8yr old can write software and post it to github. An 8yr can't build a house or car from scratch (two things who's construction is regulated). My point being software is harder and possibly impossible to regulate. Is all open source going to be banned unless it's been written by licensed certified programmers and gone through review by an appointed inspector? That seems untenable.

Writing software can't be regulated but use of unaudited software can,especially for commercial use.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#168

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

My understanding of regulated industries (e.g. CE products sold internationally) there are two sides of the coin.

1) properly understanding history as a motivation for risk management and properly funding that quality control.

2) technical ability to implement solutions to the risks identified from step one.

For example, the founder of the company that designs and builds a medical device does not necessarily understand the negatives of pressing CTRL+ALT+DELETE when the software from the manufacturer freezes. People can do so many things wrongly in just a few simple steps.

We can think of dozens of ways to fix the problem but the C levels might only understand 0.5 to 1 of those solutions.

There simply isn't enough quality work going in to a proprietary/closed system that is profit driven.

In my little dream world if all businesses were open-source (code, process, profit margins, all of it) we'd be better at building off of past work and innovation would literally be cheaper. Maybe it's a pipe dream.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#169
post #120

Seems well opinionated but I disagree. He's thinking too much in absolutes while in practice people care about relative security. Computer security has gotten a lot better,many organizations have acheived a security posture they are comfortable with. I think he's focusing strictly on application security,in reality you care about maintaining C.I.A. for the data. I don't care if the entire software stack is riddled wi…

"I'm not prepared to handle 10 guys mugging me as I walk home,but that isn't my goal."

Muggings have an understandable statistical distribution, which allows you to take a calculated risk.

It's impossible to calculate the risk of software security problems, and almost by definition the problems are less contained than you think.

Will the next secuirty breach hurt a few individuals, destroy the business, or hurt the entire country or the entire world?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#170

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

There aren't enough doctors in medicine to go around. There probably aren't enough doctors (as in PhD) in all the other technology industries supporting medicine.
Post reply on HN