Live data from Hacker News

Infosec's inability to quantify risk

blog.erratasec.com

51–54 of 54 posts

Re: Infosec's inability to quantify risk

#51
post #9

This is something I'm struggling with as I attempt to educate myself more about security. I was a bit disappointed he went on to talk about the risk of a stunt , because there is virtually no quantifications of risks in anything I've read on the results of security research. This seems to be borne out by the arguments about, say, the speed of disclosure vs patching. There is no agreement, and seemingly no desire to q…

"because there is virtually no quantifications of risks in anything I've read on the results of security research"

Nearly all results of security research are given at least some metric for risk quantification. https://cve.mitre.org is a single example of an attempt to quantify risk. I'm assuming at least at some point you have run across these numbers so the statement is patently false or a complete exaggeration.

Re: Infosec's inability to quantify risk

#52
post #51
post #9

This is something I'm struggling with as I attempt to educate myself more about security. I was a bit disappointed he went on to talk about the risk of a stunt , because there is virtually no quantifications of risks in anything I've read on the results of security research. This seems to be borne out by the arguments about, say, the speed of disclosure vs patching. There is no agreement, and seemingly no desire to q…

"because there is virtually no quantifications of risks in anything I've read on the results of security research" Nearly all results of security research are given at least some metric for risk quantification. https://cve.mitre.org is a single example of an attempt to quantify risk. I'm assuming at least at some point you have run across these numbers so the statement is patently false or a complete exaggeration.

> so the statement is patently false or a complete exaggeration.

Oh, don't misunderstand me, it could very well be either. I'm not claiming to have discovered this based on extensive knowledge.

Thanks for the link. So the CVSS metric is the one you're referring to? I've not seen that mentioned in vulnerability reports, no. Once again, more than happy to admit this is my failure or lack of diligence to notice. But when I've asked before about quantification, I've typically only got variants of 'you must take all vulnerabilities totally seriously, because the bad guys are powerful and evil.'

Re: Infosec's inability to quantify risk

#53
post #52
post #51

Earlier quoted context omitted.

"because there is virtually no quantifications of risks in anything I've read on the results of security research" Nearly all results of security research are given at least some metric for risk quantification. https://cve.mitre.org is a single example of an attempt to quantify risk. I'm assuming at least at some point you have run across these numbers so the statement is patently false or a complete exaggeration.

> so the statement is patently false or a complete exaggeration. Oh, don't misunderstand me, it could very well be either. I'm not claiming to have discovered this based on extensive knowledge. Thanks for the link. So the CVSS metric is the one you're referring to? I've not seen that mentioned in vulnerability reports, no. Once again, more than happy to admit this is my failure or lack of diligence to notice. But whe…

> But when I've asked before about quantification, I've typically only got variants of 'you must take all vulnerabilities totally seriously, because the bad guys are powerful and evil.'

The CVE system is something used (mostly) by professionals who deal with the security/usability/performance/cost/etc tradeoff every day. It makes sense that they do quantify risk. You see this all the time when MS/Google/Apple etc decide whether to patch an issue or not.

Random security "experts" on internet forums are not like that. Many are amateurs with an interest in the topic but they don't work on any major products and so have never had to be faced directly with those other costs. So of course they assume that security is the be all and end all, and nothing else is more important. But you get that in every walk of life. Ditto with cryptographers and privacy.

Re: Infosec's inability to quantify risk

#54

Author equates the risk of one person operating a single vehicle that sometimes loses power to the risk incurred when a whole fleet of cars could be subverted by somebody buying a few hundred dollars worth of hardware and tinkering for a bit.

No, OP is equating it to the trial the researchers did with a single vehicle.

doh, you're right:

> In college, I owned a poorly maintained VW bug that would occasionally lose power on the freeway, such as from an electrical connection falling off from vibration. I caused more risk by not maintaining my car than these security researchers did.

that's what I get for reading and replying on mobile.

Post reply on HN