Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem is that there are a lot of us trying to get people to take these "completely unlikely" attack vectors seriously. It's like talking to a dog or a wall. Too many humans are hardwired to respond only when confronted with an actual situation. We get frustrated because our "in theory it works..." attacks work in reality eventually and then the rest of the world is all "oh who could have predicted that ____".

We did. We, the people you called "paranoid" while we quietly try to fix things. We're the ones trying to make sure that people don't die when cyber vulnerabilities are exploited by shitty actors.



I've encountered this, with great unhappiness.

I have a theory that this heavily relates to the feedback loops and signals in play. New features are positively observable and their impact is observable from release onwards.

When defending against unknown unknowns, security is unobservable. It's observable only in its absence. All that's left are heuristics and synthetic signals like pentesting.

I wrote a multi-thousand word essay on the topic, but for an internal audience. I don't know if I could properly share it.


Yes, that's exactly right and why it's hard to sell "security" and how we get to an voluminous x86 ISA.

My own speculation is that we got here in this industry though a complete absence of liability. Bugs are not a big deal, they are _expected_ now.

The only counter example I know of is Knuth's bug reward system.


Please do share if you can, I've been thinking a lot about this topic in context of ops / "janitorial" work in general.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: