Skip to content

Comment on Cisco aids Ukraine defense with modified switches to counter Russian attacksparent

Comments

Those are the talking points of the people who got us into this mess who have been systemically incapable of deploying or even developing secure systems. There is no absolutely reason to listen to the liars who have repeatedly promised secure systems while being utterly incapable of doing so for literal decades. The task is not impossible, the commercial vendors like Cisco, Google, Microsoft, Amazon, Apple, etc. are just incompetent at security and are trying to poison the well by claiming that it is impossible just because they can not do it.

If you want to know what actual high security development looks like you can just look to Orange Book Level A1 certified systems and Common Criteria EAL 6/7 certified systems. Systems designed for high security with formal specifications, robust documentation, exhaustive testing, thorough review, spotless penetration testing by well-funded intelligence agencies, formal proofs of correctness, and proven deployment in high criticality settings. The Common Criteria SKPP literally required the NSA to fail a multi-month penetration test while having the full source code, internal documentation, and formal specification.

These commercial vendors believe protecting against state actors is literally impossible even though it has already been demonstrated in front of their faces for decades. Nothing they say about security is useful because they know nothing about what is needed to make systems that are actually secure.

High security development practices will, as you wisely say, go a very long way. That is not quite the same as some kind of zero-vulnerability "secure" system, however.

No system involving humans is, or ever can be, perfectly secure. At best you can make it uneconomic to attack the computerized parts of the system through networks. You've touched on a number of ways to do this, which are known and understood in the commercial world as both feasible and expensive. This is why Common Criteria has a spectrum of evaluation levels... and even EAL7 does not offer any kind of guarantee of zero vulnerabilities.

Meanwhile, adversaries can and will investigate if their goals can be achieved through human attacks or disruption. There's no need to devote extensive resources to breaking into a system if a carefully placed bomb can produce the same goal, after all.

As you say, this task is by no means impossible. How to go about it is well understood. It's merely very expensive.

Quibbling about how "perfectly secure" is impossible is a complete red herring. Yeah, using known techniques cryptography is not perfectly secure, it will just take billions of times longer than the age of universe and billions of times more energy than exists in the entire universe to break it. It is a distinction without meaning.

Making the computerized parts of a system go from 1 M$ to defeat to 10 G$ to defeat while employing human-error resistant design makes attacking the globally-addressable endpoint go from a cost of doing business to grossly uneconomical. It makes the cheapest, easiest, and most accessible way to attack into a nearly impossible wall and they have to look elsewhere to much less scalable vectors. You do not get the necessary 1,000,000% increase in security from 10% or even 100% improvements here or there. And you most certainly do not get it by listening to the people who are not even within a factor of 1,000x of knowing how to do it right.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.