news.volyx.in

A case against security nihilism (blog.cryptographyengineering.com)

468 points by feross · 1892 days ago · 332 comments on HN

Article summary

The article discusses the recent revelations about NSO Group's Pegasus spyware and its use to target journalists and politicians. The author argues that while it's impossible to achieve perfect security, companies like Apple can do more to protect their users by addressing fundamental weaknesses in their systems, such as the parsing of complex data in iMessage. The author suggests that raising the cost and risk of exploitation can make it harder for companies like NSO to operate at scale. This can be achieved by implementing memory-safe languages, expanding remote telemetry, and making companies liable for damages caused by their software.

Main themes

  • cybersecurity regulation
  • exploit sales
  • state-level actors
  • memory-safe languages
  • software liability
  • scale of exploitation
  • political approach to cybersecurity
  • bureaucratic measures to prevent exploitation
  • technical vs political solutions to cybersecurity problems

What commenters say

  • Regulation of the cybersecurity industry is necessary to prevent companies like NSO from selling exploits to state-level actors.
  • Implementing memory-safe languages and secure coding practices can help prevent exploits and make it harder for companies like NSO to operate.
  • Regulations would be ineffective in stopping state-level actors from obtaining exploits, as they can simply purchase them from other sources.
  • Making companies liable for damages caused by their software can incentivize them to prioritize security and fix vulnerabilities.
  • The problem of cybersecurity is not just a technical issue, but also a political one, and requires a comprehensive approach that includes regulation, international cooperation, and education.
  • The focus should be on limiting the scale of exploitation, rather than trying to achieve perfect security, and this can be done by raising the cost and risk of exploitation for companies like NSO.
  • Regulations can help to restrict the funding of companies like NSO and limit their ability to operate, even if they cannot completely stop them.
  • The use of bureaucracy, such as requiring companies to fill out paperwork and obtain approval for every customer, can help to slow down the sale of exploits and make it more difficult for companies like NSO to operate.