Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

171–180 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#171

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

You assert that "IoT devices aren't secure because their customers don't demand security."

I'll assert that customers can "demand" recycling all they want but companies are going to continue to package their products in the cheapest thing possible without regard to its ability to be recycled. Speaking with your dollar only works if there is at least one company doing what you want.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#172

Earlier quoted context omitted.

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…

Doctors would totally push cheap testicle-exploding drugs on their patients if there wasn't extensive regulation preventing them from doing that. They do push life-explodingly addictive and harmful painkillers on their patients, despite knowing the harm it does, because regulations don't prevent them from doing that. What would be the consequences of an FDA for IoT? Huge price increases, sudden workability of patents…

> Doctors would totally push cheap testicle-exploding drugs on their patients if there wasn't extensive regulation preventing them from doing that.

And who would have had some of the most input into said extensive regulation?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#173
post #58

Earlier quoted context omitted.

> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)

> The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. That's an excellent idea. I hope your country regulates the hell out of your nation's software industry. Meanwhile I'll buy a rake to help me gather all the money your economy will throw my way because somehow developing…

we have regulations for software and software services in EU (e.g. GDPR) and US (e.g, DMCA, HIPAA) and the economy has not collapsed.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#174

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

You assert that "IoT devices aren't secure because their customers don't demand security." I'll assert that customers can "demand" recycling all they want but companies are going to continue to package their products in the cheapest thing possible without regard to its ability to be recycled. Speaking with your dollar only works if there is at least one company doing what you want.

Apple takes security (and privacy, it’s natural extension) very seriously. It’s not an open source process unfortunately, but they’ve shown a clear financial and strategic commitment to hardware and software level security. They also done an excellent job communicating this to users in the way that they ask for permissions, etc.

A lot of consumers explicitly choose this option, but it’s all wrapped up in “quality”. When I buy a MacBook I know they won’t cheap out on the casing, or the user experience, or the security, and I pay a premium for that.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#175
I'll post IMO the most interesting slide of the talk.

---

The Assumptions of Technological Manifest Destiny:

1) Technology is VALUE-NEUTRAL, and will therefore automatically lead to good outcomes for everyone.

2) Thus, new kinds of technology should be deployed as quickly as possible, even if we lack a general idea of how the technology works, or what the societal impact will be.

3) History is generally uninteresting, because the past has nothing to teach us.

---

How relevant is this. With Cambridge Analytica scandal and now Google's censored search engine in China. How about self driving cars? Cryptocurrencies?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#176
post #120

Seems well opinionated but I disagree. He's thinking too much in absolutes while in practice people care about relative security. Computer security has gotten a lot better,many organizations have acheived a security posture they are comfortable with. I think he's focusing strictly on application security,in reality you care about maintaining C.I.A. for the data. I don't care if the entire software stack is riddled wi…

"I'm not prepared to handle 10 guys mugging me as I walk home,but that isn't my goal." Muggings have an understandable statistical distribution, which allows you to take a calculated risk. It's impossible to calculate the risk of software security problems, and almost by definition the problems are less contained than you think. Will the next secuirty breach hurt a few individuals, destroy the business, or hurt the e…

That's what security professionals do. We measure risk and plan for the next breach.

I used that as an example,but in security we can measure the risk of a specific data or system being compromised. We can define specific security posture requirements that can be met. Incident response plans account for recovery and cost-efficient remediation of the next breach. Extensive IR playbooks can be defined for when software security fails.

Acheiving security means being able to measure risk,place security controls,audits,policies and plan for IR. It does not mean elimination of vulnerabilities as a whole.

Like you said,the next breach could impact the entire world, the problem is that the entire world as a whole is not prepared for it. More realistically,corporations are far more prepared than individuals.

End users can't do their own computer security. Unfortunately this can only be fixed by regulation, and that can only happen when people are scared enough. But even then, people don't understand technology enough to demand such regulation. In my opinion,silicon valley's political involvement would be a roadblock since it will inevitably get perceived as a liberals vs conservatives issue. I hope technologists become more socio-politically neutral just for that readon.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#177

Earlier quoted context omitted.

This is worse. This leads to lawyers making the critical decisions instead of regulators and auditors. The latter group at least has some familiarity with the subject area.

No, judges and juries decide lawsuits. They have the benefit of being harder to bribe than regulators.

[deleted]

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#178
post #73
post #48

Speaking generally, and not about this post - Keynote speakers often aren't technical (enough), but speak about topics that have technical underpinnings. Take for example, dangerous management consultants who speak all over the place about AI, disruption, innovation, digital transformation, but don't know technology, which is the underpinning of all the things they're speaking about.

I get this feeling from even some of the biggest conventions there are... cough I felt fairly fricken disenfranchised during a recent convention for a popular containerization solution...

Good point. "Technologists in management /leadership" groups need to form everywhere to get the right people speaking about topics they understand.

It's ironic that there is an imposter syndrome among competent people, and incompetent people have no issue being imposters.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#179
post #58

Earlier quoted context omitted.

> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)

> The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. That's an excellent idea. I hope your country regulates the hell out of your nation's software industry. Meanwhile I'll buy a rake to help me gather all the money your economy will throw my way because somehow developing…

Do you really think suggesting that selfish drive for selling insecure and underregulated software is really an argument against regulation?

I don't think anybody denied that capturing an unregulated space by selling shoddy and cheap products is actually a great way of making any ruthless actor a ton of money, I'm really not sure what point you're trying to make here

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#180

A few years ago, I was working in a company that was trying to build an innovative NLP system, or in more honest words, to do a chatbot that doesn’t suck. Spoiler alert: we failed. There were a lot things wrong in how this company was run and the product we were doing, but I won’t go into details except to say that there were a lot of intelligent people forced to do silly things by a clueless micromanaging boss. Anyw…

nice anecdote thanks for sharing. You assert that it was not really ML. I think it is, It may not be true AI, however patten matching/recognition is the core part of ML. ML is just a stochastic and statistical approach to do pattern matching, the hype around ML has kind of distorted the expectation from the field.

You don't have to really control the input, it is not difficult to automate the sanitation by building a feedback loop of abuse reports to delete patterns from the corpus, if you cannot release before significant cleanup, you could either use something like Mechanical Turk/ Crowd-sourced paid users to test the system extensively, or be more through generate millions of possible questions and the answers for them and run content moderation tools on them, human assisted or otherwise, or build a filter layer into your chatbot itself. None of these approaches of course give you a guarantee something won't go wrong, they give you a reasonable probability it won't.

Post reply on HN