Skip to content

Comment on Stranded Jet Skier Breaches Multimillion Dollar Security System At JFK Airportparent

Comments

If a user on your website accidentally finds an exploit that could let him steal your user database but he didn't mean to and didn't do anything with it... do you a.) Say "well he wasn't a real threat, back to the TV" or b.) Prevent anyone else from getting in the same way?

I agree with the general hatred of security theatre, but given what it is they obviously had to be seen to fix the hole rather than just leave it wide open where any terrorist could get through it.

>If a user on your website accidentally finds an exploit that could let him steal your user database but he didn't mean to and didn't do anything with it... do you a.) Say "well he wasn't a real threat, back to the TV" or b.) Prevent anyone else from getting in the same way?

This line of logic is going the exact wrong way. In the case of a website, there are known exploiters out there stealing data and money continuously. If you have a hole it will be found and exploited with near 100% certainty. Further, fixing your hole doesn't hurt anyone and usually doesn't even inconvenience them.

Airport "security", on the other hand, is against a threat that never seems to materialize [1] and is massively inconvenient to everyone who uses the system. This sort of thing is just shadow chasing. "Oh noes! If terrorists could somehow weaponize rats, they would be able to utilize the sewer system! We better spend billions to lock down the sewers, ASAP!". This hole has been open for how long? And yet, no terrorist attacks. It's not worth investing the resources it would take to fill the hole because statistically there's no reason to believe it will ever be exploited by a terrorist.

[1] Relative to internet attacks, which are constant, terrorist attacks against the US are statistically non-existent. There are probably more cyber attacks on US websites in a single day than terrorist attacks committed on US soil in its entire history.

> This hole has been open for how long? And yet, no terrorist attacks.

Typically when a website is hacked it isn't because they opened up a vulnerability the day before, it too has been around a while before anyone malicious found it.

The rest of your argument is all about the general security theatre situation, where yes, I agree they are going over the top against very little threat. My point was that, given this policy, they had two choices here - either close the security hole ASAP, or say "to be honest, this whole security thing's a bit of a joke, let's all go home".

Or option 3: "we know we should've known a guy had made it onto the Tarmac before he made it all the way to the terminals. There's obviously something wrong there. But there's no need to worry about ze terrorists storming airport beach fronts, so heavily armed response is probably overkill. It'd be a little difficult to miss something like that."

flyinRyan's response was excellent and I refer to it out of agreement.

I'll add on top of his points:

- Online security presents a different threat model, in that your front door is immediately accessible to the entire world. Meatspace targets are inherently limited by geography and local access. Theoretical attacks on Internet infrastructure are far more likely to become actual attacks, once recognized, and automated patrolling for vulnerabilities is commonplace.

- By contrast, a massed, armed assault on any given piece of infrastructure requires planning, materiel, and forces. Outside of active combat / conflict regions (Iraq, Afghanistan, areas of the Middle East, Pakistan, India, and disrupted regions in Africa), the ability to effectively organize and marshal even a very small force (2-12 persons) has had a very low success rate. 9/11 was carried out by 20 persons, one of whom was intercepted (and several of whom were subject to surveillance and really should have been caught, see the Minnesota FBI offices investigations of Moussaoui). London's July 7, 2005 bombings were carried out by 4 individuals against a very soft target (52 deaths, ~700 casualties). The Madrid March 11, 2004 bombings, also against a soft target, (191 dead, 2050 injured) resulted in 29 arrests.

In the US an UK, since 9/11 (and excepting the 7/7 London attacks), there have been a smattering of incidents labeled "terrorist", of which most in the US were letter or pipe bomb, or single gunman mass shootings. Several plots (most consisting of 1-2 persons) were discovered and thwarted in early planning stages, presumably through communications surveillance. Several (the underwear bomber, two New York City car bombing attempts) reached execution but failed to succeed. And a few odd one-offs (small plane flown into a Texas office building).

In the UK, the bulk of incidents were domestic terrorism related to IRA splinter groups.

What you're proposing is a vast expenditure to address a potential, but in all evidence low-likelihood security hole, by a means that's much less effective than broader preemptive measures (comms intercepts, infiltration) or mitigating responses, while a target-rich environment full of far softer targets (other transport systems, schools, movie theaters, religious centers) which are being actively exploited remain.

It's a very, very poor resource allocation strategy.

It's also one that pits billions of dollars of response to thousands of terrorist planning, for no effective change in outcome.

They win.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.