Live data from Hacker News

Bruce Schneier: Chrome OS's Security Claims "Idiotic"

readwriteweb.com

11–20 of 34 posts

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#11
"Guru" is probably the right word to use for Schneier at this point, and here's another great example of him inserting himself into a story he has no involvement in, making comments that betray a complete lack of awareness of the context of the story he's commenting on. Par, unfortunately, for the course.

It is doubtless the case that Schneier is fielding constant phone calls from trade reporters asking for his opinions on the security news of the day. Taking those calls, and writing the op-ed-style pieces that generate them, is probably the bulk of his job description. And so it's to be expected that he's going to be asked questions about things like Chrome's "virus-proofness", and having given no thought to Chrome or its architecture, be at a loss for pithy commentary. Hence, "2+2=3". Thanks, Bruce.

But before you feel too much sympathy for him, remember that he always has the ability to tell the reporter, "sorry, I don't know enough to comment intelligently on this story".

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#12
post #3

"It was mathematically proved decades ago that it is impossible -- not an engineering impossibility, not technologically impossible, but the 2+2=3 kind of impossible -- to create an operating system that is immune to viruses." Does anyone know what he's referring to? That would be an interesting read.

He's talking about the halting problem, which isn't "2+2=3" impossible, but undecidable. Of course, the average engineer at Google has vastly more CS education than Schneier, would never have claimed to have solved the halting problem (or "program intent" as the AV people put it), and would have responded to this question more succinctly and accurately than Schneier did.

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#13

"Google, while announcing its new Chrome operating system late Tuesday, said users would no longer have to worry about viruses, malware and security updates" Good marketing. Tough to live down when you're first discovered to be "human" (developed by software engineers) - as it will be when Apple's first takes a major hit [which news suggests the iPhone may be vulnerable to].

"Google... said users would no longer have to worry about viruses, malware and security updates"

I'm guessing since most applications on Chrome will be web-based, the vendor will worry about them. They will be able to more easily and quickly detect + destroy phishing schemes, viruses etc. Kind of like how Facebook has responded to malicious wall posts.

For me the bigger concern would be the loss of productivity due to downtime of web services, or loss of internet connectivity.

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#14
post #12
post #3

"It was mathematically proved decades ago that it is impossible -- not an engineering impossibility, not technologically impossible, but the 2+2=3 kind of impossible -- to create an operating system that is immune to viruses." Does anyone know what he's referring to? That would be an interesting read.

He's talking about the halting problem, which isn't "2+2=3" impossible, but undecidable. Of course, the average engineer at Google has vastly more CS education than Schneier, would never have claimed to have solved the halting problem (or "program intent" as the AV people put it), and would have responded to this question more succinctly and accurately than Schneier did.

An infinite loop does not a virus make. With a multithreaded OS an infinite loop is not really a problem. Limiting resources to some defined level is a "solvable" problem.

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#15
I think making a claim like users don't have to deal with viruses, malware, and security updates is potentially more dangerous than having an OS with a less robust security model.

Even linux and BSD systems are vulnerable if malicious programs are given the necessary permissions to run. If a casual user hears something like, "This OS is immune to viruses", they're likely to be a lot less cautious about running programs that might auto load from websites. By now most Windows users know better than to click OK when a website wants to install something on your PC.

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#16
post #14
post #12

Earlier quoted context omitted.

He's talking about the halting problem, which isn't "2+2=3" impossible, but undecidable. Of course, the average engineer at Google has vastly more CS education than Schneier, would never have claimed to have solved the halting problem (or "program intent" as the AV people put it), and would have responded to this question more succinctly and accurately than Schneier did.

An infinite loop does not a virus make. With a multithreaded OS an infinite loop is not really a problem. Limiting resources to some defined level is a "solvable" problem.

The antivirus problem isn't a resource consumption problem. "The halting problem" is a CS synecdoche for the limitations of static analysis and the fundamental generality of what a "virus" is.

He's saying, "we mathematically figured out a long time that trying to look at a computer program and predetermine what it will do before running it is a task that reduces to the halting problem."

That this is a stupid way to look at the antivirus problem is besides the point here.

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#17
post #14
post #12

Earlier quoted context omitted.

He's talking about the halting problem, which isn't "2+2=3" impossible, but undecidable. Of course, the average engineer at Google has vastly more CS education than Schneier, would never have claimed to have solved the halting problem (or "program intent" as the AV people put it), and would have responded to this question more succinctly and accurately than Schneier did.

An infinite loop does not a virus make. With a multithreaded OS an infinite loop is not really a problem. Limiting resources to some defined level is a "solvable" problem.

Allowing friendly programs to access resources but disallowing unfriendly ones is impossible, because it is impossible to distinguish between the two without some form of enforced signing that is impossible for the user to subvert(and who wants that?). And no, defaulting to reduced permissions for some programs is insufficient. People will still click "Ok, allow higher permissions" on programs if prompted.

What's the difference between 'rm -rf foo', for example, and 'run-virus'?

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#18
post #11

"Guru" is probably the right word to use for Schneier at this point, and here's another great example of him inserting himself into a story he has no involvement in, making comments that betray a complete lack of awareness of the context of the story he's commenting on. Par, unfortunately, for the course. It is doubtless the case that Schneier is fielding constant phone calls from trade reporters asking for his opini…

You've been interviewed by a reporter, yes? His very next sentence could have been something like, "It's not going to be virus-proof, but I'm glad to see they're thinking about security early. There is still a lot that can be done at the operating system level to improve security for the user."

The reporter would have cut that part out. It's not controversial enough. You could do the same thing with his blog post on homomorphic encryption if you took the phrases, "Gentry’s scheme is completely impractical," and "I think he’s being optimistic with even this most simple of examples," in isolation from "practicality be damned -- this is an amazing piece of work," and "I never expected to see one [a secure fully homomorphic cryptosystem]."

I don't understand this need to pull Schneier down. He's a smart guy, most of his writing is good, and he helped design a cipher that came pretty close to being selected for AES. Anyone who enters the media game is going to end up getting a bit caricatured.

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#19
These sorts of arguments really make me facepalm.

Listen, Bruce, they don't literally mean that their OS will be completely and 100% totally impervious to any sort of malware or virus attack of any kind ever to exist ever in the future ever ever ever to infinity times infinity.

They mean that their OS will be considerably more resistant to any sort of reasonable malware attack in the foreseeable future, and they're 100% correct.

Windows, even just because of its target market, will be the low hanging fruit for as long as I think anybody can foresee. Simply because of this, linux and bsd-kernel based operating systems that are using proper user isolation (meaning not running as the freaking root account by default) are going to be more secure than windows.

Re: Bruce Schneier: Chrome OS's Security Claims "Idiotic"

#20
post #15

I think making a claim like users don't have to deal with viruses, malware, and security updates is potentially more dangerous than having an OS with a less robust security model. Even linux and BSD systems are vulnerable if malicious programs are given the necessary permissions to run. If a casual user hears something like, "This OS is immune to viruses", they're likely to be a lot less cautious about running progra…

By now most Windows users know better than to click OK when a website wants to install something on your PC.

Have any data to back that up? Because my impression is the opposite.

Post reply on HN