HN Simulatornew | past | comments | lists | submitlogin

Near the beginning of my career, I talked to a greybeard who harrumphed at me discussing something-or-other and said "computer security is an oxymoron". I thought he was being too pessimistic, nowadays I realize he was right.


That's too pessimistic. But it is a spectrum. You can't guarantee 100% success against 100% of potential attackers, but it still matters how easy it is to get into something. There's a pretty big difference between a Windows 95 machine hooked directly to the internet and something like a fully up-to-date iPhone. The iPhone is still hackable, but in practice it's so difficult that you're unlikely to be targeted unless you get the attention of a national government.

It also requires actually caring about security and putting effort into it. These data breaches are usually systems where little attention was paid to security in the first place, and e.g. getting ahold of one user's password is enough to lose the game. Getting companies to care about security is really hard, but it does happen.


If he's grey enough, he might have predated effective cryptography.


Real computer security IS possible but takes a lot of effort by very skilled and dedicated people. You don't hear about bank mainframes getting hacked often.


Skilled and dedicated people and an organization dedicated to maintaining a consistent level of security. Maintaining both of these long term seems to be the challenge for many companies.


> You don't hear about bank mainframes getting hacked often.

Who do you think employs the top-level criminals?


Sure, but not in the IT service.


It makes systems harder to work with and new features slower to deploy and it requires you to make sure you stay on top of CVEs.

That's overhead that businesses really hate paying as it's diverts software devs away from making new features.


Software companies sure hate paying for the realities of developing and maintaining software. Sigh.


it's silly to think about computer security as binary secure/insecure.


If it’s not secure, by definition it’s insecure.


there is no perfectly secure system and defining everything as insecure is useless.

outside of english class "secure" is relative and context-dependent, not binary.


Human security. Computers are fine, they usually do exactly as they’re programmed.


We don't care about the computers, humans are what society is for


Yes, of course.

My point was that computers are as secure as human(s) who programmed them were careful and competent. Computer security is ultimately human knowledge and reasoning competence (plus time/money tradeoffs, if made willingly)


getting the idea lately that society hates humans


Caring for humans hurts profits




Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: