What an absurd world view.
It is like a bank that has sloppy security and exposes you to the whole world, including adversaries from Russia china NK etc.
Things like Telco cloud banks should absolutely be thrashed for having bad security. Responsible disclosure should also be a thing but we all know these companies sue people for that too.
How do you compensate someone who's dead?
This isn't hypothetical: https://www.politico.com/news/2022/12/28/cyberattacks-u-s-ho...
Anything network connected that can be reached by an adversary. And, I did not say it shoukd be legal or illegal, just that the fault lies with who administers/secures those systems, not with whoever breaches them.
> How do you compensate someone who's dead?
In some countries where I lived, there were pricelists based on nationality that insurance would pay out in case of accidental death. If you live in a more homogenous country, you can use other factors to determine what the payout should be.
Is it about a perceived lack of consequences of the one vs the other? What if the hack caused real damage and suffering? For example, people's medical histories get stolen and exposed? Ransomware encrypts hospital systems, disrupting medical care?
Or, the inverse: while you're away, somebody breaks into your home non-destructively, takes some photos, sleeps on your couch, and leaves. Should that be forbidden? Your fault for allowing it? It is easier to pull something like this in the digital world, is that why it seems different to you?
Making burglaries illegal is a real way of preventing many burglaries from happening, because it puts people committing them in prison and deters some from doing it in the first place. This only works because the burglar is in the same place as the burglary, and so they can be arrested.
People with little to no computer experience apply the same standard to cybersecurity and treat foreign hackers the same way as burglars. Then they get surprised when the Russians hack them and the FBI does nothing.
We're in a thread that starts from the notion that it should not be illegal to "hack a telecom network and take control of it", because "the people running it did not do a good job configuring and securing it." That's essentially the free-for-all position, and defending it by claiming that the opposite extreme is the only other option is a false choice. Nuance and compromise exist, and our world is made of them.
Also, your argument about burglars can be applied to "hackers", too. Police can find and arrest people domestically and beyond. Consequences deter people from all sorts of illegal activity. On the other hand, nation states are not necessarily deterred by laws from kidnapping and killing people inside the territory of other countries. You've probably seen the news.
What's different is the ease of access to digitical, internet-connected systems, and the scale of abuse that affords. That's a reason to think differently about _how_ to shape the rules and laws around "hacking", but not a reason to have no rules or laws at all.
I really don’t understand the urge or need to compare software security with physical security.
Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.
I also notice that you haven't really answered my questions around that.
> if you get hacked, it is on you. The attacker was smarter than you, simple as that.
From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?
I think physical and "cyber" security are not so dissimilar in the need to back them up with rules and laws at some point. Still, there are differences, so I don't think the rules and laws need to be the same. You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.
Yes, it would suck if the hospital got hacked while I underwent a surgery for example, and the ventilator stopped working. But if that happens, whoever is doing it is not stronger, just smarter than the people administering the hospital network.
> From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?
I gave an analogy with chess. You don't have to be strong in the physical sense to win a chess match, just smarter than your opponent. This is how I see the difference.
> You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.
For software, the playing field is level: you use a computer, your opponent uses a computer. But the difference is the other person's capabilities. You can be smarter and you don't get hacked, or your opponent is smarter and hacks you.
For instance, I’m pretty sure I’m better at computer security than Terence Tao but no way would I say I’m smarter than him.
You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.
You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength, or any other advantage, to cause such adverse outcomes in other ways; it is not clear to me if you would also regard that as okay and think we should not have the laws that sanction such things; or if and why you think this anarchy should only exist in some sort of "digital computer space", crossing which would serve to make actual, real world consequences not matter that much anymore. It's almost like, by putting a computer between actions and consequences, one passes through a waterfall that washes away responsibility and "sin", in the ethical sense. But that depends on whether you think those were there to begin with, and is only an interesting metaphor for me; please don't get distracted by it.
In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?
(Edit: Please disregard "what you gain", it comes across completely wrong and takes it in an unintended direction. "Where does it come from" is what I mean.)
I said the fault lies with the administrators of those systems, not with attackers. I really think I never said it should be legal or illegal. I don’t really care if it is illegal or not, hackers are not dettered by the legality of it. Do you think someone in The Gambia cares that hacking is illegal in Canada?
> You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength
For me being smart and being strong are two wildly different things. It is like asking me why I don’t compare apples to oranges. I can’t.
> In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?
I am not trolling. I see this, hacking and securing something against hacking, as an “intellectual fight”.
Let’s say you are a 50 year old security admin that gets owned by a 14 year old with a computer. You were beat because the 14 year old one was smarter than you, not that he had more experience or was physically stronger than you. Just smarter.
Now imagine you’re part of a security team and you still get owned. What does that say about you?
I am at a loss on how to explain that when it comes to computer security the fault, in my book, does not lie with the hacker.
Just like when a flaw is found and exploited I do not blame the one who found it, but whoever made it possible in the first place. And in the case that the flaw was patched and a software update was made available, but it was not installed promptly, then the fault lies with whoever did not update the system.
Regarding arguing: I made a statement expressing my position and got mobbed for it. Now I am defending my position.
We can agree to disagree and keep enjoying what is left of our weekends.
I think I do get it now, and it seems to be pretty much to what I described before. While I think that there is responsibility for the outcomes of one's actions no matter through which ways and means they are accomplished, for you, it seems to depend: making it about smarts or intellect or whatever, and putting a computer in between, causes it to transcend legality and morality. Adverse consequences are not on the actor anymore, and purely on the "defender".
That's not how a lot of people (including myself) see this issue. They would not agree that responsibility and outcomes should get disconnected or redistributed by changing the ways and means in between. (Edit, just to make this extra clear: The idea is that it should not matter if one uses their brain and a computer to effect damage, or some other means. Computers are a different tool, not a different game.) Even more, people find it hard to follow both the ethics and the logic of your argument, because you've not been able to express WHY an exception should be made for "smarts" and "computers" and not in other cases. Whenever I've asked you to explain, you've either misunderstood or evaded the question and responded with re-iterating that "smart" is different from "strong", as if that explains anything. (It boils down to being asked: "Why should the difference between red and blue matter here?" and answering with "Because they are different.")
So, you're taking an position that people find ethically problematic and logically inconsistent, and that's the reason why you receive this pushback: people feel motivated to counter what they see as an uncontested "ethical divergence", and you gave them an obvious logical chink to pry a lever into.
What I'm taking away is that you truly believe this, which is so foreign to me that I'm completely mystified. It makes me curious, and also uncomfortable, and for both reasons I wonder: How? Why? However, you're simply re-iterating your position, and I've come no closer to finding out, nor do I think I actually will, because I can't find a way to phrase my questions in a way that would bridge a barrier of understanding between us and make you respond to what I'm asking.
I'm still curious. But in any case, please do enjoy the rest of your weekend.
There is no door, that cannot be opened with enough effort. Part of what stops people trying, is the fear of consequences.
My issue is that software security is not taken seriously most of the time because features are more important than spending a little more time on code quality.
The hacker is not the one writing buggy software.