Live data from Hacker News

Cyber Security: A pre-war reality check

berthub.eu

11–20 of 286 posts

Re: Cyber Security: A pre-war reality check

#11
Who cares? In the case of some sort of big war why would you care about "cyber security" when the day to day problem is not dying from starvation, being drafted, radiation posioning or what ever the problem is.

These kind of "we need to prepare" are silly since they implicitly downplay the severity of war and bring us closer to it.

Re: Cyber Security: A pre-war reality check

#12

Who cares? In the case of some sort of big war why would you care about "cyber security" when the day to day problem is not dying from starvation, being drafted, radiation posioning or what ever the problem is. These kind of "we need to prepare" are silly since they implicitly downplay the severity of war and bring us closer to it.

Everything is computerized now. And most adjacent power wars will most likely be non-nuclear in nature until it crosses a red line.

Re: Cyber Security: A pre-war reality check

#13
Is there an enemy factor measure which reflects how many countries have to sanction/attack you directly before you are enable to maintain the economy and social services? It would be interesting to have an index of geostratigic resilience.

Re: Cyber Security: A pre-war reality check

#14
As an outsider on most IT security so take the rest of this with a grain of salt, but I think reliability is a good way to view this topic. Complexity is the enemy of reliability and security. Most organizations seem to operate under the delusion that you can brute force your way to security through audits and policy. They're trying to 'test the quality in' so to speak. Think of the legion of security admins who diligently tweak windows group policies, firewall settings, and systems like 2FA/MFA. Nobody can stomach the truth that most of these things have grown in complexity beyond their ability to be truly reliable. They're basically the IT equivalent of locks on a few doors of mansion with 80 windows, they prevent some crimes of opportunity but won't stop an attacker motivated by something else.

This also doesn't tend to bother security people. It's interesting, it quickly shifts to, "Well we don't run a nuclear reactor..." or "We're not a cloud provider or a bank", so they think they're not critical infrastructure and crimes of opportunity are really their main threat (ransomware, disgruntled ex-employees, etc). Also, their job usually depends on tweaking the knobs in this complex pachinko machine, so to have some outsider tell them to throw it all away is basically like saying you think they should lose their job as well.

I don't know where this rant should end, but I think if I was tasked with making infrastructure decisions, It would be really hard for me to not use things like OpenBSD and SQLite for a lot of it. I'm sure someone here will say actually those are bad for various reasons, but they at least seem to capture the ethos of, "We're going to just say no to things and try to control the complexity of this thing." They also don't seem very motivated by making money which tends to be the root of most compromising decisions.

Re: Cyber Security: A pre-war reality check

#15

Who cares? In the case of some sort of big war why would you care about "cyber security" when the day to day problem is not dying from starvation, being drafted, radiation posioning or what ever the problem is. These kind of "we need to prepare" are silly since they implicitly downplay the severity of war and bring us closer to it.

Everything is computerized now. And most adjacent power wars will most likely be non-nuclear in nature until it crosses a red line.

Everything being computerized is a major peace time concern too.

Ideally systems should not be as centralized as they are now and have offline fallbacks.

I believe there is a great deal of over automization too.

You can notice how war mongerers have turned to "cyber threats" to instigate on unfalsifiable information.

I feel it might be better to pull the plug on the whole internet if that actually is such a concern.

Re: Cyber Security: A pre-war reality check

#18
post #17
post #3

Author here - if you have any questions, please do let me know!

What were the vulnerabilities in your 1600 lines imgur alternative?

https://github.com/berthubert/trifecta/blob/main/README.md#k... has a list. The most painful one for me is that I did not know .svg files can contain javascript that gets executed in the site context if you can get someone to click on a link to your .svg file!

Re: Cyber Security: A pre-war reality check

#19
When I recently asked some air traffic controllers what would happen if GPS became unavailable, it was grumpy sounds all around.

I understand a scramble to vector everything to land everything would result in a very busy day for them, because suddenly most planes would be unable to safely navigate, and thus effectively grounded.

Cutting the budget for ground based navaids is nuts, in my opinion.

Re: Cyber Security: A pre-war reality check

#20
> I know it sounds devastating, but you have to get used to the fact that a new era has begun. The pre-war era.

It is madness that we're in a position where this can be baldly stated by a PM and there has been no "huh?" moment when people stop and assess how badly the broader West's military, economic and diplomatic efforts have failed over the last 30 odd years. Possibly longer. I wasn't expecting to see land wars in Europe even before the cold war ended.

Humanity has unprecedented destructive power at our command and the systems that sustain 8 billion people are delicate. We can't afford to be in a "pre-war era" and act like this is just going to be something to deal with when we get to it plus a little prep in specialist domains.

Post reply on HN