Some good points. Lets see what we can do here:
> The problem isn’t that you can’t trust people.
Good. It's always best to have an optimistic view of our fellows,
that's how we build good social structures.
> The problem is that people are defenceless in the face of
malicious hackers
So. Make then not defenceless. We arm them. With education and other
tools they need to defend themselves. Digital Self Defence (Or Digital
Literacy 2.0 if you want a fluffier title) is the project I am
committed to. Defensive tools belong in the hands of users.
> with vastly more expertise
We can balance the theatre twofold, by giving people more defensive
capability, knowledge and rights, and by attacking the knowledge base
and knowledge value of malicious actors. We must recognise that many
of our own institutions play part of the problem, from vendor malware,
and backdoors to security disinformation. Cyber-law needs radical
reform to give end-user better security rights, and "surveillance
capitalism" needs dragging to the dock.
> zero day vulnerabilities.
Starting maybe with an all out assault on "zero days", including the
companies, agencies and re-sellers of them, using the law.
> It’s that you can’t trust them to defend themselves from being
mugged.
Part of ones job then, is to enable them to defend themselves. You
cannot follow your children around for the rest of their lives in case
bullies pick on them. You need to teach them fighting skills so they
won't be doormats. That's the reality of the digital workplace today.
Also, don't give your kids gold Rolex Oyster watches and diamond rings
to mooch around scuzzy neighbourhoods with. Limit assets, practice
compartmentalisation. Half an ounce of sensible opsec is worth a ton
of authoritarian technical non-solutions.
> The removal of freedom is not the goal so much as a side effect.
The removal of freedom is NEVER an acceptable "side effect" of any
security action. Security and freedom are not diamtrics. Otherwise
"the terrorists win" and one may as well join the ranks of malicious
principles and directly attack our own people (which is the stance
many US agencies have taken since 2001 toward baby and bath-water
alike)
> real world ... borders armies police
But this isn't the real world. Its a digital one which is different.
The old military model of perimeters and weapons isn't working and
smart people in cybersecurity know that. The collateral damage of that
broken model is our digital economy and liberal democracy itself
(which are intimately linked in the American/Western mind if you
believe one jot in things like startups and entrepreneurialism).
We'll simply have to do better than handing over the responsibilities
of our elected guardians to unelected companies considered by some [1]
to be criminally motivated. We still have laws, schools and hopefully
enough common sense to avoid that.
EDIT: subtracted fulmination.
[1] https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor.... https://en.wikipedia.org/wiki/Microsoft_litigation