Live data from Hacker News

Infosec's inability to quantify risk

blog.erratasec.com

41–50 of 54 posts

Re: Infosec's inability to quantify risk

#41
I was flying with a friend one time and he jokingly said "never hack the plane your flying on", while it was just joke, it's something I'd never actually considered although it's blatantly obvious. Sometimes people get caught up in their own curiosity, don't think through their plan and loose perspective on the consequences of their actions.

While what they did was reckless and irresponsible, I think their overall intentions were to inform of the risk associated with vulnerabilities/hacking of this nature and raise awareness. I would assume that they have learned from this, and won't be shutting down cars on a highway to show off anymore.

The thing about risk is that it's best dealt with when there is a clear understanding of it, the conversation on what is appropriate testing, and raising the general awareness of the public regarding these vulnerabilities are both factors that will hopefully mitigate risks moving forward.

Re: Infosec's inability to quantify risk

#42
I dont wanna secure shit and i like clicks.

Risk is about data. It doesn't matter if its security related or not. No data, no risk quantification.

You do not have data - so you blog post is actually useless.

Re: Infosec's inability to quantify risk

#43
Note that before software development suffered from Infosec's inability to quantify risk, it suffered (and still suffers) from lawyer's inability to quantify risk. If you want a black-and-white requirement, ask your legal department. After some length of time, they'll say "yes" or "no". Nothing in between.

It's the same phenomenon.

Re: Infosec's inability to quantify risk

#44
"Quantifying risk" statistically is meaningful when the risk is triggered by random events. It's not meaningful against an intelligent enemy.

In the early days of commercial security, the enemy was usually lone "hackers". Today, it's organized crime and nation-states. Consider "spear-phishing", aimed at people in key positions, which appears to be how someone (China?) got the entire background check records of most Federal employees. That was statistically unlikely, but as an attack, was worth it.

Too much of computer security is based on defense against large numbers of nuisance attacks. Military thinking on defense starts from "what's the worst they can do to us". It's about capability, not intent. Military organizations have to be aware that kids throwing rocks at the perimeter fence is not the real security threat; it's somebody seemingly authorized getting inside and getting to the good stuff.

Re: Infosec's inability to quantify risk

#45
post #31

Earlier quoted context omitted.

every security hole should be treated as though the lives of every human on Earth depended on it What possible reason would lead you to do that?

Maybe the personalities of some security researchers? /s

yes, this is correct and what I alluded to.

Re: Infosec's inability to quantify risk

#46
post #44

"Quantifying risk" statistically is meaningful when the risk is triggered by random events. It's not meaningful against an intelligent enemy. In the early days of commercial security, the enemy was usually lone "hackers". Today, it's organized crime and nation-states. Consider "spear-phishing", aimed at people in key positions, which appears to be how someone (China?) got the entire background check records of most F…

You are 100% correct. One of the best explanations of this that I've heard recently was on this interview with Brian Snow on the security weekly podcast: http://wiki.securityweekly.com/wiki/index.php/Episode332

I think the discussion was in the second half of the podcast.

I deal with infosec people all of the time, and the devotion to risk models (with questionable calculations of risks) is usually annoying, and in many cases whitewashing real issues.

Re: Infosec's inability to quantify risk

#47
post #26

Earlier quoted context omitted.

> Who will be responsible for these deaths? There is not always a responsible party. What about the child that runs out into the road, and you have no chance to avoid them? Will you decry self-driving cars when this incident happens to them? Searching for "who is responsible" when the car is self-driving is self-defeating. When the car is driven by an algorithm, the algorithm can be improved. One death could prevent…

Curiously, back when cars first appeared, people did decry them for hitting children (and adults) even if they ran into the road. It was only after a wide campaign (which also created the term "Jaywalk") that car proponents got the public to reverse their opinion. From an episode of the great podcast 99% Invisible: Much of the public viewed the car as a death machine. One newspaper cartoon even compared the car to Mo…

It happened many years ago, but I'll never forget the time I was coming home from work, buzzing west along Foothill Blvd in the darkening evening, and I turned north toward my neighborhood. A small child jumped out from behind parked cars, directly into my path. I laid my bicycle down, the pedal and frame spraying gravel as I stepped off. She looked at me, not scared so much as lost in thought, and wandered on across the street. I smiled and picked my bike up.

It is no wonder that cars kill children, and always have. That child would have died if I had been driving.

Re: Infosec's inability to quantify risk

#48

  In hindsight, it's obvious to everyone that Valasek
  and Miller went too far. Renting a track for a few
  hours costs less than the plane ticket for the
  journalist to come out and visit them.
In a good world, this would be true. In the world we actually live in, we should remember that a different group of researchers did this in 2010 and 2011[0] and as far as I know, not a single automobile was recalled from the road over that. This time, over a million were.

Security researchers do irresponsible shit like this because too many organizations don't fix bugs when they're "disclosed responsibly". And no one cares about that. When an organization sits on a bug that was quietly reported, no one tells them they're being irresponsible or endangering anyone. It's only after someone does something "reckless" enough with a bug that change happens, and then we blame the people who did some particular reckless event, rather than the people who created a whole system of reckless neglect.

Don't get me wrong. I wish we lived in a world where security researchers didn't have to disable cars on a public highway to make a god damn point. But I don't blame them that we live in a world where that may well be the best avenue available to them to get dangerous flaws fixed.

[0] http://www.autosec.org/publications.html

Re: Infosec's inability to quantify risk

#49

> In hindsight, it's obvious to everyone that Valasek and Miller went too far. Not at all; they didn't create new risks, they just exposed existing risks. And the security community's reaction isn't their fault, either. And sometimes an industry needs a wakeup call to take a topic serious.

If doing something risky doesn't increase the risk of bad consequences happening, what does? Whether they "created new risks" seems beyond the point of the criticism - this isn't about exposing the flaw, it's about reproducing it in an unsafe way.

The thing is that on one hand it increased the risk of bad consequences to them, but on the other hand it indirectly reduced the risk of bad consequences happening to others.

Increasing the net effect on consequences is what matters.

Re: Infosec's inability to quantify risk

#50
post #14

This article is flawed. It seems to revolve around the fact that 'people commuting to work are more dangerous than 1 car stopping on the freeway'. The article then proceeds to explain why this is so: > 'No human is a perfect driver. Every time we get into our cars, instead of cycling or taking public transportation, we add risk to those around us.' > 'We often see cars on the side of the road. Few accidents are cause…

It is quite ironic that the article completely fails at risk analysis even from a perspective where an abundant amount of data is available. After some brief googling through top causes of accidents [1] most attributed deaths to speeding, drunk driving, or distracted driving.

It would be a fair attribution to say that the behavior of the vehicle as viewed from another drivers perspective was none of these situations as the driver was to at least some extent still in control of the car. While I do not know the exact model of the Jeep I'm assuming that there is a mechanical emergency brake still present.

Stopping in the middle of traffic is probably very low on the metric of causes of accidents or death. Although I did not accumulate enough data to give a metric on how much risk the researchers incurred through this experiment it may be beneficial for the author to at least do some due diligence in acquiring data before labeling an industry (one the author is well known in for that matter) as having an inability to quantify risk and then immediately fail to quantify risk.

[1] Pretty ironic that the author fails in his own analysis while talking about 'proper "risk analysis"'.

Post reply on HN