logoalt Hacker News

josephgyesterday at 10:09 PM5 repliesview on HN

> It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.

Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.

We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.


Replies

taurathyesterday at 11:20 PM

> Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”.

I work in secure systems and it’s shocking how many people believe this - the incentives from management are all about it too.

iugtmkbdfil834yesterday at 11:22 PM

<< And as such, it’s much more expensive. And nobody wants to pay.

Eh. If only it was that simple. I mean, yes, money is always a factor, but not nearly as big of a factor as 'my convenience outweighs pretty much everything ( until it causes sufficient amount of havoc.. and even then.. )'. You can see it in just about everything. It is not just the money. It is the convenience that drives most of the unsecure behavior.

mslayesterday at 10:20 PM

The bank has the best doors, the best locks, and the best cameras, and it is patrolled by a guard who props the doors open to so he doesn't have to keep fooling with the locks and points the cameras the other way to extend his smoke break. SeL4 would be another system used by humans.

show 3 replies
bjtitusyesterday at 10:17 PM

[dead]