Discussion about this post

User's avatar
Tom Welsh's avatar

Between about 1988 and 1993 (when I left DEC) I did a good deal of lecturing and consulting about software security. Also hardware and human security, as security is seamless and cannot be divided up without leaving gaping holes.

One thing that I always warned my audiences and clients about was that, given the state of security in general and the capabilities available to attackers, the most remarkable fact was that so little damage was being done. Even in 1985, anyone with the inclination and a little knowledge could have cut a swathe of destruction through any country's computing infrastructure. Government and military installations were no exception - indeed, some of them were exceptionally vulnerable. (Like the US government VAX computers whose "system" (root) credentials had been left for years as account "System" and password "Manager". (Should have been changed the moment the computer was powered up for the first time)).

Software has not become noticeably more secure since then, but it has become enormously more complicated. That suggests more attack possibilities. Hardware, which used to be considered pretty safe, has developed alarming vulnerabilities such as Spectre and Meltdown. There have even been reports that manufacturers like Intel have put undetectable hardware features into all their processors that could be used to break security.

It is a well-known rule that complexity always militates against security. Early experiments like the MULTICS operating system held out some hopes of establishing a relatively secure baseline, but all such ideas have now gone with the wind. Low cost and high performance have won the day; even when hiring programmers cheapness is a powerful consideration.

Since 1985 or earlier, the whole computing world has been building on sand. Virtually any software can be snatched away without warning, causing untold harm. Iranian officials say they would not stoop to such sabotage, and they may well be telling the truth. But they have the capability.

The Alarmist's avatar

As I wrote yesterday, given the US, Israel, and the EU/NATO via Ukraine were the aggressors, I would be hard pressed to fault the Iranians or Russians for taking the shot at vulnerabilities Western “leaders” knowingly left open before starting this rodeo. Expecting the Iranians and Russians to not take their shots or feigning outrage when they do exposes the naked calculation that the population of the Western countries could be used as human shields, or, worst yet, bait.

5 more comments...

No posts

Ready for more?