Live data from Hacker News

Rebuttal: LulzSec Ups The Ante

attrition.org

11–13 of 13 posts

Re: Rebuttal: LulzSec Ups The Ante

#11
post #4

Does anybody else think that the kitchen table analogy totally stands? I have things in my house that contain a significant number of other people's personal information in them. I don't lock them in an extra protected safe in my house because I consider my house to be (relatively) secure by both convention and practice. If somebody were to forcibly enter my house and steal that information and publish it on the inte…

The problem is that many of the recently published hacks are embarrassingly simple. These are hacks that are impossible if you have a decent security policy in place. The biggest issue, and the one that these hacks are highlighting, is that the software industry has a huge security problem. And this is mostly because the industry has a huge quality problem (security is an aspect of quality, it's not a feature).

It's not that it's that much more expensive to build high-quality secure software. The research indicates that high-quality software projects are actually cheaper than average software projects because the maintenance cost is much lower. The state of the art is far removed from the average practition of the art. Nobody has a solution for that. Lulzsec are just a symptom, they are not the problem.

Re: Rebuttal: LulzSec Ups The Ante

#12
post #4

Does anybody else think that the kitchen table analogy totally stands? I have things in my house that contain a significant number of other people's personal information in them. I don't lock them in an extra protected safe in my house because I consider my house to be (relatively) secure by both convention and practice. If somebody were to forcibly enter my house and steal that information and publish it on the inte…

To make the analogy more fair, let's say your house (filled with people's personal information) had an unlocked secret entrance way, even though many lock experts say that unlocked entrance ways are generally unsafe. People may or may not be going into your house everyday while you're gone, and using that personal information while everyone remains blissfully unaware. One day, someone comes in and takes all the perso…

I don't think that physical locks are much more secure than a reasonably secured apache instance, which is definitely still exploitable, just like the locks on my door are, which I guess is part of why I think saying the analogy to papers on my kitchen table doesn't work rubs me the wrong way. It's _totally_ analagous.

There wouldn't be any rebuttal or arguing that LulzSec's work is actually good because it's going to increase security if we were talking about physical break ins to real buildings, even though there are many well known attack vectors on most modern locks.

Re: Rebuttal: LulzSec Ups The Ante

#13
post #9
post #4

Does anybody else think that the kitchen table analogy totally stands? I have things in my house that contain a significant number of other people's personal information in them. I don't lock them in an extra protected safe in my house because I consider my house to be (relatively) secure by both convention and practice. If somebody were to forcibly enter my house and steal that information and publish it on the inte…

I disagree, I have no expectation that my personal friends will be taking measures to ensure my privacy, I have not paid them money and signed off on a TOS that says they will take measures to protect my personal information. So if someone broke into their house and stole my information it would certainly be unfortunate, but I would not have expected them to be keeping this information encrypted or secured in any sig…

I see what you're saying here. The notion that this would be more analagous to a corporate office break-in makes more sense, but it still seems like a poor argument for why what LulzSec is doing, though seemingly negative, is actually beneficial.

I mean, if we were talking about LulzSec exploiting the locks on the corporate office doors or socially engineering their way past security to get at physical files, scanning them and then posting them on the internet, I don't think many people would say that what LulzSec is doing is for the good of humankind, you know?

Post reply on HN