I can't think of a great solution to this problem.
I can't think of a great solution to this problem.
There's really only one "final solution" to the problem in the purely technical realm. That would be to make provable security (in the theorem-proving sense) a non-negotiable requirement to all digital logic (both hardware and software) running on networked devices. I don't know if there's even a workable definition that would rigorously describe the goal of such an effort.
... But I believe that if provable security was important enough to everyone (just like "winning the war" in the 1940s or "getting to the moon" in the 1960's), we might possibly achieve it -- at least below the OS syscall level in a few major OSs and in several important userland libraries.
However, that ignores the human element of security, which can't ever be completely solved via mere human effort. People will always be vulnerable to social engineering, for example.
High security MCUs go through great lengths to defeat sideband attacks on the package (some really neat stuff too like failing if exposed to die shaving).
There are secure bus initiatives but they don't extend to the BOM (bill of materials) for all the components.
On top of that, GUI techniques for obscuring physical input (keyboards, UI touches) are needed.
Given Apple's posturing and patch release cadence, I think/feel they are on the side of privacy. Android too. We're on the right track, I wonder if eventually tech will win the arms race for exploits like this? (The rubber hose exploit will always work...)
It does. I said all digital logic, which includes all the ICs, FPGAs, and silicon.
If something can be created to be provably secure, then it can be an argument for government legislating a back door.
"You said it's provably secure. Now you can give us provably secure access too without hurting your customer's privacy or security, because they're protected by the 4th amendment."
I don't think this can be solved by technology, I think this comes down to politics of freedom, if you get right down to it. And it looks like you're going to have to have that fight anyway.
So the best provable security could do would be to eliminate security holes like buffer overflow/etc. Trust issues (and even side-channel attacks) would still be present as always.
There are some low-level libraries that have already been partially converted to theorem-proved functions for the sake of security.
The mentioned government agencies have the "NOBUS" belief: that the concept of "NObody But US" (having access to the "keys to the secrets") works.
This article is just one of a many good examples that it doesn't.
What could work are just the systems which are secure without any exceptions. Which is hard to achieve when enough powerful influences (most often directly or indirectly tax funded, even if not explicitly government organizations) do all they can to make that not happening. It's then easier than it appears to be to achieve the goals of nobody having an access to a really secure system.
An example:
https://en.wikipedia.org/wiki/Dual_EC_DRBG
"In September 2013, The New York Times reported that internal NSA memos leaked by Edward Snowden indicated that the NSA had worked during the standardization process to eventually become the sole editor of the Dual_EC_DRBG standard,[7] and concluded that the Dual_EC_DRBG standard did indeed contain a backdoor for the NSA.[8] As response, NIST stated that "NIST would not deliberately weaken a cryptographic standard."[9] According to the New York Times story, the NSA spends $250 million per year to insert backdoors in software and hardware as part of the Bullrun program.[10]"
Hmm. Wait. Was that sarcasm?
provided, of course, that they agree.
But then again many physicists were also convinced Nazi officers.
If the Germans would have won the war, we'd probably celebrate those officers :/ All the torture and killing would be spun as "necessary evil" (if it even came to light), and further investigations would be blocked by the government. How we perceive the past is...complicated.
I don't expect much from a person that won a Noble piece prize then proceeded to drop 26,000 bombs in 2016 a bomb every 20 minutes.
https://www.theguardian.com/commentisfree/2017/jan/09/americ...