Live data from Hacker News

Infosec's inability to quantify risk

blog.erratasec.com

1–10 of 54 posts

Re: Infosec's inability to quantify risk

#3

"Risk is binary, either there is risk or there isn't." What tripe.

That's what he was saying...

>Infosec isn't a real profession. Among the things missing is proper "risk analysis". Instead of quantifying risk, we treat it as an absolute. Risk is binary, either there is risk or there isn't. We respond to risk emotionally rather than rationally, claiming all risk needs to be removed. This is why nobody listens to us. Business leaders quantify and prioritize risk, but we don't, so our useless advice is ignored.

Re: Infosec's inability to quantify risk

#5
I'm not sure I agree - maybe I'm lucky to work in an organisation where we have a good understanding that infsec is all about risk. We build this into pretty much everything we do, and the only way to get stuff done is by demonstrating some reduction in risk.

Where we do have a problem, and it's an industry-wide problem, is that there is no real widely applicable methodology for evaluating and quantifying security risk. There are lots of risk assessment methodologies, but all of the ones we've tried still leave you making subjective decisions and best-guesses.

Re: Infosec's inability to quantify risk

#6
This disturbs me. Basically I think he's saying we should accept flawed and unproven technologies in the name of progress because "eh, any new risk is small compared to the risks we already face anyways".

The difference between a software hack and bad driving is one of responsibility for the risks we face. When people are negligent, we humans like to see people taking responsibility and facing justice. This is why the Jeeps have been recalled: the manufacturer is taking responsibility. Sloppy driving is also transient and hard to predict. It occurs when drivers are stressed, fatigued or distracted. Software flaws are just there. They can be triggered maliciously on-demand.

Debating whether self-driving cars are OK, because, hey, they will probably save more lives than they will take gives me chills. What about the emotional detachment this brings? Who will be responsible for these deaths?

I'm not exactly sure what I'm trying to put my finger on. It's not so much our inability to calculate probabilities and run statistical models. This is about something more sociological than that.

Re: Infosec's inability to quantify risk

#7
Infosec is easy to quantify: every security hole should be treated as though the lives of every human on Earth depended on it; also, 100% of software has security holes. If you take the logical conclusion of these two statements, it's obvious that the only winning move is not to play.

Re: Infosec's inability to quantify risk

#8
post #6

This disturbs me. Basically I think he's saying we should accept flawed and unproven technologies in the name of progress because "eh, any new risk is small compared to the risks we already face anyways". The difference between a software hack and bad driving is one of responsibility for the risks we face. When people are negligent, we humans like to see people taking responsibility and facing justice. This is why th…

I think he's saying that 'new risk' is replacing an older risk that is greater. But any risk model that doesn't take into account the risks we are replacing or mitigating is useless. If all risk is unacceptable then even mitigating risk is an unachievable goal.

Re: Infosec's inability to quantify risk

#9
This is something I'm struggling with as I attempt to educate myself more about security. I was a bit disappointed he went on to talk about the risk of a stunt, because there is virtually no quantifications of risks in anything I've read on the results of security research.

This seems to be borne out by the arguments about, say, the speed of disclosure vs patching. There is no agreement, and seemingly no desire to quantify the risk and danger of different types of flaw, different strategies for patching them, different disclosure schedules, etc. So, from my layperson's view, it seems like a wild west where the person who shouts the loudest, or acts the most obnoxiously, wins the argument. Cheered on by others who claim that such behavior is optimal overall. As an engineering discipline, it is rather mystifying, imho.

Re: Infosec's inability to quantify risk

#10
Not a fan of this post.

Yes, Charlie Miller and Chris Valasek's stunt had relatively low risk, but the difference is that they were risking the lives of innocent people who had nothing to do with it. You don't get to "quantify risk" for others who didn't ask for it, who are completely unassociated with you and your activities.

  "Business leaders quantify and prioritize risk, but we don't, so our useless advice is ignored."
I do agree that progress needs to be made on this front.
Post reply on HN