TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Is Cybersecurity an Unsolvable Problem?

27 点作者 cm_silva将近 2 年前

9 条评论

noonething将近 2 年前
Yes. Super AI vs Super AI, attack will always beat defense eventually.
m3047将近 2 年前
Security is largely a quality problem, and quality is something you do not something you buy; this is why. For some reason I&#x27;ve latched onto baseball as my analogy for this.<p>A high-performing team has quality metrics, not only for the players but for the team. A high-performing individual outperforms a low-performing individual (a tautalogy for sure, definitional even). What qualities would you say the high-performing individual exhibits?<p>If you give both players high-quality or low-quality gear, what happens?<p>Can a baseball player who does a quality job of hitting home runs make better baseballs? Oh yeah: can they make better baseballs within the constraints under which baseballs are made? Why do those constraints exist?<p>The high-performing team is going to practice. They will wear out or destroy equipment in the process. Teammembers could potentially suffer career-ending injuries, during practice. During practice.<p>But when the real thing comes along, the practice is the deciding factor for performance individually and as a team.
mikewarot将近 2 年前
Of course cybersecurity can be solved... the solution was worked out in the 1970s, and there are commercially available secure systems. The Operating Systems most of us use daily, on the other hand, do not support multi-level security, nor the Bell-LaPadula model.<p>If we did use such systems, the user interface would be almost identical, but our applications would only be able to open the files we fed them, and not everything, by default. The world would be a much more secure place, but that would have made the NSA&#x27;s job a lot harder, so such systems aren&#x27;t talked about much.
评论 #36109169 未加载
AndrewKemendo将近 2 年前
Having done this for a long time, I agree even more at the practical level - holding perfect Turing security to the side.<p>My priorities now are:<p>- Don’t use computers if you don’t have to<p>- if you do, keep complexity at an extreme minimum<p>- also minimize who needs to access it<p>- minimize data collection where possible for strictly the task you need it for<p>- Keep data mostly at rest and with as few stops when it does have to move<p>- End-to-end is your friend<p>- Where possible make everything transparent<p>- State machines for all the things
incomingpain将近 2 年前
Perpetual cat and mouse game. I would venture to guess we are in a &#x27;hackers winning&#x27; cycle right now. In a couple years itll cycle back to us winning.<p>Imagine a hospital. There will ALWAYS be people looking to break in to find out some specific information. &quot;What did the doctors do that resulted in the death of my loved one?&quot;<p>This is APT you can never stop regardless of budget. they can build any 0day, go to any extent, build completely custom undetectable tools that will never be stoppable.
RadixDLT将近 2 年前
had no idea the founder of hacker news was a hacker
评论 #36105532 未加载
nuc1e0n将近 2 年前
It&#x27;s very difficult to overcome an airgap. How could society reorganise around that? Going back to sneakernets?
2snakes将近 2 年前
Can all reverse&#x2F;bind&#x2F;web shells be prevented with network firewall at the process level?
davidivadavid将近 2 年前
Is Football an Unsolvable Problem?