Remix.run Logo
curuinor 3 days ago

Near the beginning of my career, I talked to a greybeard who harrumphed at me discussing something-or-other and said "computer security is an oxymoron". I thought he was being too pessimistic, nowadays I realize he was right.

wat10000 3 days ago | parent | next [-]

That's too pessimistic. But it is a spectrum. You can't guarantee 100% success against 100% of potential attackers, but it still matters how easy it is to get into something. There's a pretty big difference between a Windows 95 machine hooked directly to the internet and something like a fully up-to-date iPhone. The iPhone is still hackable, but in practice it's so difficult that you're unlikely to be targeted unless you get the attention of a national government.

It also requires actually caring about security and putting effort into it. These data breaches are usually systems where little attention was paid to security in the first place, and e.g. getting ahold of one user's password is enough to lose the game. Getting companies to care about security is really hard, but it does happen.

mitxela 2 days ago | parent | prev | next [-]

If he's grey enough, he might have predated effective cryptography.

UltraSane 3 days ago | parent | prev | next [-]

Real computer security IS possible but takes a lot of effort by very skilled and dedicated people. You don't hear about bank mainframes getting hacked often.

cmiles74 3 days ago | parent | next [-]

Skilled and dedicated people and an organization dedicated to maintaining a consistent level of security. Maintaining both of these long term seems to be the challenge for many companies.

FLeXMurphy 3 days ago | parent | prev | next [-]

> You don't hear about bank mainframes getting hacked often.

Who do you think employs the top-level criminals?

pyrale 3 days ago | parent [-]

Sure, but not in the IT service.

cogman10 3 days ago | parent | prev [-]

It makes systems harder to work with and new features slower to deploy and it requires you to make sure you stay on top of CVEs.

That's overhead that businesses really hate paying as it's diverts software devs away from making new features.

radarsat1 3 days ago | parent [-]

Software companies sure hate paying for the realities of developing and maintaining software. Sigh.

john_strinlai 3 days ago | parent | prev | next [-]

it's silly to think about computer security as binary secure/insecure.

deadbabe 3 days ago | parent [-]

If it’s not secure, by definition it’s insecure.

john_strinlai 3 days ago | parent [-]

there is no perfectly secure system and defining everything as insecure is useless.

outside of english class "secure" is relative and context-dependent, not binary.

drdaeman 3 days ago | parent | prev [-]

Human security. Computers are fine, they usually do exactly as they’re programmed.

curuinor 3 days ago | parent [-]

We don't care about the computers, humans are what society is for

drdaeman 3 days ago | parent | next [-]

Yes, of course.

My point was that computers are as secure as human(s) who programmed them were careful and competent. Computer security is ultimately human knowledge and reasoning competence (plus time/money tradeoffs, if made willingly)

iAMkenough 3 days ago | parent | prev [-]

getting the idea lately that society hates humans

keybrd-intrrpt 3 days ago | parent [-]

Caring for humans hurts profits