Live data from Hacker News

Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

usenix.org

41–50 of 184 posts

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#41

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

I have to ask, because IoT and lack of security are synonymous, who is providing secure IoT platforms to consumers? Is there history of such companies failing?

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#42
How about a law where someone who finds an exploit can claim a bounty against the company selling the product or publishing the website? This doesn't address the machine learning part, but it does address IoT and security generally.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#43

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

I have to ask, because IoT and lack of security are synonymous, who is providing secure IoT platforms to consumers? Is there history of such companies failing?

Such a company would be maybe 5 years late to the market, so...likely would never happen.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#44

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

I have to ask, because IoT and lack of security are synonymous, who is providing secure IoT platforms to consumers? Is there history of such companies failing?

At Azure Sphere we're trying! Dev boards ship in a month.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#45

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

I'm not sure that companies responding to obvious market failures isn't the companies' fault. We're not some geoup of mindless automatans max/mining for profit (that's the purview of the ML at discussion here). Selling shoddy, dangerous wares should come with consequences.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#46

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

This is like saying doctors should push cheap drugs that may or may not make your testicles explode because customers don't demand non-testicle exploding drugs.

We trust doctors to take into account all the nuances of medicine that laymen have never even heard of, and give us good advice. Because not everyone can be an expert on everything.

Its the same with software. We can't expect everyone to be an expert.. its up to our industry to act responsibly.

Sure its "market failure" in so far as duping uninformed people is a good way to make a quick buck, but the deeper issue is moral failure / failure to take responsibility.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#47

Oh boy Mickens must really hate blockchains and uncensorable platforms like a̶s̶s̶a̶s̶s̶i̶n̶a̶t̶i̶o̶n̶ prediction markets

"Blockchains Are a Bad Idea: More Specifically, Blockchains Are a Very Bad Idea."

https://www.youtube.com/watch?v=15RTC22Z2xI

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#48
Speaking generally, and not about this post - Keynote speakers often aren't technical (enough), but speak about topics that have technical underpinnings.

Take for example, dangerous management consultants who speak all over the place about AI, disruption, innovation, digital transformation, but don't know technology, which is the underpinning of all the things they're speaking about.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#49
He says at one point "Patrick Thistle" and I grant this seems like it makes sense, but indeed the name of that particular association football club is "Partick Thistle" and Partick is a real place, albeit not one which today would obviously be in need of a professional soccer team, and it isn't where they play.

Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?

#50

I love Mickens' work, and think this is overall a great presentation, but I feel like it misses (or maybe just doesn't fully explore) an important point. Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expre…

i agree with everything. however.

i recently subscribed to Curiosity Stream. its like netflix but only academic-ish documentaries. its "curated" by human beings. i can almost feel the lack of "algorithm". its weird how i feel about it, compared to youtube or whatever.

it reminds me a little bit of going to a "health food store" in the mid 1990s. they were all tiny, tiny niche shops usually owned by one person or a family. they sold weird stuff like organic tofu and soy milk. nowdays, you can buy both of those products in walmart and target.

something very strange happened... somehow the shitty mass market moved towards the tiny, higher quality, higher price niche products.

how did that happen?

Post reply on HN