Live data from Hacker News

Infosec's inability to quantify risk

blog.erratasec.com

11–20 of 54 posts

Re: Infosec's inability to quantify risk

#11
The problem with asking for better risk management for infosec is that "better risk management" pretty much comes out the same. In security terms, systems are secure when the cost of breaking the protection exceeds the value of what is being protected. In the software world, in the vast majority of cases, once a vulnerability is known, the cost of breaking the protection is indistinguishable from zero. The result is that it superficially appears that we treat things as binary risk, but in fact we are being perfectly rational.

Some of the rare examples of software security bugs where the attacks are practical but not free: Breaking RC4. BEAST. DDoS. The rare arbitrary code executions that require significant time to attempt due to needing to spray the heap just right.

But most of the time, it's click -> own.

The other thing that prevents useful quantification is that we don't have a Gaussian distribution to be seen. Rate of discovery, maybe, but that's it. We do not have Gaussian distribution on size of protected items, density of vulnerabilities, or anything else. Without that most of our good risk estimation techniques don't produce numbers that mean much to managers.

This is, IMHO, the fundamental reason why infosec doesn't get listened to. Our management structures are still highly Gaussian-biased (decades of manufacturing envy). They can't even wrap their head around software engineering schedules and costs after several decades, and infosec risks have even worse distributions! It is, in my very strong and considered opinion, perfectly rational for infosec to be vigorously ringing the bell. Consider exactly the bug we're talking about now... it's a vulnerability that has the potential to destroy the auto industry, were it properly exploited. (It would not just by Chrysler caught in the crossfire! And my use of present tense is considered. I have little reason to believe this is fixed, nor that it is the only such bug.) Our risk management procedures can not even properly express the idea that an engineer drawing a line between two nodes in the car's communications bus could have that result, can not properly express the Black Swan nature of that decision. But that's not infosec's fault, or at least, not infosec's fault alone.

And it's certainly not a solution for infosec to get more realistic about risk, because "more realistic about risk" probably means we ought to be a good factor of magnitude or so more strident, not less! The more I learn about the risks in this world the more horrifying it gets, and it's getting worse, not better, as things get more interconnected. Again, look at this car bug... it's something that could not possibly have existed 20 years ago. None of us, from CEO to engineer to QA, have even begun to properly process what this means, let alone react to it! And we won't until the Black Swan bites and probably not even then!

Re: Infosec's inability to quantify risk

#14
This article is flawed.

It seems to revolve around the fact that 'people commuting to work are more dangerous than 1 car stopping on the freeway'.

The article then proceeds to explain why this is so:

> 'No human is a perfect driver. Every time we get into our cars, instead of cycling or taking public transportation, we add risk to those around us.'

> 'We often see cars on the side of the road. Few accidents are caused by such cars. Sure, they add risk, but so do people abruptly changing lanes.'

The problem with this is that, obviously, the act of stopping the car in the middle of traffic needs to be _added_ to the risk that the security researchers involved have been generating the whole year round. Instead the author seems to compare the security risk of this incident with the risk an average driver generates in a whole year.

And even if it didn't the author's example is also a fallacy of relative privation. The fact that other things are more risky than stopping a car on the freeway, does not mean that it is not dangerous.

Pretty ironic that the author fails in his own analysis while talking about 'proper "risk analysis"'.

Re: Infosec's inability to quantify risk

#15
An inability to quantify risk is attributing a skill set to an industry which is probably not responsible for quantifying risk. Infosec researchers should only be beholden to identifying and detailing risks. There are infosec subsets that require better skills to identify risks, but those subsets are the one's more responsible for quantifying risk in an appropriate manner not the ENTIRE industry.

Quantifying risk is a very difficult endeavor to do properly so any measure of it is done from the security researchers biased perspective. Yes infosec researchers seem to want attention for their work this is often because there is not near enough attention paid to their work. Actuarial science is an entire professional field specifically tasked with quantifying risk, at least from an insurance perspective.

The inferred statement, at least in the title, is that not only do infosec researchers now have to stay up on crypto, assembly, js[buzzword] framework and on and on, but now they must also become actuarial scientists. As a neophyte in the industry I'm having trouble getting caught up to a static point let alone that the static point is a moving and rapidly accelerating target and not in my favor. Adding to this unachievable standard I now must study and become at least somewhat proficient in actuarial sciences is maddening!

Re: Infosec's inability to quantify risk

#16
What apologetics for this demo seem to gloss over, or worse, not realize is the real problem, is not just the increased risk. It's the increased risk and removal of choice from all the unwitting participants.

> In college, I owned a poorly maintained VW bug that would occasionally lose power on the freeway, such as from an electrical connection falling off from vibration. I caused more risk by not maintaining my car than these security researchers did.

If while in college and driving this vehicle you decided to film yourself, made it clear your were pretty certain the car was going to lose power, got onto a freeway, and when the car lost power said something to the effect of "oh shit, this is dangerous", then yes, you would be facing a lot of criticism right now too.

If you were a researcher and had a few more years than college age under your belt, and if the point was also to raise awareness about something dangerous, you should expect criticism doubly so, because more is expected from you than some yokel on youtube trying to make a funny video.

Driving a car is an inherently dangerous activity. We've become complacent about it, but there's still many deaths each year (~1.4 of each 100 deaths was car related in 2013)[1]. For most people, it's the most dangerous thing they'll do each day. Driving requires a level of cognitive dissonance about how likely other drivers are to be paying attention, and driving with good intentions. When this is broken, though obviously dangerous driving on the road (such as the speeder doing dangerous lane changes) or introducing unnecessary risks, our reaction is to punish. Police stop dangerous drivers when they see them. These researchers broadcasted equivalent behavior, they are getting an equivalent response (albeit from the public).

1: http://www.cdc.gov/nchs/data/nvsr/nvsr64/nvsr64_02.pdf

Re: Infosec's inability to quantify risk

#17
> In hindsight, it's obvious to everyone that Valasek and Miller went too far.

Not at all; they didn't create new risks, they just exposed existing risks. And the security community's reaction isn't their fault, either.

And sometimes an industry needs a wakeup call to take a topic serious.

Re: Infosec's inability to quantify risk

#19

Not a fan of this post. Yes, Charlie Miller and Chris Valasek's stunt had relatively low risk, but the difference is that they were risking the lives of innocent people who had nothing to do with it. You don't get to "quantify risk" for others who didn't ask for it, who are completely unassociated with you and your activities. "Business leaders quantify and prioritize risk, but we don't, so our useless advice is igno…

Every time you drive a car you are risking the lives of innocent people who had nothing to do with it.

Re: Infosec's inability to quantify risk

#20
post #16

What apologetics for this demo seem to gloss over, or worse, not realize is the real problem, is not just the increased risk. It's the increased risk and removal of choice from all the unwitting participants. > In college, I owned a poorly maintained VW bug that would occasionally lose power on the freeway, such as from an electrical connection falling off from vibration. I caused more risk by not maintaining my car…

It isn't that apologetic:

In hindsight, it's obvious to everyone that Valasek and Miller went too far.

It's not encouraging them to double down and do more live traffic tests, it's encouraging other people to calibrate their reactions a little bit, so as to not lose sight of the very real benefit that came out of the research.

Post reply on HN