Sure seems like a 1000:1 problem to me.
Sure seems like a 1000:1 problem to me.
Seismic, Infrared, Radar, and other monitoring systems could be deployed and ALL land crossings would be known soon enough to stop anyone crossing. Of course, a shoot on sight order is the part nobody has the stomach for, nor should they, we're not at war.
Naval patrols could greatly curtail routing around the ends.
Capability based security could greatly curtail the leverage you get from access to a given computer. The current default access systems we're using everywhere are about as effective as building a fortress out of crates of C-4 explosive.
Assuming you are referring to the United States, even if you deployed all of those sensors at all crossings, it would not be sufficient to deter crossings; those only provide detective capabilities. Yes, you would radically increase the number of people guarding the border, but that would also require a radical investment in enforcement, and such an investment would bankrupt the country for no real practical effect. Even if you did fund and build it, the maintenance costs of preserving the effectiveness of such a land border along the northern border with Canada means protecting a nearly 9,000 km border that about 200 km from the West Coast turns into extremely inhospitable to hostile terrain and climate for a minimum of three to four months out of the year. This terrain is absolutely awful to stalk and patrol in, but is a pleasure to sneak through (at least I really enjoyed it back in my hunting and military training days :D)
It is not feasible to scale the navy to the point where it would be practical to prevent access to the continental United States, for example, let alone the island territories. Attempting to do so would bankrupt the nation. Hell, modern technology can't even reliably prevent folks from bobbing over from Cuba despite the relatively small attack surface there.
Even if you managed to invest more than the current percentage of GDP (which is already ridiculous), you would also have to confront an increasingly hostile domestic population who is used to freedom of movement, is already paying punishingly high taxes in contrast to the value and benefit they receive for them, and rapidly diminishing quality of life.
Good luck with that!
Oh, and one last note about capability based security - it works great in lab and somewhat small environments, but I would appreciate a practical explanation of how you would scale up capability based security to an environments operating in 87 distinct countries (with disparate regulatory requirements that preclude centralized management), 3600 offices, and 800,000 employees, with approximately one third of those employees having employer managed devices, notebooks, and managing a total of 2,300 distinct software applications (granted it's been about 14 years since I worked in that environment, but that company has grown substantially since then).
I'm listening for a real, practical suggestion here, not being facetious.
That said, I don't envision shoot on sight orders or the use of SM-70 directional mines on the American border. What I find particularly interesting is the complete reversal of positions from years ago. CSPAN has a video of Dianne Feinstein talking about border security with AG Janet Reno, and you could swear they were talking points cribbed from a Trump strategy session.
Increased immigration tends to lower wages which favors employers. OTOH, protectionist immigration policies tend to keep the status quo especially for low-skilled labor, whom you would think the DNC is pledged to protect. It's just interesting to see how political fashions have switched. Is it the fear of terrorists crossing the border or..?
It hasn’t reversed, though the right-wing bipartisan consensus on the issue of the early 1990s has gone.
> Increased immigration tends to lower wages which favors employers.
Immigration mostly increases and decreases by economic conditions (at home and abroad). Immigration policy mostly influences the proportion of immigrants with legal status. More immigrants with legal immigration status means immigrants are less likely to be in fear of asserting things like labor rights, whereas more without legal status means more fear of things like that.
> It’s just interesting to see how political fashions have switched.
They haven’t switched, at least not in well over a generation. Republicans have been for narrower legal immigration policies for decades (the backward-reaching amnesty under Reagan was a component of tighter forward policies). There was a brief period of general bipartisan consensus on the direction of change (though still distance on the details), but no reversal.
If one wanted to control wages, one would want to ensure the unskilled labor supply was somewhat limited. Otherwise an employer can drive down to minimum wage rather easily.
One might do that by better securing the borders. I'm purposely leaving out the antiterrorist wish of at least getting some idea of who's coming in and out of Disneyland so to speak.
The fascist client state that collapsed due to an increasingly hostile domestic population who were angered by the growing economic challenges, and were tired of the continued state violence?
The same German Democratic Republic that has been consigned to the historical scrap heap of failed totalitarian regimes?
One might even consider holding North Korea up as a current example, since they have outlasted the GDR by 31 years so far, but they are also a client state, and their economy has been in relatively steady decline. The only thing keeping North Korea a functioning country is military and economic support from China, with even Russia's central bank continuing to push back against further economic development with North Korea.
However, if adequate security is actually important, such as when lives are at stake, these methodologies completely fail to fulfill such requirements. This is not merely the case when tackling the hard problem of large scale systems, where it might be forgiven to be unable to solve the hardest problem available, it is the case at every scale. At least capability-based systems have demonstrated adequate security at a usable scale, the prevailing techniques can not even do that. There is little reason to believe that abject failure at scale and an inability to solve any interesting sub-problem or smaller scale problem is a better way to success at scale than attempting to scale small successes.
I can't say which organization it was, or when it was, because I maintain enough of a public profile that it could leak specific information, but while doing a security consulting gig for a major global financial organization between 2001 and 2011, the team I was working with identified numerous serious concerns. The client company agreed that they were real risks, and even likely risks, but the financial impact, even if those risks were realized multiple times, were far below their documented thresholds for risk tolerance. In other words, the individual risks would have had to exceed $10M in impact per year, for multiple years before the financial impact of those issues would justify the massive cost of investment to remediate the risks. It's not that they didn't take them seriously, but the cost of the new system in development, which included addressing those risks, was so high that starting separate remediation efforts that would detract from those in progress changes introduced risk of the main replacement project failing. It was easier and lower risk and lower cost to just accept the impact of fraud, including compensating victims, than to try to fix it.
Whether or not those "self-insuring" risk tolerance figures are public are a different matter.
I do agree on the value and efficacy of capability-based systems, however the cost and effort to deploy and manage them, even in life critical environments, is so high that they are only practically effective in centrally planned environments where the funding for systems security is strongly decoupled from how that funding is acquired. In other words, capability based systems are, and will only be effective, at scale, in environments such as government (and even then, only military) or publicly funded, single payer, centrally managed health care systems (which don't really actually exist - most public funded healthcare in the world is centrally and publicly funded, but delivered by private service providers who bill the public funder).
It's an effective model where the cost of reliably deploying and managing capability based security can be externalized from the line of business that requires that level of security.
Most of the advantage of having a capability system is that it allows users to more transparently control what resources are given to a program at runtime. Instead of trusting the application to go pick a file and do something, the OS relies on a PowerBox UI to allow the user to directly pick files.
The closest analogy is that of a wallet (or purse) with currency in it. You chose directly which money you wish to use in a transaction, and that's the most you can lose if you make a mistake. There's no equivalent in Linux, Mac, Windows, etc... you're forced into a situation where you had your wallet to code, and hope for the best.
Users aren't the great weakness we've grown to think of them as, they just have insanely crippled tools.
That said, I don't think any sane person would favor using things like SM-70 directional mines to secure the American border. We can make a dent on illegal labor and more importantly get some idea of who these people are without resorting to the tactics of the DDR.
- The response can't have a blast radius
- Human software systems can't be formally verified in a tractable amount of time
- etc.
I'd go as far as to wager that if it weren't for MAD, the US might be sending SEAL or Special Forces teams in to deal with hackers.
When we have an AGI, perhaps it will develop systems impervious to intrusion. Or maybe it'll take the simpler approach and eradicate all humans and other capable AI actors.
This is expensive because it's guerrilla warfare.
Do you have a source on this? Sounds like an interesting read
That sounds like wet dream of a genocidal maniac. There is no way this claim is credible
And no I don’t think it was likely, but there’s only so many time in history senior military people have referred to nuking something in a non joking manner.
If you wanted to use military force, you would create a power blackout in target area by destroying closest substation or powerplant.
"In the end, two California High School students were arrested and pled guilty. Their mentor, an 18 year-old Israeli, was also arrested"
Surely noone is mad enough to nuke their own country? Or would you nuke the wrong ciutry instead?
It’s that moment the options are to successfully hack the machine, do nothing and hope no physical attack is incoming, try and penetrate serious air defenses with conventional aircraft, or use an ICBM. I don’t mean to suggest people where requesting authorization from the president for a nuclear strike, just that it was considered which is a serious escalation for a cyber attack.
As to the articles, you will note Iraq is mentioned many times by military officials even the attacks originated from teens in the US and Israel. Some of that’s timing, but the other part is as I said the machine happened to be located in Baghdad. Also, the press briefing before they arrested the teens shows just how serious this was being taken. It really wasn’t business as usual.
Why can't we tell? US has a world-wide network of early warning radars and satellites specifically built for this purpose during cold war. Various allied countries have their own networks too, and would warn US.
Iraq never had ICBMs and no-one ever claimed that they do.
I am not seeing a plausible scenario of 'unnoticed incoming ICBM' on US.
"try and penetrate serious air defenses with conventional aircraft, or use an ICBM"
US has bombed Iraq (and many other contries) multiple times by then with minimal losses. I am struggling to see how nuclear holocaust was an appealing option.
Increadible thing do sometimes happen, so I would be interested in there is an article explaining the events or this line of thinking.
Lack of ICBM’s was assumed, but on the moment when your early warning system goes down while your preparing for an invasion it’s hard to stay rational.
The plausible scenario as to why the warning system went down is ARPA net was designed to keep military computers in contact through a nuclear attack. ARPA net became the internet but before SIPERnet and so it was still being used to keep those critical systems in contact. Hackers compromised those systems, because the military was using the same sendmail software as everyone else.
Now for us looking backwards it’s like wait what about computer security, but it largely didn’t exist back then.
Given that you can't refer anyone to anything written, this whole story defies logic and smells of a dead possum.
Blue team: every time
Red team: once
Then, and this is crucial, they not only teach the blue team from their findings - they also rotate out to blue teams, to become the defenders themselves. At the same time, some of the blue team rotates in. Rinse and repeat. The whole point is that you have to understand both sides properly, and continuously work with the teams involved. Otherwise you're nothing more than a consultant.