Live data from Hacker News

Cyber Security: A pre-war reality check

berthub.eu

271–280 of 286 posts

Re: Cyber Security: A pre-war reality check

#271
post #269

Earlier quoted context omitted.

My colleagues and I submitted a similar talk/paper for a different NCSC conference (but weren't accepted). I see that this talk by Bert Hubert covers mostly the ground. so I am pleased, but worried about what this take misses out. Hubert is addressing much of the ground that lies between security and resilience. Our emphasis is on how mitigation lies in education and autonomous systems over regulation. Not that regul…

@nonramdonstring: The email address hr@... in your profile is broken. You're welcome to try the one in my profile.

Thankyou for telling me. I may have missed other coms, my apologies.

Re: Cyber Security: A pre-war reality check

#272

Earlier quoted context omitted.

Look at the rate at which munitions are expended on the frontlines in Ukraine, for example. Those kinds of amounts need the transportation network to be working in good order. Bring down a single major logistics hub, and bad things happen.

If the US were truly engaged production would scale up like it did in wwii. We can always go back to a centrally planned economy.

I'm not talking about production here, but delivery. For that you need roads and railroads, bridges etc to function. How many of those are susceptible to digital takedowns?

Although factories are also an interesting case if they are not airgapped.

Re: Cyber Security: A pre-war reality check

#273

Earlier quoted context omitted.

It is the most reasonable choice when you get to disregard the long-term risks because by the time they are likely to manifest in a problem, it's no longer your concern anyway. I don't think it's accurate to describe it as "loss of progress", either. It just makes progress more expensive . There's no reason why e.g. those support & maintenance jobs cannot be located in the same country, or at least a friendly one - i…

Nothing magical about them except: 1. They work for far less money. 2. They designed the equipment that's being managed. Those two reasons are sufficient on their own to make them inherently better at managing 5G networks. The first reason in particular is lost if you relocate the jobs to the west.

That's exactly my point. The first reason can be reformulated as, "security isn't free". The problem, of course, is that expenditures are immediate, while any mitigated attacks would be in the future. So any politician and any businessman who tries to solve it gets held accountable for the expenditures, and loses to competitors who just promise cheaper everything (and who won't even be there when SHTF as a result of those policies).

The second reason is largely the consequence of the first. There's no reason why that equipment couldn't be designed locally, either, except that costs of labor would be higher.

Tangentially I will also note that the main reason why costs of labor are lower in China is because the quality of life is so much shittier. I think it behooves us all in First World countries to consider what it really means for our societies if they truly cannot function without relying on the kind of cheap labor elsewhere that we made impossible in our own countries, largely for ethical reasons (labor rights, social welfare etc).

Re: Cyber Security: A pre-war reality check

#274
post #269

Earlier quoted context omitted.

My colleagues and I submitted a similar talk/paper for a different NCSC conference (but weren't accepted). I see that this talk by Bert Hubert covers mostly the ground. so I am pleased, but worried about what this take misses out. Hubert is addressing much of the ground that lies between security and resilience. Our emphasis is on how mitigation lies in education and autonomous systems over regulation. Not that regul…

@nonramdonstring: The email address hr@... in your profile is broken. You're welcome to try the one in my profile.

In spite of my typo in the parent, I really did send to hn@. I just checked the bounce to be sure.

Re: Cyber Security: A pre-war reality check

#275

Over a decade ago I wrote an article that included the prediction that the vulnerability of western infrastructure to cyber operations would prevent the US from intervening to support lesser allies. The rationale was the domestic costs of chaos caused by infrastructure attacks would cause hesitation to intervene in foreign wars, and this hesitation and vulnerability would embolden foreign antagonists like Russia and…

I think what is missing from this analysis is the offensive capability of American cyber. The way it is completely downplayed I suspect is proportional to its strength. If there was all this chatter how we need to invest more in offensive cyber I would be worried. The way we pretend like it doesn't even exist is all you need to know.

Where's the deterrent effect?

Re: Cyber Security: A pre-war reality check

#276

Earlier quoted context omitted.

> Part of this is that nobody has cared about security since the beginning, for basically anything in tech. > It’s an industry-wide issue that permeates every level of the stack. Can you explain? I don't understand. Here's my take. Let's start from the bottom of the stack. CPU has some good security protections. They have ways to ensure that boot code is signed. They have hardware protection for memory. They have mem…

>Let's move to OS. Well, there's lot of security stuff in any OS. Process isolation, namespace isolation, encrypted storage. How can the user run some random application and not have it wipe out their OS? Can they plug in a random USB stick safely? There's no real security in the OS part of the stack, but lots of security theater.

What app on my phone could delete the OS? It isn't even possible. It can't even delete normal user files without explicit file access permission.

Re: Cyber Security: A pre-war reality check

#277

Earlier quoted context omitted.

>Let's move to OS. Well, there's lot of security stuff in any OS. Process isolation, namespace isolation, encrypted storage. How can the user run some random application and not have it wipe out their OS? Can they plug in a random USB stick safely? There's no real security in the OS part of the stack, but lots of security theater.

What app on my phone could delete the OS? It isn't even possible. It can't even delete normal user files without explicit file access permission.

Both iOS and Android have had zero day exploits announced this year, what makes you think they've all been found?

Re: Cyber Security: A pre-war reality check

#278
post #191

Earlier quoted context omitted.

The only thing that would have changed is that Russia now also could invade the baltic states. Why do you think Russia would not have invaded Ukraine if the NATO had not been expanded?

Under what circumstances would Russia feel a need to invade Ukraine if they didn't fear NATO involvement? It is pretty clear in the current war that exactly what the Russian leadership feared was happening - a pushover country on their border was being militarised by the US. In hindsight they must feel naive for not being more paranoid and bulking up their military before going in. The NATO enlargement is a broad str…

are you saying that if US was kot involved then Ukrainy would have to do whatever Russia tell yhwm yo do and that would be better for Ukraine?

And yes sure, Russia is nust defending itself

Re: Cyber Security: A pre-war reality check

#279

Earlier quoted context omitted.

>Let's move to OS. Well, there's lot of security stuff in any OS. Process isolation, namespace isolation, encrypted storage. How can the user run some random application and not have it wipe out their OS? Can they plug in a random USB stick safely? There's no real security in the OS part of the stack, but lots of security theater.

What app on my phone could delete the OS? It isn't even possible. It can't even delete normal user files without explicit file access permission.

Who runs container orchestrators on phones?

Re: Cyber Security: A pre-war reality check

#280
post #278
post #191

Earlier quoted context omitted.

Under what circumstances would Russia feel a need to invade Ukraine if they didn't fear NATO involvement? It is pretty clear in the current war that exactly what the Russian leadership feared was happening - a pushover country on their border was being militarised by the US. In hindsight they must feel naive for not being more paranoid and bulking up their military before going in. The NATO enlargement is a broad str…

are you saying that if US was kot involved then Ukrainy would have to do whatever Russia tell yhwm yo do and that would be better for Ukraine? And yes sure, Russia is nust defending itself

Ukraine was faced with a choice - do what the US wanted, or do what Russia wanted. The US choice resulted in massive death, destruction and so far it looks like Russia is going to get what they wanted anyway.

What would the downside have been of just folding before the troops started moving?

> And yes sure, Russia is nust defending itself

Best defence is a good offence. They're flailing under strategic pressure from the US.

Post reply on HN