Disclaimer: The above is an opinion. Double-blind trials have not been performed!
548 karma · joined January 3, 2015
Co-founder and CTO of Clovyr, a company that makes it easy to build and use decentralized applications
Disclaimer: The above is an opinion. Double-blind trials have not been performed!
It's true that abstractions in functional languages can seem foreign and hard to understand, but generally they have some purpose, being grounded in mathematical practice. OO abstractions and patterns OTOH, taught essentially in "elementary school" which possibly makes them seem easier to understand, do a very poor job of solving more problems than they create.
Learning a functional language is often a transformative experience that lasts throughout a career, whether you even use functional languages or not. It might make you do something as simple as partitioning which functions have side effects and which don't, even if the type system doesn't enforce it. Or use a form of quick/fuzz testing, even if it's not the standard test suite. Or make parts of the data immutable for scalability, auditability, etc. Or...
There really are few things as satisfying as developing a large codebase in a functional language. A lot of the frustrating maintenance work just goes away. But even if you don't, functional principles can yield similar benefits in imperative languages.
At the same time, tribes in Papua New Guinea who eat almost exclusively carbohydrates have been shown to be virtually free of heart disease.
Zooko and Amber Wilcox-O'Hearn maintain a fascinating blog on the science of ketogenic (very low carb) diets that I can highly recommend: http://www.ketotic.org/
Now, that's mostly anecdotal. There are very few studies on diet in general. As far as type 2 diabetes is concerned, though, low-carb diets have empirically been shown to reduce the need for insulin injections, slow progression of disease, and prevent the disease in the first place.
Is there anything that competes/a "next Nginx"?
It should be "smart work," not "hard work." Hard implies it's all just the transfer of energy--what seems to excite MBAs--when all that should matter is delivering results. Isn't that what capitalism is supposed to be?
The key will likely be something like Android, that's based on the Linux kernel, but locks the vendors into some notion of a safe environment, and applies updates in a timely manner (the Linux kernel still has frequent critical security fixes.)
(Having vendors be able to articulate what the devices should be able to connect to or do, and having the OS/runtime enforce that would be a huge step forward.)
But Android itself is also insecure primarily due to fragmentation and end-of-lifeing, hence the feeling of hopelessness.
- There are so many different kinds of devices and different hardware
- Vendors want to maximize profits like everyone else, which entails making new devices all the time, and ending support on the last model fairly quickly (typically within two years,) but consumers regularly keep their devices for more than two years.
- Hardware vendors historically were not software vendors. For many IoT makers, this is their first real foray into software. The mistakes being made are amateurish, at a level that we saw on PCs in the mid-90s.
- Although there are some IoT standards, they're mostly concerned with communications, not the operating system. It feels like we're still 5+ years off from something as basic as automatic updates being a given (even just notifying users that an update is available and allowing them to easily install it is a challenge currently.)
Two things that are really bothersome:
- A huge number of IoT devices don't need the 'I'. They are perfectly capable of serving their purpose without an Internet connection (e.g. over Bluetooth,) but a huge attack surface is added to make you able to configure the device via a central website, or simply to monetize usage data.
- It is futile to trust each vendor to have the security expertise to lock down every device. An "IoT operating system" would be highly desirable, but there is nothing anywhere near real world implementation, and given the heterogeneous of hardware components it doesn't seem likely something non-Linux-based will come along.
Brickerbot is hostile and aggressive and shouldn't be necessary, but maybe it is. That's beside the point, though: Nobody has to be given permission to brick insecure IoT devices. Vendors don't feel it where it hurts (the bottom line,) and consumers increasingly just don't care (studies show people have grown accustomed to security incidents -- "it happens to everyone and everything; replace it and move on, there's nothing you can do")
Hacks made Microsoft shape up in the 90s and early 2000s, but Windows has only become actually secure since after Vista. Maybe just don't buy IoT devices for another 5-10 years, or at least put them on a separate vlan.
There are a bunch of groups trying to spread the word, but it doesn't seem many vendors are listening (or if they are, they don't have the capability to really secure their devices.) We've had some success with Securing Smart Cities working with local and state governments, and trying to address some of these issues before hilariously insecure IoT hardware becomes ubiquitous in cities/related to critical infrastructure: http://securingsmartcities.org/
It's hard to see how it's not going to get much, much worse before it gets better.
Interesting. Should this be available as a compiler warning in other languages?
A couple of years ago, I wouldn't have believed we would be seeing essentially zeroconf TLS/PKI in software anytime soon. Letsencrypt, the "encrypt everything" movement, and people like Steve, Ponzu's author, have improved internet security tremendously at a time when it is critically needed.
I didn't mean that hacking is as culturally significant as the Dala horse or Semla. Just that, for example, nearly every kid in our town came to the LAN parties, even the "jocks." And everyone needed to troubleshoot networking issues, figure out how to get the games to run (cough without a serial key cough,) and so on. The biggest jock in town was cool because he played a MUD without ASCII colors, making him "hardcore." (Not to mention that the largest LAN party in the world, Dreamhack, which continues to this day, is in Sweden.)
Does that mean that all those kids became hackers? Of course not. But clearly being exposed to system internals coupled with a driving curiosity is how a lot of hackers got started, and so it's no surprise to me that IKEA has capable infosec talent.
A lot of the early Internet's game cracking scene originated in Sweden, too.