Between about 1988 and 1993 (when I left DEC) I did a good deal of lecturing and consulting about software security. Also hardware and human security, as security is seamless and cannot be divided up without leaving gaping holes.
One thing that I always warned my audiences and clients about was that, given the state of security in general and the capabilities available to attackers, the most remarkable fact was that so little damage was being done. Even in 1985, anyone with the inclination and a little knowledge could have cut a swathe of destruction through any country's computing infrastructure. Government and military installations were no exception - indeed, some of them were exceptionally vulnerable. (Like the US government VAX computers whose "system" (root) credentials had been left for years as account "System" and password "Manager". (Should have been changed the moment the computer was powered up for the first time)).
Software has not become noticeably more secure since then, but it has become enormously more complicated. That suggests more attack possibilities. Hardware, which used to be considered pretty safe, has developed alarming vulnerabilities such as Spectre and Meltdown. There have even been reports that manufacturers like Intel have put undetectable hardware features into all their processors that could be used to break security.
It is a well-known rule that complexity always militates against security. Early experiments like the MULTICS operating system held out some hopes of establishing a relatively secure baseline, but all such ideas have now gone with the wind. Low cost and high performance have won the day; even when hiring programmers cheapness is a powerful consideration.
Since 1985 or earlier, the whole computing world has been building on sand. Virtually any software can be snatched away without warning, causing untold harm. Iranian officials say they would not stoop to such sabotage, and they may well be telling the truth. But they have the capability.
As I wrote yesterday, given the US, Israel, and the EU/NATO via Ukraine were the aggressors, I would be hard pressed to fault the Iranians or Russians for taking the shot at vulnerabilities Western “leaders” knowingly left open before starting this rodeo. Expecting the Iranians and Russians to not take their shots or feigning outrage when they do exposes the naked calculation that the population of the Western countries could be used as human shields, or, worst yet, bait.
Thank you Rosemary. In nearby Chiba, 20,000+ homes lost power. There is widespread flooding. . My roof -balcony is a little swimming pool. In all my time in Japan, I have never seen a summer like this! But problems seem to be worldwide.
Thanks. I'd add that Russian/Iranian weapon systems are also VERY precise and since their guidance software works well, they hit the military infrastructure intended. Many of the casualties in Ukraine seem to be from the Ukrainian defense bits and pieces falling out of the sky.
I've been reading Alastair Crooke, a good bloke to follow, Resistance, the essence of the Islamist revolution. I like Islam more and more - I don't include the Saudi sort mind.
I set up West Asian networks for Toyota so I have worked with Muslims from all sorts of places - -Sufi, Sunni, Shi'a. And also Palestinians. I have also studied the Qu'ran --again (I read it when I was in High School). The people I work with are not just colleagues - they are friends. That does not mean that I always agree with present-day interpretations of the Qu'ran, visions received in a certain cultural context. Present day Islam is a bit like Christianity --it is institutional. Jesus had a Message. The message was more important than culturally bound institution. The Prophet spoke Angels, who delivered a Message also.
Between about 1988 and 1993 (when I left DEC) I did a good deal of lecturing and consulting about software security. Also hardware and human security, as security is seamless and cannot be divided up without leaving gaping holes.
One thing that I always warned my audiences and clients about was that, given the state of security in general and the capabilities available to attackers, the most remarkable fact was that so little damage was being done. Even in 1985, anyone with the inclination and a little knowledge could have cut a swathe of destruction through any country's computing infrastructure. Government and military installations were no exception - indeed, some of them were exceptionally vulnerable. (Like the US government VAX computers whose "system" (root) credentials had been left for years as account "System" and password "Manager". (Should have been changed the moment the computer was powered up for the first time)).
Software has not become noticeably more secure since then, but it has become enormously more complicated. That suggests more attack possibilities. Hardware, which used to be considered pretty safe, has developed alarming vulnerabilities such as Spectre and Meltdown. There have even been reports that manufacturers like Intel have put undetectable hardware features into all their processors that could be used to break security.
It is a well-known rule that complexity always militates against security. Early experiments like the MULTICS operating system held out some hopes of establishing a relatively secure baseline, but all such ideas have now gone with the wind. Low cost and high performance have won the day; even when hiring programmers cheapness is a powerful consideration.
Since 1985 or earlier, the whole computing world has been building on sand. Virtually any software can be snatched away without warning, causing untold harm. Iranian officials say they would not stoop to such sabotage, and they may well be telling the truth. But they have the capability.
They certainly have the capability.
Have you seen the meme that 1980s cyber security was the lock on the floppy disk holder?
As I wrote yesterday, given the US, Israel, and the EU/NATO via Ukraine were the aggressors, I would be hard pressed to fault the Iranians or Russians for taking the shot at vulnerabilities Western “leaders” knowingly left open before starting this rodeo. Expecting the Iranians and Russians to not take their shots or feigning outrage when they do exposes the naked calculation that the population of the Western countries could be used as human shields, or, worst yet, bait.
Amen, Julian!
Just following up on your comment yesterday. I realized that my previous article was not clear enough.
PS Hope all is well in Japan - earthquakes, heatwaves, economy and so on look pretty awful.
Thank you Rosemary. In nearby Chiba, 20,000+ homes lost power. There is widespread flooding. . My roof -balcony is a little swimming pool. In all my time in Japan, I have never seen a summer like this! But problems seem to be worldwide.
Thanks. I'd add that Russian/Iranian weapon systems are also VERY precise and since their guidance software works well, they hit the military infrastructure intended. Many of the casualties in Ukraine seem to be from the Ukrainian defense bits and pieces falling out of the sky.
I've been reading Alastair Crooke, a good bloke to follow, Resistance, the essence of the Islamist revolution. I like Islam more and more - I don't include the Saudi sort mind.
I set up West Asian networks for Toyota so I have worked with Muslims from all sorts of places - -Sufi, Sunni, Shi'a. And also Palestinians. I have also studied the Qu'ran --again (I read it when I was in High School). The people I work with are not just colleagues - they are friends. That does not mean that I always agree with present-day interpretations of the Qu'ran, visions received in a certain cultural context. Present day Islam is a bit like Christianity --it is institutional. Jesus had a Message. The message was more important than culturally bound institution. The Prophet spoke Angels, who delivered a Message also.
👍👍👍