I grew up in a country where every kind of software was availbale on a CD - usually a collection of whatever could fit on a CD. And paying for software was a considered a blasphemy.
My first software purchase was I think after 2015, and it still felt weird compared to the usual process of finding a keygen somewhere.
So if you steal something it means the owner didn’t do a good job securing it and if you murder someone they didn’t do a good job protecting themselves?
The diff is that owner is responsible for their own shit where a telco has everyone's things in there and is exposed to the whole world instead of just one street.
It is like a bank that has sloppy security and exposes you to the whole world, including adversaries from Russia china NK etc.
Things like Telco cloud banks should absolutely be thrashed for having bad security. Responsible disclosure should also be a thing but we all know these companies sue people for that too.
Does that extend to medical systems? If someone hacks my pacemaker and destabilizes my heart, or my pharmacy/hospital and prevents me from receiving medical care, is that something that should be legally permitted on the basis that "medical device makers/pharmacies/hospitals should try harder, and should somehow compensate their patients if a hack occurs"?
Anything network connected that can be reached by an adversary. And, I did not say it shoukd be legal or illegal, just that the fault lies with who administers/secures those systems, not with whoever breaches them.
> How do you compensate someone who's dead?
In some countries where I lived, there were pricelists based on nationality that insurance would pay out in case of accidental death. If you live in a more homogenous country, you can use other factors to determine what the payout should be.
Since you mentioned it below several responses to this comment: Why do you think this is okay for software, but not okay in the "physical world"?
Is it about a perceived lack of consequences of the one vs the other? What if the hack caused real damage and suffering? For example, people's medical histories get stolen and exposed? Ransomware encrypts hospital systems, disrupting medical care?
Or, the inverse: while you're away, somebody breaks into your home non-destructively, takes some photos, sleeps on your couch, and leaves. Should that be forbidden? Your fault for allowing it? It is easier to pull something like this in the digital world, is that why it seems different to you?
I don't agree with GP at all, but making hacking illegal indeed gives companies a false sense of security.
Making burglaries illegal is a real way of preventing many burglaries from happening, because it puts people committing them in prison and deters some from doing it in the first place. This only works because the burglar is in the same place as the burglary, and so they can be arrested.
People with little to no computer experience apply the same standard to cybersecurity and treat foreign hackers the same way as burglars. Then they get surprised when the Russians hack them and the FBI does nothing.
You're presenting a false dilemma, there are more options than "all hacking is completely illegal" and "all hacking is a free-for-all".
We're in a thread that starts from the notion that it should not be illegal to "hack a telecom network and take control of it", because "the people running it did not do a good job configuring and securing it." That's essentially the free-for-all position, and defending it by claiming that the opposite extreme is the only other option is a false choice. Nuance and compromise exist, and our world is made of them.
Also, your argument about burglars can be applied to "hackers", too. Police can find and arrest people domestically and beyond. Consequences deter people from all sorts of illegal activity. On the other hand, nation states are not necessarily deterred by laws from kidnapping and killing people inside the territory of other countries. You've probably seen the news.
What's different is the ease of access to digitical, internet-connected systems, and the scale of abuse that affords. That's a reason to think differently about _how_ to shape the rules and laws around "hacking", but not a reason to have no rules or laws at all.
Because it is a battle of the brains, like when you play chess. And I believe the smarter one should win. This is why I have this strongly held belief that if you get hacked, it is on you. The attacker was smarter than you, simple as that. So you have to get smarter and become better. Or you get hacked again and again.
I really don’t understand the urge or need to compare software security with physical security.
> I really don’t understand the urge or need to compare software security with physical security.
Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.
I also notice that you haven't really answered my questions around that.
> if you get hacked, it is on you. The attacker was smarter than you, simple as that.
From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?
I think physical and "cyber" security are not so dissimilar in the need to back them up with rules and laws at some point. Still, there are differences, so I don't think the rules and laws need to be the same. You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.
> Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.
Yes, it would suck if the hospital got hacked while I underwent a surgery for example, and the ventilator stopped working. But if that happens, whoever is doing it is not stronger, just smarter than the people administering the hospital network.
> From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?
I gave an analogy with chess. You don't have to be strong in the physical sense to win a chess match, just smarter than your opponent. This is how I see the difference.
> You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.
For software, the playing field is level: you use a computer, your opponent uses a computer. But the difference is the other person's capabilities. You can be smarter and you don't get hacked, or your opponent is smarter and hacks you.
You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.
You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength, or any other advantage, to cause such adverse outcomes in other ways; it is not clear to me if you would also regard that as okay and think we should not have the laws that sanction such things; or if and why you think this anarchy should only exist in some sort of "digital computer space", crossing which would serve to make actual, real world consequences not matter that much anymore. It's almost like, by putting a computer between actions and consequences, one passes through a waterfall that washes away responsibility and "sin", in the ethical sense. But that depends on whether you think those were there to begin with, and is only an interesting metaphor for me; please don't get distracted by it.
In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?
(Edit: Please disregard "what you gain", it comes across completely wrong and takes it in an unintended direction. "Where does it come from" is what I mean.)
> You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.
I said the fault lies with the administrators of those systems, not with attackers. I really think I never said it should be legal or illegal. I don’t really care if it is illegal or not, hackers are not dettered by the legality of it. Do you think someone in The Gambia cares that hacking is illegal in Canada?
> You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength
For me being smart and being strong are two wildly different things. It is like asking me why I don’t compare apples to oranges. I can’t.
> In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?
I am not trolling. I see this, hacking and securing something against hacking, as an “intellectual fight”.
Let’s say you are a 50 year old security admin that gets owned by a 14 year old with a computer. You were beat because the 14 year old one was smarter than you, not that he had more experience or was physically stronger than you. Just smarter.
Now imagine you’re part of a security team and you still get owned. What does that say about you?
I am at a loss on how to explain that when it comes to computer security the fault, in my book, does not lie with the hacker.
Just like when a flaw is found and exploited I do not blame the one who found it, but whoever made it possible in the first place. And in the case that the flaw was patched and a software update was made available, but it was not installed promptly, then the fault lies with whoever did not update the system.
Regarding arguing: I made a statement expressing my position and got mobbed for it. Now I am defending my position.
We can agree to disagree and keep enjoying what is left of our weekends.
Oh, I don't mind the disagreement, I'm curious to understand why your position is so different from mine, after getting closer to understanding what your position actually is. (I had to do that because there are some implicit premises in my thinking vs what you're saying which seem fundamentally different, and I had to work those out for myself.)
I think I do get it now, and it seems to be pretty much to what I described before. While I think that there is responsibility for the outcomes of one's actions no matter through which ways and means they are accomplished, for you, it seems to depend: making it about smarts or intellect or whatever, and putting a computer in between, causes it to transcend legality and morality. Adverse consequences are not on the actor anymore, and purely on the "defender".
That's not how a lot of people (including myself) see this issue. They would not agree that responsibility and outcomes should get disconnected or redistributed by changing the ways and means in between. (Edit, just to make this extra clear: The idea is that it should not matter if one uses their brain and a computer to effect damage, or some other means. Computers are a different tool, not a different game.) Even more, people find it hard to follow both the ethics and the logic of your argument, because you've not been able to express WHY an exception should be made for "smarts" and "computers" and not in other cases. Whenever I've asked you to explain, you've either misunderstood or evaded the question and responded with re-iterating that "smart" is different from "strong", as if that explains anything. (It boils down to being asked: "Why should the difference between red and blue matter here?" and answering with "Because they are different.")
So, you're taking an position that people find ethically problematic and logically inconsistent, and that's the reason why you receive this pushback: people feel motivated to counter what they see as an uncontested "ethical divergence", and you gave them an obvious logical chink to pry a lever into.
What I'm taking away is that you truly believe this, which is so foreign to me that I'm completely mystified. It makes me curious, and also uncomfortable, and for both reasons I wonder: How? Why? However, you're simply re-iterating your position, and I've come no closer to finding out, nor do I think I actually will, because I can't find a way to phrase my questions in a way that would bridge a barrier of understanding between us and make you respond to what I'm asking.
I'm still curious. But in any case, please do enjoy the rest of your weekend.
You don’t have to be smarter than your opponent to beat them in chess. You need to be better at chess, that’s it. Sure you need some degree of intelligence to be good at chess but being better at chess is not an indicator that you are smarter than your opponent. Same goes for computer security or any other intellectual field.
For instance, I’m pretty sure I’m better at computer security than Terence Tao but no way would I say I’m smarter than him.
Semantics. If you have a computer, the hacker has a computer, and you get hacked, the hacker is smarter. For whatever values of better/creative/resourceful you want to attribute to “smarter”.
My issue is that software security is not taken seriously most of the time because features are more important than spending a little more time on code quality.
A few years back, NATS went down because a flight plan waypoint confused the system and it crashed. They had to manually find the problematic flight plan, remove it and start the whole system back up.
Considering the last issue they encountered, it looks like in more than one place, there is no error catching and graceful resolution for those errors.
I would assume a system of such importance to handle issues without hiccups and alert the operators of what did not work. Like “this input caused this problem”, not just crash.
Back in 2023 when the previous issue happened, it didn't actually "crash", it detected what it perceived as an inconsistency (which was due to invalid waypoint logic for waypoint codes in multiple countries) and put itself in "maintenance mode".
My point was that it should not have happenned in the first place. It should have just rejected the flight plan, sent a notice to whatever coordination center would have been in charge of the flight and kept running.
The fact that it entered in maintenance mode still ruined a lot of people’s days.
I don’t think any flight crew or passenger cared about semantics back then.
If you think about this for a minute, maybe you'll be able to form a theory for why this is already very common for military vessels, but not so much for unarmed civilian ones...
I guess this is not exactly "cost", but also lifetime spans. A nuclear reactor can sustain a ship for about 20+ years, and that lifetime is too long for many ships, who would be headed out to the scrap yard in less time than that.
Unless you have a synchronous like setup where you don’t acknowledge data writes unless the remote has aconowledged them first, you will lose data in case your datacenter is hit by a warhead.
Now, there are a few things to consider:
- AWS best practices recommend multiple AZs for workloads and cross-region backups for things like databases and other “stateful” data
- You have to read the fine-print on what AWS offers in terms of recovery: do they reffer to their own infrastructure when they say “you won”t notice” or your data
When Google’s Paris colocation facility was flooded and all AZs there went dark, they sent an email saying “restore from backup in another region and if we can restore your data, we will make it availbale to you”. They did not even issue credits for the downtime.
An extraordinary statement itself that shows the difference between a proper cloud where they AZs are at least 60 to 100 miles apart...and Google or Microsoft... pretend clouds...where those AZs are just firewalls across the same data center...
> You keep spreading this, but the eurocommssion president gets appointed by the European Council, which consists of democratically elected heads of state.
It does not matter who elects the EU commission, there needs to be a popular vote across the EU for every commissioner job and the EU Commission head. What we have today in EU is pure BS: every country gets a commissioner based on that country's influence within the bloc and every time a new country joins the EU, a new commissioner role just happens to be created.
I want to be able to choose from a number of candidates who should run the EU, not the prime minister or the president of a member country.
Everybody who holds even a little power in the EU construct needs to be voted by EU citizens, not appointed by who knows who.
This second- or third-hand "democracy" is not a democracy at all.
> there needs to be a popular vote across the EU for every commissioner job and the EU Commission head.
Your talking points are misinformed and pretty ridiculous which makes me think you're a troll rather than having a faithful argument. But on the off chance you are trying to have a real discussion: The Council and Parliament both get elected and the commission cannot do anything without them, so it's not like the system is not democratic.
I don't see the US asking for their attorney general or supreme court justices to be democratically elected. At some point you have to trust that the people you actually elect will appoint people who know what they're doing.
Just because there's someone in the chain you're not doing a round of elections on doesn't make the system bad. You need the system to have agency at some point.
EU did commit a suicide, absolute disaster in terms of investment for decades, and a very 'aristocratic' climate policies. Oh, not to mention the immigration 'policies' which were written with crayons, and resulted in a very low social cohesion. But it might still be better than being absorbed by the US!
This and previous submission about the Automattic board attempt to fire the founder should be used as a lesson that you should never ever give up control of your company to anyone.
Facebook is a good example on how to structure your company to keep control of it.
And FB is a lesson to a lot of companies and the public not to allow the same dual class stock structure. Zuckerberg can cash out a lot of his equity and still be the controlling force behind FB even though other people "own" a majority stake of the stocks and equity.
> This and previous submission about the Automattic board attempt to fire the founder should be used as a lesson that you should never ever give up control of your company to anyone.
I'm afraid in this case, this "should never" barely makes Mullenweg's top 10.
If a founder is going to VCs or the markets in general for funding, there's no way to really do this. I don't see how the vast majority of founders can realistically expect others to fund their companies and still let the founder have the final say on all company matters.
If founders are willing to self-finance or finance based on cash-flow/collateral, that's a different story. But if you're selling majority stakes of your company's equity to others in order to finance your operations and growth, the equity owners should get a majority vote in how your company runs.
> I don't see how the vast majority of founders can realistically expect others to fund their companies and still let the founder have the final say on all company matters.
By not selling the controlling majority stake in their company, or retain super-voting rights. Anything to not give anyone the possibility to take their company from them.
Well, not selling controlling majority stake is fine. What people have issues with are the super-voting rights that where the people owning those rights get to play with other's money with the others not having much say on how that money gets used. E.g. look at meta's VR spending as an example.
The unhappy investors can sell their Meta shares and invest in something else if they don't like it, no? Now, since they are just unhappy but don't sell, it means Meta still makes money for them.
As fou der - yes. The question is if investors accept that gamble.
Facebook, when, Meta took a bunch of bad decisions in recentyears. All that Metaverse is just a write off ... for now the stock market liked the "vision" but that may end.
How willing investor's then are to play such a game is to be seen. I guess this only works in exceptional cases. Facebook was a money printing machine everybody wanted to be a part of.
My first software purchase was I think after 2015, and it still felt weird compared to the usual process of finding a keygen somewhere.
reply