Re: A more fundamental issue..

Jeroen van Drie <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
Hello Marius,

My main concern is accountability in the development process in general, also 
in computing. Security has everything to do with accountability and 
transparency. If a software community or company didn't have accountability 
and transparency developers wouldnt even know where to start looking for a 
flaw let alone fix it. 

But computing isn't isolated, in fact it is currently the most central process 
in pretty much any other type of development/engineering. Whatever we as 
computer security people do has ramifications throughout. 

OS and library software (data formatting standards as well) are becoming 
fundamental to the operation of society, so their openness (accountability, 
transparency) is becoming increasingly important to democracy. In democracy 
the fundamental operation of society is public; Important infrastructure can 
be privately owned but there's a gray area and OS & library functions have 
moved into that gray area.

In genetic engineering the call for debate about openness should ring out even 
louder because our DNA is inalienably even more "public property" than a 
computer operating system and its related functions can ever be. 

And computing security has everything to do with genetic engineering. In 
genetic engineering, especially in DNA sequencing, we increasingly see 
programmers involved in the creation of new DNA sequences; that's because DNA 
sequencers are computers that need to be programmed to produce the proper 
sequence. It isn't hard to do, my guess is that it's programatically easier 
than coding in php or vb and getting easier with each new version of 
sequencer machines. Also, those machines run an operating system. 

So we need this openness all across the board if we want to retain democratic 
controls over large areas of society that can be rapidly changed by emerging 
technologies. Anyone can buy DNA sequencers on ebay and how much expertise 
would it really take to design a virus that takes advantage of our 
"vulnerabilities"? Or how secure do we feel we about the operating systems 
running on DNA sequencers? Or those that hold our medical or tax records? Or 
voting machines?


> So, if things don't change direction, you fear that the entire
> industry (or would you say the entire world?) will depend on a few
> 'gurus' to maintain the link between the low-level and the high-level
> in a secure fashion?

No I'm not afraid of that, that already is basically how things work for the 
larger operating systems. And there's no alternative to that. And yes as 
hardware moves into our bodies any vulnerability in the software that runs 
that hardware could be disastrous. Especially because it's all becoming 
integrated and networked.

Politics seems to be legislating private ownership in the public realm (you 
can own genetic code and species, retain ownership over artistic copyright 
much longer, etc, etc) while ignoring its responsibility in protecting the 
public against private ownership of basic public matters (such as DNA and 
document formats).

> I think microsoft would be in big trouble if they could be held
> accountable for the security problems in their software.

It would be easier to hold colt accountable for people using colt revolvers in 
shootings. Making software developers responsible for misuse of their 
software would end the viability of pretty much all software development.

It's the end user that is be responsible. The end user needs to be well 
educated and before we (over the next few decades) give that end user the 
power of god to create life we better make damn sure we can also stop that 
end user from ending all users.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.