Live data from Hacker News

Security for the people

google-opensource.blogspot.com

31–40 of 58 posts

Re: Security for the people

#31
It's very odd that they lead off by focusing on unrelated FUD.

> However, if people are indeed working to protect themselves, why are we still seeing incidents, breaches, and confusion?

That references a completely different security area, and as much as it's a juicy source of scare stories for mass media, it's unrelated to end user security with respect to government and corporate mass surveillance.

The former is basically insecure by design (based on the assumption that transactions are always reversible), with the duct tape occasionally failing. The latter will never manifest itself as a discrete problem for the sheer majority of people, but just an ever-growing set of annoyances and chilling effect on one's thoughts and actions.

They require completely different approaches. For the former simply having backup credit cards, being prepared to sue your banks for negligently giving away your money, and flagging the pop culture scare articles off Hacker News - that's about all you can do, because the deficient technology is not yours.

The latter requires proactively analyzing the implications of one's technology choices and avoiding the attractive nuisances. Fixing these problems is not at all straightforward and is one of the great struggles of our time, which is why it is such a disservice to conflate the two.

Re: Security for the people

#32
post #12

Researching and developing usability and security auditing practices. How do we measure the two in a single assessment? You don't. They're wildly different disciplines. Security auditing is fundamentally a systems programming problem. The least effective security "auditors" approach security as something different than software engineering. The most significant security issues arise from correctness issues; finding a…

I agree that these are separate disciplines, but I think that one reason we're not seeing anyone who does security usability work well right now is that that the best practitioners in each field tend to be silo'd by their specialization.

A single assessment is not necessarily a single metric, and an assessment comprised of audits in each domain seems like a good first step toward building understanding of a common goal and measuring progress toward it. Putting these audits together will hopefully start to expose not only the tradeoffs, but also the synergies at play in designing secure systems.

It seems to me that at the root of the security usability problem is a failure in collaboration between developers with solid software engineering practices and designers with solid UX design practices. Talent on both sides is in high demand, but there are few organizations that are able to get both working together effectively on these hard problems.

Re: Security for the people

#33

A PR announcement of an initiative to form a coalition to investigate making it easier to use security tools that most people don't care about. How thoughtful of you, Google. This wouldn't be an attempt at improving the public's negative view of you with regard to privacy issues, now would it? Funny how Google doesn't offer a messaging service that's secured to a physical device the way Apple does, and these projects…

You seem to imply that there is no real value in the initiative. I humbly suggest you ask the teams doing all the work (Guardian Project, Open Whisper Systems, F-Droid, etc.) how excited they are about this. I suspect it's not as intangible or fuzzy as you imagine. They're expecting real resources and real funding, which will result in real progress for their already-strapped projects.

Re: Security for the people

#34
On the topic of bringing better security to normal users, the project I'm most hopeful about is the FIDO alliance's U2F and UAF standards.[0] There's a new YubiKey that implements U2F, which is supposed to ship soon.[1]

I'm optimistic because these are open standards backed by many big organizations, and web browsers will be shipping with support built right in, no drivers, no plugins.

Tokens like that Yubikey work over USB HID (they look like keyboards to the OS, so they don't need dedicated drivers). They also work over NFC on mobile devices (ok, on Android devices. Still waiting on iOS.)

[0] https://fidoalliance.org/specifications [1] http://www.yubico.com/2014/09/yubikey-neo-u2f/

Re: Security for the people

#35
post #10

The toolbox logo for simply secure is killing me. Whomever made the logo has never used any hand tools. The saw is part hacksaw part panel saw.

It's a back saw. Sure it has a weird handle and low tpi, but every woodworker knows what a back saw is.

And how many woodworkers have a back saw with a hack saw handle? I just went through a ton of clip-art toolboxes and cant find any where the designer decided to go with the extemporaneous saw design.

Re: Security for the people

#36
I'm excited to see how the Guardian Project will use the resources. God love em, but their projects seem to have less UX polish compared to those of Open Whisper Systems, likely due to Twitter's positive post-acquisition influence on the latter.

Re: Security for the people

#37
post #35

Earlier quoted context omitted.

It's a back saw. Sure it has a weird handle and low tpi, but every woodworker knows what a back saw is.

And how many woodworkers have a back saw with a hack saw handle? I just went through a ton of clip-art toolboxes and cant find any where the designer decided to go with the extemporaneous saw design.

If you're nitpicking the handle design on some clip-art, then I think you should probably just step back a bit.

Re: Security for the people

#38
post #35

Earlier quoted context omitted.

And how many woodworkers have a back saw with a hack saw handle? I just went through a ton of clip-art toolboxes and cant find any where the designer decided to go with the extemporaneous saw design.

If you're nitpicking the handle design on some clip-art, then I think you should probably just step back a bit.

This thread has some great 'Shit HN says' lines. We are truly a tiny little bubble.

Re: Security for the people

#39
post #15

Earlier quoted context omitted.

> We believe that SJCL provides the best security which is practically available in Javascript. (Unforunately, this is not as great as in desktop applications because it is not feasible to completely protect against code injection, malicious servers and side-channel attacks.)

And? It's vetted by a cryptographer who noted the caveats that apply. Do you take 'vetted' to mean 'unreservedly recommend'?

I would, yes.

His disclaimer mentions three game-over problems.

Re: Security for the people

#40

The simplysecure.org domain uses Google Analytics which isn't disclosed on their privacy page (as required by Google Analytics' TOS). There is also a mixed-content warning because someone hard-coded an http:// link to the balloons image in the blog post on their https site. I went to email them and first looked for PGP keys (us pro-privacy & security people all use PGP, right?) and found none for the domain on any ke…

    I've offered to help and recommended they switch to Piwik (and fix the http link).
HN does tech satire so much better than the rest of the internet..
Post reply on HN