The World Is Getting Hacked. Why Don’t We Do More to Stop It?
nytimes.com
nytimes.com
Users have been fooled: Turn it off and on, is a reasonable and well-known troubleshooting guide, but nobody blames the software vendor. If I'm on the phone with a company and they tell me to turn it off and on, I can't even point out "so you sent me something defective?" this is normal folks.
Maybe we need to teach programming younger and younger -- and it'll take two or three generations to become common enough that management will actually understand what I'm doing. Or maybe we need awareness campaigns to keep users from putting up with shit experiences!
Or maybe someone has some other idea, but the major barrier exists: We don't know how to program computers, and saying that out loud makes a lot of people with the job-title (or description) of programmer clam right up.
Large systems are extremely complex but even so we have process, tools and methods to build reliable, verifiable and bug free code. What is stopping us from using them for every piece of software is the cost.
Consumers are happy with the status quo of quality/cost.
Consumers cannot understand the cost because they are not programmers.
I don't understand the rest of your post. I'm not making an analogy to any psychical [sic?] items, physical items, or any other kinds of items.
1. Software currently has a lot shorter life expectancy than physical items, due to how fast ecosystem changes (bitrot). SaaS model shortens that even further.
2. In fact, as a consumer, I'd expect a car to last a lifetime, if properly maintained. That I can't is a testament to throwaway economy we've created.
That maintenance is not free, in terms of both money and time. Anecdote time: the most maintainable vehicle I had the displeasure to own required a yearly investment of several dozen hours to grease the multitude of bearings via zerks located all throughout the chassis. The seats wore out, the heating system sprung a leak, consumables were consumed... all were fixable, but only when given an appropriate application of money and time.
Sure, that truck is still running to this day, but very rarely used - because it's simply 2-3x less fuel efficient than a newer (but still 5 years old) vehicle, and the cost-benefit ratio of maintaining it is far too high.
How much money are we willing to put into the maintenance of software? Reading through the comments of this thread - very little. If we were interested in paying, you can be fairly sure there would be a player in the industry willing to make those fixes for an appropriately large amount of money - commensurate with the time and effort required to understand and fix a 45M line codebase.
But the root of the problem is, that computer security still does not get the proper awareness and attention. This starts from how we write software, but from a society point of view, mostly how we deal with computer systems. Computer systems are not toasters which you can replace easily. Often they are part of larger installations, difficult to replace as a component. We need to deal with them as with aspects of traffic or workplace safety, or hygiene. There should be a clear concept (I sincerely hope we don't require too strict state regulations) that like any professional tool, a computer system has to be reviewed in regular intervals for being fit for its intended purpose, and maintenance for security should be done as naturally, as mechanical or electrical checks.
So, for any computer-powered (and networked) device, this would mean, that either there is a maintenance contract in place, which in the end would mean, the provider has a contract with Microsoft, if Windows is used, or, like with any other device, the machine is no longer considered fit for professional use.
> The money they made from these customers hasn’t expired; neither has their responsibility to fix defects.
This is wrong. We don't ask for mandatory lifetime guarantees in any other industry I'm aware of, and perhaps more importantly, much of what is done in the field wouldn't be possible if it did (could you imagine having to continue to maintain an IE5 webpage for another twenty years?).
It goes on:
> In its defense, Microsoft probably could point out that its operating systems have come a long way in security since Windows XP, and it has spent a lot of money updating old software, even above industry norms. However, industry norms are lousy to horrible, and it is reasonable to expect a company with a dominant market position, that made so much money selling software that runs critical infrastructure, to do more.
If I buy a toaster it comes with a one year warranty, maybe. A nice car might come with a five year or two hundred thousand mile limited warranty. Microsoft sold a product at a fraction of that cost and supported it, unconditionally, for 8 years. 8. And they supported it for five more after that with appropriate arrangements with enterprises (and after a select few enterprises who somehow concluded that paying some engineering salaries at Microsoft for dedicated support was cheaper than upgrading). That's a 13+ year lifetime of support on what was an $80 a license product. Industry norms can only be "horrible" insofar as there's only been a serious industry for 30 years... And XP was supported for half of it (man, I suddenly feel old). My point is that there is no world in which the "cash-strapped National Health Service" is not the primary entity which was grossly negligent in its maintenance of critical infrastructure.
Stepping back and looking at the article as a whole and less at specific inflammatory parts, it is, well, filled with inflammatory parts. It starts as a thin attack piece on Microsoft for being slow to provide free support for a 16 year old product, offhandedly references IoT for some added scare factor, then starts calling for action (from both corporate and government actors) without any serious discussion on either the merits of the proposed actions or the impacts taking them would have on those organizations or the implications that they would create for future actors.
But hey, if you're a fan of Bruce Schneier's more recent musings, at least you'll enjoy the conclusion: That we must legislate software, and fast.
The analogy falls down when you consider it's possible to fix your own toaster or car, or take it to some other engineer to do it. Cars last longer than 13 years due to servicing at garages and things like that.
I agree that the implementation at the NHS is clearly awful, but it's crazy that staying on top of security means you're essentially forced to pay Microsoft more for a newer version of Windows (as well as retraining due to changes, retesting all your software). It's a mess of a situation and I don't know the solution, but continuing your analogy Microsoft should share the Windows source when they no longer support it so that third-parties can. I know that's never going to happen btw, just that's what's reasonable by your analogy.
There's clearly a need for this sort of support so it makes senses. Either that, or Windows should stop being overhauled every few years, making upgrades too costly to implement, and just focus on security and bug fixes. That's obviously not going to happen though.
If a company wants to stop supporting software, they have to publish the entire source, documentation, and guides for how to work in it.
So that others can then fix it.
I can fix a toaster.
I can’t fix a smart toaster with DRM.
What guarantee used to mean is that if product has manufacturing defects then these will appear within limited period of time.
Having a 5 year guarantee for a car does not mean that it will fall apart after this period of time. It means that defects that occur after this period of time are due to wear and not manufacturing defects.
The main difference between a software product and say a car is that it appears that manufacturing defects of the software would take much longer to appear than 2 or 5 years. Sometimes it may take even 10-20 years for a defect to appear.
The main issue with Microsoft software is that the problem, when it becomes apparent, can not be fixed by the owner as it could be with any other product. This is caused by the closed nature of the Microsoft software.
Another thing you get wrong is that you call XP a $80 product. It is not. It is a $80 x number of owners product.
I think this is nice in theory, but impractical with our current level of technology. If your toaster broke, would you be able to fix it? How many owners have the analog circuit knowledge to fix even a toaster from the pre-IC world? Would you be willing to invest the tens of hours and dollars required to fix it? Or would you just go buy a new one for $20?
Aside from people who train to do so, even your above-average owner can not maintain or repair a modern car drivetrain. Or an IC which has, thorough the laws of physics, formed whiskers that have caused it to short out. Most people couldn't even replace such an IC, even if given all the fairly specialized tools.
Nor could they realistically learn enough about programming to realistically find and repair defects in a 45 million LOC codebase.
Hell, as a (as called by peers in the past) above-average programmer, I couldn't grok 45M lines of code in anything resembling a reasonable timeframe.
Just opening the source is not enough. And just as car maintenance costs money (sometimes more than the car cost originally), if you want software patches past a reasonable span of time, those are going to cost money.
Security of a object is a thing you can only evaluate the day it turns around and snaps at you.
Now the default american solution for this, would be to have a "Late-Adopter" plugin, allowing to install "Additional" Gated-Comunity-Security for the rich - and let the mob become one huge botnet, held back by aggressive campaigns of bricking whole device classes remote should they be a threat to the "devices" in the better neighbourhoods.
Unfortunatly the rest of the world is either too poor or unwilling to follow this model, which means we are going to see a regulated, securty TÜV checked model in europe and japan, state regulated devices in china & russia - and a wild west everywhere else.
The world has been getting hacked since before 2013 by the NSA and related parties. They wanted to keep it hackable (by them, but an open door is open for everyone), not to fix what was wrong (even they asked/forced companies to include backdoors, unsafe encryption and so on). They developed (directly, or hired third party companies) software to hack it even more, and not just systems but people too. They created an entire market of malware/exploit/zero days, where was pretty profitable to find zero days and sell/hoard them instead of warning the world.
Is not amazing that in this scenario of planned/designed insecurity at every level even they get hacked/intruded/disclosed, and not just not to get information but the software weapons they were already using too.
Is like the department of health has been developing all the latest years new flu strains, are weaponizing them, and somewhat, you get sick, they get sick, everybody else get sick and some of the people you know dies. Would you complain about the last person that transmitted you the disease, the vaccine makers that run behind the (designed) diseases and even are forbidden/delayed to make a cure for them, or the root cause of it all?
Instead of asking why we don't do more to stop it, ask yourself why we did (and keep doing) so much to make it happen.
Until people start losing personal money they won't bother educating themselves. They see these "hacking games" as, well, games.
Take for example, the Fappening. This was possible because iCloud. iCloud is only necessary - like Dropbox and other services like it - because OS vendors decided they didn't want people to have control over their content, using their local computers - that it was 'easier' to provide servers dedicated to the purpose, than to actually add dedicated file sharing to the individuals' computers.
(There are no really good reasons why your modern PC can't serve its own content - especially in this era of bandwidth and monster CPU power. We hosted the 90's Internet on far less powerful computers than your average mobile phone, with less bandwidth too.. the point is, the protocols.)
So I honestly think that OS vendors need to be forced back behind the wheel to make our computers better, and the "network is the computer" business model needs to die. This was always a terrible idea, formed on the basis of an accountants wet dream, and should be forgotten as soon as possible. Instead, lets build better computers, simple as that. Computers that are actually safe to use because they've been designed that way, from the get-go. The cloud must die.
i.e. IPFS, Akasha, Ethereum, etc. These need to become first-class services in a default OS install. Then, maybe, we'll start evolving again ..
Anyway money equation I think is quite simple :
Why buy Windows, when you can use Linux and buy backup infrastructure.
And no UEFI Windows Partition driver BS, either! Get with the old times, people, before needing Ring 5+ mitigation, when people would actually FIX THEIR HARDWARE.
Having proper multiuser envrionment is already a huge security win.
The only thing that Linux has is free as beer. Many people don't want to spend money on buying new Windows and Windows XP works for them just fine. Linux could certainly help here.
There need to be a meaningful distinction between a software update for a product and a new product. For a operative system, hardware requirement and driver support is quite critical.
As a small testament to this, I had a server which hardware initial had 3.0 Woody as the version and ran until 6.0 Squeeze, at which point the motherboard gave up.
- The value of Linux is the very thin cost of update (OS and applications).
- 1t the cultural level, *nix users are much more tempted to find solutions rather than keep dangerous attack surface running.
- Linux runs on old hardware easier, kernel supports old arch, user space is less demanding and doesn't tie you with graphical hardware capabilities for the sake of market share. Linux Mint XFCE is my go to graphical distro for anything even from the XP days (it's butter smooth on a LV 1st gen core + 512MB)
It all started with poor ethics. Every single version of Microsoft Windows have intentionally left backdoors for NSA and some hackers knew how to use it. This is like you pay some money and buy a house, but the previous owner keeps backup keys to watch you. And some others get the backup keys, kick you out of your own home unless you pay them.
This is such a shame for Microsoft, NSA and American government. People trusted Microsoft products and purchased them, in return, Microsoft wanted more than money; they wanted to spy them for their ideological goals.
Is there any proof of this?
However, NSA is strongly suspected of (known to?) having backdoored the Dual_EC_DRBG pseudorandom generator by inserting into the standard numeric parameters which allow cracking by those who generated them (i.e. the NSA).
https://en.wikipedia.org/wiki/Dual_EC_DRBG
This algorithm ended up in certain Juniper firewalls and a year ago turned out to have been covertly re-backdoored by unknown actors who replaced NSA's parameters with their own.
https://rpw.sh/blog/2015/12/21/the-backdoored-backdoor/
There was also another low-tech backdoor in these routers, again not clear who did it.
Snowden documents show that they have a budget allocated to the backdooring of cryptographic standards and products:
http://www.nytimes.com/interactive/2013/09/05/us/documents-r...
Anyone who wants to surf can easily do so on their personal smartphone with no risk to corporate systems. No one has ever been able to put together a coherent rebuttal to my proposal, yet still the PCs remain connected and still people click things they shouldn't...
I've always considered SO to be more a sign of devolution than anything else. It hasn't produced better programmers - just more programmers. Is that better?
Sure I remember having lots of fun with Turbo Pascal and paper books, as well as Perl and `man perlre`, but nevertheless there is always one weird error that will cost you half a day of debugging, which nowadays is replaced with 5 minutes googling.
SO community are doing fine job with preventing bad code left without the warnings, but anyway I think SO delivered more to programming than it actually took.