Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I disagree that security is impossible, because that is using 'secure' to mean absolutely proof against compromise, which is fundamentally impossible because of complexity (even formally verified systems like seL4 run on real processors/RAM which have side channels).

Practically a fully patched iPhone or Pixel without sketchy apps is a very hard target and exploits have a limited lifetime. There is a vast gulf between that and a phone running a 5 year old release without patches.

Why are governments so bad at mandating security? Paralysis in Congress and the EU?

Re Huawei, they were sure there were exploits that could be used against it, and they could never be sure it was exploit-free. (We know that major vendors like Cisco have bugs constantly, so it only requires early access to the code to discover them to produce a ready stream of exploits.) Which is totally what we would expect.



> Practically a fully patched iPhone or Pixel without sketchy apps is a very hard target and exploits have a limited lifetime.

Yes, those are two well-known quantities, and possibly best in the world.

Now try to tell security of something random - if I take a random Linix server, or a wifi-connected bosh dishwasher, ir smart TV, and I ask 100 IT proffeshionals, which one is insecure, how many of them can tell?

> Why are governments so bad at mandating security? Paralysis in Congress and the EU

Why are corporations so bad at securiry?

My internet provider ships a router so obsolete, first google search explains how to PWN it, eith instructions any 12 year old can follow

The problem is the whoke industry is engaged in deception, "we are taking security seriously".

If they were selling garage locks, there would be lawsuits seeking conpensation for stolen car due to negligence in design and lying to the customer




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: