back

by sans_souse·2y ago·view on hn ↗
At times it's a bit difficult to read, as it seems to be a telescript of a speech. But the overall gist and main topic are one that needs much more attention sooner rather than later/never.
1 comments
My colleagues and I submitted a similar talk/paper for a different NCSC conference (but weren't accepted). I see that this talk by Bert Hubert covers mostly the ground. so I am pleased, but worried about what this take misses out.

Hubert is addressing much of the ground that lies between security and resilience.

Our emphasis is on how mitigation lies in education and autonomous systems over regulation. Not that regulation is wrong, just that it doesn't work as a stick without a carrot. We also looked at timescales and how so much is already too late because of the lag-time from drafting to efficacy. And what I know from hanging out here on HN is that technologists appear hostile to regulation, but giant companies love it so long as they get to write the rules that give them more monopoly power.

Where we went wrong I think is lack of political tact. Hubert stops himself from even finishing off the remark about the quality of Microsoft products. But I don't think the real problem can be ignored for much longer. Instead, we went all-in and emphasised (as previously here [0]) that "Big Tech is the cybersecurity problem" (as Bruce Schniere recently echoed) because it pushes (in addition to highly centralised single points of failure) an irresilient "insecurity industry" that is based on protection not security.

Hubert's talk doesn't get to the key issue;

Security and protection are not the same thing.

Protection leads to dependency that ultimately erodes real security.

However "protection" is easy and profitable to sell. Real security is not.

That is ths succinct way in which it must be put.

If the intel appraisal is accurate and we are entering a serious war footing than we can have no more patience for the profitable but dangerous "insecurity industry" that gives an appearance and simulation of security, without the reality.

[0] https://techrights.org/o/2021/11/29/teaching-cybersecurity/

"Security" is not the same thing itself, it cleaves meaning:

1) Hypervigilance; which is unsustainable.

2) Carefree ease; which is what the champion Red Bull athlete achieves from constant practice and repetition.

I thank Kelly Shortridge (https://kellyshortridge.com/blog/posts/) for pointing out the cleavage.

These are interesting distinctions.

I'm working on distinguishing a whole cluster of things that frequently get collaopsed into the same mushy confusion;

security, safety, reliability, resilience, protection, sustainability...

And there's also inner and outer security, which I think your remark addresses.

Thanks for the link which I wasn't aware of.

@nonramdonstring: The email address hr@... in your profile is broken. You're welcome to try the one in my profile.
In spite of my typo in the parent, I really did send to hn@. I just checked the bounce to be sure.
Thankyou for telling me. I may have missed other coms, my apologies.