Live data from Hacker News

Infosec's inability to quantify risk

blog.erratasec.com

31–40 of 54 posts

Re: Infosec's inability to quantify risk

#31

Infosec is easy to quantify: every security hole should be treated as though the lives of every human on Earth depended on it; also, 100% of software has security holes. If you take the logical conclusion of these two statements, it's obvious that the only winning move is not to play.

every security hole should be treated as though the lives of every human on Earth depended on it What possible reason would lead you to do that?

Maybe the personalities of some security researchers? /s

Re: Infosec's inability to quantify risk

#32
Verizon has a 70-page report on data breaches as of early 2015, which is a necessary step towards the quantification of security risk by insurance companies: http://www.verizonenterprise.com/DBIR/2015 . As explained in "Cyber-Insurance: Triumph of the Accountants", https://securityledger.com/2015/05/cyber-insurance-triumph-o...

"What will this mean for companies? At the behest of insurers, they will need to clean up their acts. Just as drivers must show proficiency behind the wheel over long periods of time, companies will need show progress along the curve of “cyber maturity” to gain access to the lowest premiums and the smallest deductibles."

Re: Infosec's inability to quantify risk

#33

Not a fan of this post. Yes, Charlie Miller and Chris Valasek's stunt had relatively low risk, but the difference is that they were risking the lives of innocent people who had nothing to do with it. You don't get to "quantify risk" for others who didn't ask for it, who are completely unassociated with you and your activities. "Business leaders quantify and prioritize risk, but we don't, so our useless advice is igno…

> "You don't get to "quantify risk" for others who didn't ask for it, who are completely unassociated with you and your activities." To take an example from the article: when you change lanes in a car, you're incurring risk for others "who didn't ask for it, and are completely unassociated with and your activities." I agree that it's generally unacceptable to incur risk to others' lives, but in actual fact we do it o…

  when you change lanes in a car, you're incurring risk for others
The difference is there's a reasonable expectation of danger from other drivers every time you're on the road. OTOH, you have no reasonable expectation of danger coming from random security researchers.

  people seem to ignore existing systematic risk and privilege preventing non-systematic risk
Agree 100%, I think we agree on a lot here.

Re: Infosec's inability to quantify risk

#34
post #26
post #6

This disturbs me. Basically I think he's saying we should accept flawed and unproven technologies in the name of progress because "eh, any new risk is small compared to the risks we already face anyways". The difference between a software hack and bad driving is one of responsibility for the risks we face. When people are negligent, we humans like to see people taking responsibility and facing justice. This is why th…

> Who will be responsible for these deaths? There is not always a responsible party. What about the child that runs out into the road, and you have no chance to avoid them? Will you decry self-driving cars when this incident happens to them? Searching for "who is responsible" when the car is self-driving is self-defeating. When the car is driven by an algorithm, the algorithm can be improved. One death could prevent…

Curiously, back when cars first appeared, people did decry them for hitting children (and adults) even if they ran into the road. It was only after a wide campaign (which also created the term "Jaywalk") that car proponents got the public to reverse their opinion. From an episode of the great podcast 99% Invisible:

Much of the public viewed the car as a death machine. One newspaper cartoon even compared the car to Moloch, the god to whom the Ammonites supposedly sacrificed their children.

Pedestrian deaths were considered public tragedies. Cities held parades and built monuments in memory of children who had been struck and killed by cars. Mothers of children killed in the streets were given a special white star to honor their loss.

http://99percentinvisible.org/episode/episode-76-the-modern-...

Re: Infosec's inability to quantify risk

#35
post #14

This article is flawed. It seems to revolve around the fact that 'people commuting to work are more dangerous than 1 car stopping on the freeway'. The article then proceeds to explain why this is so: > 'No human is a perfect driver. Every time we get into our cars, instead of cycling or taking public transportation, we add risk to those around us.' > 'We often see cars on the side of the road. Few accidents are cause…

I think this is an interesting and valid response but that you might be missing his point. He's not saying that relative risk says the highway stunt was ok; in fact, he's saying the opposite, if you read all the way to the end.

In that context, it is reasonable to argue that the added risk was minimal.

Re: Infosec's inability to quantify risk

#36
post #6

This disturbs me. Basically I think he's saying we should accept flawed and unproven technologies in the name of progress because "eh, any new risk is small compared to the risks we already face anyways". The difference between a software hack and bad driving is one of responsibility for the risks we face. When people are negligent, we humans like to see people taking responsibility and facing justice. This is why th…

But if, over the course of a year, self-driving cars are shown to be even a smidgen safer than manual cars, they are undeniably superior — even if assigning responsibility is a bit more complex. I agree that emotional detachment concerning road fatalities is unacceptable, but you have to be careful that, in your quest for justice, you don't see more road deaths as an acceptable cost.

Re: Infosec's inability to quantify risk

#37
post #35
post #14

This article is flawed. It seems to revolve around the fact that 'people commuting to work are more dangerous than 1 car stopping on the freeway'. The article then proceeds to explain why this is so: > 'No human is a perfect driver. Every time we get into our cars, instead of cycling or taking public transportation, we add risk to those around us.' > 'We often see cars on the side of the road. Few accidents are cause…

I think this is an interesting and valid response but that you might be missing his point. He's not saying that relative risk says the highway stunt was ok; in fact, he's saying the opposite, if you read all the way to the end. In that context, it is reasonable to argue that the added risk was minimal.

I did not miss his point, I even agree with his final paragraph. But all but the last paragraph of the article is based on flawed comparisons.

Re: Infosec's inability to quantify risk

#39
How the hell can we quantify the risk of data? Where is the price discovery mechanism in a world where "information must be free"? You can only buy insurance if you know not only how likely it is that you'll lose the thing you're insuring but also how much it costs!

Maybe we need to update whatever concept of intellectual property we developed in the 90s that got us to the current state of affairs...

Re: Infosec's inability to quantify risk

#40

Earlier quoted context omitted.

> "You don't get to "quantify risk" for others who didn't ask for it, who are completely unassociated with you and your activities." To take an example from the article: when you change lanes in a car, you're incurring risk for others "who didn't ask for it, and are completely unassociated with and your activities." I agree that it's generally unacceptable to incur risk to others' lives, but in actual fact we do it o…

when you change lanes in a car, you're incurring risk for others The difference is there's a reasonable expectation of danger from other drivers every time you're on the road. OTOH, you have no reasonable expectation of danger coming from random security researchers. people seem to ignore existing systematic risk and privilege preventing non-systematic risk Agree 100%, I think we agree on a lot here.

>>The difference is there's a reasonable expectation of danger from other drivers every time you're on the road. OTOH, you have no reasonable expectation of danger coming from random security researchers.

Not sure what you mean. If you're driving on the freeway and the car in front of you loses power, why does it matter whether it lost power due to lack of maintenance or because it got hacked by security researchers? The impact for you, and your solution, will be the same: momentary confusion followed by corrective action.

Post reply on HN