ZH version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
64% Positive
Analyzed from 2086 words in the discussion.
Trending Topics
#software#security#old#don#anything#more#data#imei#years#bbc

Discussion (59 Comments)Read Original on HackerNews
Our water and power utilities need to re-watch the pilot.
Remote management has clear benefits, don’t be obtuse. I totally agree on the security risks, but the benefits are obvious.
It's the same lesson that we can learn from Star Trek, Star Wars, and all the other self-aggrandising lore that humanity concocts when gazing lovingly in the mirror.
There is no greater enemy than greedy, barbaric humanity itself.
From a efficiency perspective centralized anything seems better at first glance, however decentralized anything just seems more resilient in the long run like nature and/or our universe.
The thing is: police actually have data on swords and bows, and the fact it is so unusual to commit crimes with these limit the search space and tend to make the investigation easier.
I haven't really gotten really into this, but from what I can tell, anything that has to do with mobile phones is strictly worse in terms of anonimity than Wifi.
At least anything that ties a Wifi connection to you you can change in an OS setting, but if you get into faking IMEI/SIM stuff, that can very quickly get you charged with an actual crime.
If you dig into the fake cell tower rabbit hole you'll find what you're talking about to be an even worse problem.
How do you suppose mobile phones are meant to work without subscriber info?
> I haven't really gotten really into this
Clearly.
I was hoping it was gonna be about how our modern practices are making things less secure.
For instance, we claim we need to be able to rapidly update clients so that we can patch security vulnerabilities as they are discovered (often without involving the user at all). And there are a lot of companies that have an incentive to push this narrative because they have products which facilitate this whack-a-mole approach to security. But there's no reason to believe that new software is more secure than old software. Old software is just more likely to be known to be insecure. So anything written before it became trendy to update without your user's consent is more secure in at least one way because it is not configured to automatically update to whatever comes down the pipe from "the vendor".
hmm
For Windows 3.1/95/98 I feel they were incredibly vulnerable in the 2000s and 2010s, but now they have aged so much where getting to them is becoming a hurdle and a chore preventing attackers from making it to the target.
The article links to a vulnerability from 1998, which I expect is already fixed in the versions of Eudora people still use.
I agree it would probably be easy for AI to find exploitable bugs though.
This is BBC Future - the BBC's tech clickbait publisher - not BBC News.
BBC consists of the non-profit news bureau as well as at least a dozen for-profit clickbait and listicle publishers. BBC's ad-free mandate is only for the UK.
> in the age of Claude - I am pretty sure I can destroy your legacy software in minutes
Yep. One of our PortCos has unrestricted access to Anthropic and GPT models. With whitebox testing, it's trivial to identify vulns in legacy environments. With blackbox testing, it takes some effort but it doable with the right steering.
It feels like fantasy imo
While I could understand using outdated or not popular protocols, then software with known vulns seems crazy when we are living in world of automated, ai assisted scanners
Vs.how many dire flaws have been found in big-name security products in the past year, that even a low-budget adversary is likely to be regularly checking for?
There are databases that list every known flaw in existence, and the bots just go down the list checking each and every one. And if it doesn't work, in 5 minutes, they'll run those same tests again as if something changed in those 5 minutes.
How would you arrive at this percentage in your risk analysis?
Paying $$$ for a LatestGreatest(tm) Firewall won't make you 100% secure either. And the $$$ might better be spent on an extra layer of swiss cheese, or better recovery capability.
[1] https://en.wikipedia.org/wiki/The_Cuckoo%27s_Egg_(book)
[2] https://news.ycombinator.com/user?id=CliffStoll
[3] https://news.ycombinator.com/item?id=21830277
[4] https://news.ycombinator.com/item?id=39843930
[5] https://news.ycombinator.com/item?id=49406713
That said, as a strategy it will only protect you from bots going after low-hanging fruit, not someone targeting you specifically.
https://www.theregister.com/on-prem/2018/02/06/ghost-in-the-...
The problem is that most of these older devices are about to be replaced and many manufacturers have switched to Linux for their operating system, which is cheaper and requires no licensing, but is also far more insecure. It needs almost constant patching to stay secure because the attack surface is so large.
There are hospitals out there still running on windows XP. Someone's going to skim this article and say "look, we're actually being prudent"!
You can't just create a tiny csv of the records you want. You need to upload GBs of data which is easily noticed by any of the routers involved.
Although I mean just because somebody noticed data is being leaked they might not have the authority to stop that doge employee or whomever.
While I don't know any of the relevant numbers involved, imagine a scenario where exfiltrating even 10% of the total data would take years. What would be the point?
A malicious actor can target individual records, but leaking a lot of them becomes impractical.
I have also seen virus source code published in books and magazines. We don't have such threats anymore.
virus source code published in books and magazines. We don't have such threats anymore.
--
No, we do not need this anymore - today you have CAPTCHAs, convincing people to copy & paste PowerShell code on their machine and execute it with Admin privileges! :-D