Live data from Hacker News

Cyber Security: A pre-war reality check

berthub.eu

41–50 of 286 posts

Re: Cyber Security: A pre-war reality check

#41
post #25

Earlier quoted context omitted.

What kind of diplomacy would have prevented Russia from invading its neighbours?

Picking on Ukraine, the US not having a policy of signing new people up to the anti-Russia military alliance every few years [0] seems like low hanging fruit. Or not working to integrate their intelligence with the CIA [1] for the last decade. I don't speak German but apparently Merkle said that we weren't negotiating in good faith to keep the peace either [2]. These are the sort of thing I suspect Russia would see a…

> US not having a policy of signing new people up to the anti-Russia military alliance every few years

Weird how all of Russia's neighbors are eager to join a military alliance protecting them from Russia. I wonder if that has something to do with Russia's actions towards its neighbors? No, no, surely the US is to blame for that...

Re: Cyber Security: A pre-war reality check

#42
He mentions the threat of remotely taking over autonomous vehicles, but really its any vehicle who's a) network connected and b) drive-by-wire. Which is why I won't buy one, and why the problem is even worse than it appears.

The other problem that he doesn't address is the centralization of critical (and semi-critical, like logistics) software in large shared data-centers. If you wanted to disable large chunks of the American software economy for an extended period, you only have to kill ~100 buildings.

In a way I think the ransomware people are doing us all a huge favor by putting the fear of God into executives around cybersecurity. Unfortunately, as other commenters have mentioned, the real problem is hard to address, because it's the complexity inherent in the "worse is better" philosophy. Current systems have grown in a lovely, nice environment that is generally reliable. When that environment changes quickly (which is one way to characterize a cyber attack) these systems will fail, and there will be no time or tools to repair them. This includes software and infrastructure hardware. Somewhat ironically, this is precisely the kind of non-extinction-level threat that "having a bunker" and a large store of food would actually get you through - something only executives can afford. Perhaps we might consider outlawing such bunkers to properly motivate the monied elite to address these issues.

Re: Cyber Security: A pre-war reality check

#43
Very interesting article. I think the author makes a compelling point about the vulnerability of infrastructure.

To be honest I wouldn't be surprised that in an actual unlimited war, between two major developed nations nothing will actually continue to function. None of the systems have ever been actually tested and still make assumptions about the rest of the infrastructure. I also don't believe that simplicity can fix this, everything already has deep built-in assumptions about everything else, which makes any replacement a daunting task.

Re: Cyber Security: A pre-war reality check

#44

Who cares? In the case of some sort of big war why would you care about "cyber security" when the day to day problem is not dying from starvation, being drafted, radiation posioning or what ever the problem is. These kind of "we need to prepare" are silly since they implicitly downplay the severity of war and bring us closer to it.

The underlying assumption of e.g. food distribution are that a certain part of infrastructure remains intact. This assumption comes into greater question the more individual parts are dependant on large software installations.

E.g. some countries have an entire redundant telecommunications network for government functions precisely so that it can actually withstand such a scenario. The more enmeshed that infrastructure is into other systems the more likely it is that it too will fail.

Re: Cyber Security: A pre-war reality check

#45

Earlier quoted context omitted.

Everything is computerized now. And most adjacent power wars will most likely be non-nuclear in nature until it crosses a red line.

Everything being computerized is a major peace time concern too. Ideally systems should not be as centralized as they are now and have offline fallbacks. I believe there is a great deal of over automization too. You can notice how war mongerers have turned to "cyber threats" to instigate on unfalsifiable information. I feel it might be better to pull the plug on the whole internet if that actually is such a concern.

It is incredibly hard to maintain an unused system. The Internet is the default mode of communications because it outperforms all other options on most metrics. Any backup would go nearly totally unused and therefore couldn't be effectively used during an outage.

Re: Cyber Security: A pre-war reality check

#47
post #41
post #25

Earlier quoted context omitted.

Picking on Ukraine, the US not having a policy of signing new people up to the anti-Russia military alliance every few years [0] seems like low hanging fruit. Or not working to integrate their intelligence with the CIA [1] for the last decade. I don't speak German but apparently Merkle said that we weren't negotiating in good faith to keep the peace either [2]. These are the sort of thing I suspect Russia would see a…

> US not having a policy of signing new people up to the anti-Russia military alliance every few years Weird how all of Russia's neighbors are eager to join a military alliance protecting them from Russia. I wonder if that has something to do with Russia's actions towards its neighbors? No, no, surely the US is to blame for that...

Yeah, sure. But the US chooses who it integrates with militarily. An alternative approach would have been to say "hey, yeah we can see why you'd want to join - but this will foment tensions with Russia, so you can't".

That is the kind of diplomacy would have prevented Russia from invading its neighbours. It would have been difficult to get worse outcomes with that approach than what the powers that be managed to get us to - we could be staring at the start of a major pattern of wars here and the US's deterrence has been spectacular in not quite succeeding. The Russian border is still closer to Moscow right now than it was in the 80s, but it has gotten a lot bloodier than the 90s.

Re: Cyber Security: A pre-war reality check

#48
> So you can have a whole board full of people that studied history and art and French, and they sit there making our cloud decisions. And they simply don’t know.

> And if there had been more nerds in that room, some of these things would not have happened. And that is also a call to maybe us nerds, although you don’t really look that nerdy, but do join those meetings.

> Because quite often, we as technical people, we’re like, “Ah, these meetings are an interruption of my work, and I’m not joining that meeting.” And while you were not there, the company decided to outsource everything to India.

Oof. This is hitting me hard on two levels.

As I'm racking up years in the operational business, the best impact I can have isn't that I can understand log files twice as fast as the guy next to me. Many people can learn that. The bigger impact is to be able to connect the effects of technical decisions onto the overall business and vice-versa to higher management.

Like, sure, I can rattle down a lot of technical requirements we need to self-host a highly available infrastructure, and I can rattle down a lot of the advantages of the cloud /in a small company situation/ and such.

But that is largely useless to the CEO of a small and medium business. The more interesting statement is: Self-hosting requires a larger upfront and a larger continuous investment over time at a certain range of scale. You need to buy servers, firewall, switches, rent bandwidth and DC space and to hire people to take care of all of these. However, we can achieve a higher level of security and data protection on these systems and in the long run, we can become cheaper than the big cloud providers, because the current product-visions are already decently big. The cloud can be more flexible and innovate faster, but we will have more security discussions with our customers and the control over our systems will be lower, for better or worse.

Put this way, we're setting up a pretty good self-hosted plan, which primarily uses the cloud as a way out if we or our DC hosters fuck up.

This plan cost the company more money than the existing cloud infra would have for a year or two, but now it is starting to pay off and in a year or two, hardware extensions will be a welcome expense.

But that is bringing me to a second point, deeper point: This only works because the board here is fine planning for benefits 3-5 years down the line. "In 2-3 years we'll be even", we said, and "in 3-5 years we'll be cheaper, a lot". We're even now 2 years after.

If they were just maximizing next quarters profits, we probably would have migrated everything to AWS and just started shoveling more money across the Atlantic, making us highly dependent on cross-atlantic and US infrastructure. It would've been cheaper for a year or so.

And this profit-maximizing mindset looming over good decisions and great tech is frustrating me.

Generative AI is similar there to me. Generative AI should be something I should be excited about. For example, Runegate Studios cooperated ethically with Unleash the Archers and Bo Bradshaw to create a music video[1] in Bo's style we just wouldn't have without generative AI and it would never be created without. And like, sure, it's not Disney quality, but you're looking at ~10 people cooperating here. For that headcount, that video is amazing.

But I know it will be used to slash jobs, prevent juniors from learning because AI is cheaper, ruin careers "because the AI can do 80% for less costs" and such. Short-term perspectives. And then in 10 years there will be a crisis of "Why can't we find good writers/cartoonists/musicians/... anymore?"

Sorry for the TED-talk. I'm currently torn between a very excited and a very frustrated person.

1: https://www.youtube.com/watch?v=eLPMBD7i0IU

Re: Cyber Security: A pre-war reality check

#49
I wonder if we, in secret, have “mutually assured destruction” of cyber-warfare.

It seems like a reasonable assumption to me that major world powers probably have enough 0-days at any one time that they could use them together to format a significant proportion of the world’s computers and phones. It would be not be that hard to make these worms intelligently use IP to target particular countries.

It’s hard for me to imagine how much damage it would do if I could wipe even say 25% of all work and home computers, maybe every phone not updated in the last 6 months, and a decent chunk of online servers.

Re: Cyber Security: A pre-war reality check

#50
post #3

Author here - if you have any questions, please do let me know!

You talked a lot about how bad it is for governments to outsource stuff to Huawei and a handful of US clouds, but didn't really touch on what drive all those decisions beyond claiming it's due to non-technical leadership. It'd be great to see a somewhat deeper analysis than that in future. There are plenty of tech companies that also outsource a lot to the cloud, so it has to be more complicated than that, and there are European mini-clouds that don't get much love from European governments also.

The basic problem is fundamental: outsourcing is a very common thing you find in all walks of life, it is often the most reasonable choice due to comparative advantage. This is the reason I eventually gave up on "decentralization" as a worthwhile technical goal (after years spent working on Bitcoin). Everyone is trying to outsource everything that isn't their key competitive advantage, and that's because specialization is the heart of progress. The costs of centralization are obvious in terms of loss of resiliency, but when people aren't actually needing that resiliency for entire lifetimes it's hard to convince anyone to take the loss of progress that decentralization may appear to entail.

So what to do? As you found with your 1,600 line imgur alternative just starting over to make stuff be secure is ... hard. You wrote in C++ (not the most security conscious choice) and some of those vulnerabilities are very basic, like the one where you discover that due to a bug some users are getting empty passwords. You also sort of assume that your users will keep your app up to date, but we know they won't. So simply demanding programs be smaller isn't going to work. You'll just speedrun the history of vulnerabilities. Indeed, one reason to outsource stuff to a handful of giant providers is that they do a much better job of security overall. Yeah Microsoft may have problems with Chinese hackers, but government IT routinely has problems with greedy teenagers. So MS is still ahead of the pack.

IMO the most critical thing is really whole-systems analysis to find sources of unnecessary complexity and fix it. That won't necessarily turn the tide, but it can at least help. As a trivial example, HTTP stacks don't understand the concept of load balancing. They're still stuck in a world where every website is run by a single computer. That entails a lot of server-side complexity like dedicated LBs, maybe even DNS LB, replicated databases, health checks, drain periods etc just to avoid users seeing little dinosaurs due to normal maintenance. The complexity of this is overwhelming. When users accepted things like "This service will be offline on Sunday due to maintenance" you could get away with it but now people expect everything to be 24/7, so that complexity drives people to the cloud where it's somewhat handled for them.

Thus an obvious quick win - extend HTTP and DNS to understand IP address globbing and maybe even static route matching. If a connection to a server fails, have the stack transparently fail over to another one. Now you can scrap your server side LBs and reverse proxies but still have an HA service.

Post reply on HN