Interesting People mailing list archives

Re: NYT article on the (ever-more-sophitsticated) bot wars


From: David Farber <dave () farber net>
Date: Wed, 10 Dec 2008 09:15:49 -0500



Begin forwarded message:

From: "David P. Reed" <dpreed () reed com>
Date: December 10, 2008 8:46:34 AM EST
To: dave () farber net
Cc: ip <ip () v2 listbox com>, "Eugene H. Spafford" <spaf () mac com>
Subject: Re: [IP] Re: NYT article on the (ever-more-sophitsticated) bot wars

Dave - I'd like to ask Spaf, whose opinions on this subject are important, to amplify and to explain what he means in the following paragraphs:
It's unfortunate that (for "political" reasons) every report on the topic that bubbles up to high levels suggests that if only we coordinate enough and invest enough, we can patch the current steaming pile in some way.

No report points out that the people responsible have been told that this can't work but they continue with business as usual. No one reports that we continue to throw good money after bad by buying and deploying the same gunk that got us in this mess.

1. In particular, what is the "same gunk"? It's easy for me to imagine which things he means to be: "operating systems that offer services whose authentication and security models were never designed properly" (e.g. Windows File Sharing), and "security solutions that are based on assumptions about physical topology that are clearly false" (inside the firewall =no bad guys,. outside the firewall=bad guys), and finally, an unfortunate lack of attention to principles like the "principle of least privilege" in all systems.

2. I'm not sure who "the people responsible" are. Do you mean the Chief Executive Officers of corporations? The US government has no office in charge of citizen or corporate security. NSA is responsible for DoD security, as far as I can tell. And my local police department is responsible for holding criminals accountable to laws.

It would be a great contribution to society were Spaf and others to write down a plan that would help Americans feel safe against intrusions into their lives that are unwanted and unwelcome.





-------------------------------------------
Archives: https://www.listbox.com/member/archive/247/=now
RSS Feed: https://www.listbox.com/member/archive/rss/247/
Powered by Listbox: http://www.listbox.com


Current thread: