Earlier quoted context omitted.
What you are describing is an example of of customers demanding non-testicle exploding drugs as why we don't have them. When a drug causes problems, customers often end up suing the manufacturer/developer of said drug. If doctors prescribe said drugs after it becomes common knowledge that it could cause a problem, they also might be sued for malpractice. Are people sing IoT companies for poor security practices? If s…
nobody's ever sued me for leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation to do exactly that. why? well, gosh darn it, because it's the right thing to do! i think the drive to reduce every bit of human behavior to economic incentives backed by a government force structure is ultima…
Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
101–110 of 184 posts
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#102Earlier quoted context omitted.
nobody's ever sued me for leaving flaming bags of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly. yet, every day, i resist the overriding temptation to do exactly that. why? well, gosh darn it, because it's the right thing to do! i think the drive to reduce every bit of human behavior to economic incentives backed by a government force structure is ultima…
Good but me and I'm sure many other people will happily leave flaming of dog poop on your front porch before ringing your doorbell and making a getaway by segway while cackling madly if nobody ever sued me.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#103Earlier quoted context omitted.
> They are instead classic examples of market failure. The way to fix market failure is well understood, though; regulation. You're arguing for regulation of the software industry, just as we have regulation of the medical industry or the oil industry. (The software engineering industry is, I would argue, drastically under-regulated.)
Not necessarily. It could also be done by allowing people to sue makers of insecure software or hardware.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#104Earlier quoted context omitted.
This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs . We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything. Its the same with software. We can't expect everyone to be an expert.. its u…
...and we don't just rely on drug makers, for example, to be moral and take responsibility. We have government agencies that _require_ strict testing of their safety and effectiveness. If we left it up to the market, we would get inferior results. The problem is, we have no FDA equivalent for tech security.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#105Earlier quoted context omitted.
Customers can't evaluate security of IoT devices and, furthermore, they can't even evaluate what the downside of an insecure device is. So my printer is insecure- what does that mean for me? How much should I care? At least with cars, you know what an unsafe car can do (kill you) and it still took Ralph Nader's book and citizen pressure to set up a federal agency to oversee car safety. Also, even when most people kno…
They can for some of them if you give them this pic from Brian Krebs: https://krebsonsecurity.com/2012/10/the-scrap-value-of-a-hac... Got through to a lot of them that way. They were more likely to practice better computer security or buy less "smart" products that don't need to be smart.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#106Earlier quoted context omitted.
Not necessarily. It could also be done by allowing people to sue makers of insecure software or hardware.
This is worse. This leads to lawyers making the critical decisions instead of regulators and auditors. The latter group at least has some familiarity with the subject area.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#107I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…
I'm not sure that companies responding to obvious market failures isn't the companies' fault. We're not some geoup of mindless automatans max/mining for profit (that's the purview of the ML at discussion here). Selling shoddy, dangerous wares should come with consequences.
Haven’t spent much time around investment bankers huh?
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#108Earlier quoted context omitted.
But how can a customer demand security? There is nothing that a customer can do to choose a more secure IoT device over a less secure one. Even if you look at known vulns, simply having vulns in the past is not necessarily reflective of current security posture. Beyond pentesting an app, how does a consumer act on their desire for a secure device?
There's been security evaluations of products where evaluators do both checklist stuff and try to hack the product. Consumers could buy the stuff that gets cleared through those processes. For instance, there's products on the market like INTEGRITY-178B and LynxSecure designed specifically for securely partitioning systems. They have networking stacks available, too. On occasion, a company would make things like rout…
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#109Fixing security is quite possible. Install a backdoor, go to jail for "exceeding authorized access". Fail to fix an security bug, get sued for negligence. Make it public policy that license contracts cannot override those responsibilities.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#110I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…
Here is the most classic and widely cited paper ever on market failure when customers can't tell what's good and what's a lemon: The Market for "Lemons": Quality Uncertainty and the Market Mechanism https://www.sas.upenn.edu/~hfang/teaching/socialinsurance/re... It's strikingly prescient that Akerlof mentions 'group insurance' as another market that is rife for failure due to a slightly different mechanism. Here we a…