Re: A more fundamental issue..
Jeroen van Drie <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
Hello Marius, My main concern is accountability in the development process in general, also in computing. Security has everything to do with accountability and transparency. If a software community or company didn't have accountability and transparency developers wouldnt even know where to start looking for a flaw let alone fix it. But computing isn't isolated, in fact it is currently the most central process in pretty much any other type of development/engineering. Whatever we as computer security people do has ramifications throughout. OS and library software (data formatting standards as well) are becoming fundamental to the operation of society, so their openness (accountability, transparency) is becoming increasingly important to democracy. In democracy the fundamental operation of society is public; Important infrastructure can be privately owned but there's a gray area and OS & library functions have moved into that gray area. In genetic engineering the call for debate about openness should ring out even louder because our DNA is inalienably even more "public property" than a computer operating system and its related functions can ever be. And computing security has everything to do with genetic engineering. In genetic engineering, especially in DNA sequencing, we increasingly see programmers involved in the creation of new DNA sequences; that's because DNA sequencers are computers that need to be programmed to produce the proper sequence. It isn't hard to do, my guess is that it's programatically easier than coding in php or vb and getting easier with each new version of sequencer machines. Also, those machines run an operating system. So we need this openness all across the board if we want to retain democratic controls over large areas of society that can be rapidly changed by emerging technologies. Anyone can buy DNA sequencers on ebay and how much expertise would it really take to design a virus that takes advantage of our "vulnerabilities"? Or how secure do we feel we about the operating systems running on DNA sequencers? Or those that hold our medical or tax records? Or voting machines? > So, if things don't change direction, you fear that the entire > industry (or would you say the entire world?) will depend on a few > 'gurus' to maintain the link between the low-level and the high-level > in a secure fashion? No I'm not afraid of that, that already is basically how things work for the larger operating systems. And there's no alternative to that. And yes as hardware moves into our bodies any vulnerability in the software that runs that hardware could be disastrous. Especially because it's all becoming integrated and networked. Politics seems to be legislating private ownership in the public realm (you can own genetic code and species, retain ownership over artistic copyright much longer, etc, etc) while ignoring its responsibility in protecting the public against private ownership of basic public matters (such as DNA and document formats). > I think microsoft would be in big trouble if they could be held > accountable for the security problems in their software. It would be easier to hold colt accountable for people using colt revolvers in shootings. Making software developers responsible for misuse of their software would end the viability of pretty much all software development. It's the end user that is be responsible. The end user needs to be well educated and before we (over the next few decades) give that end user the power of god to create life we better make damn sure we can also stop that end user from ending all users.