Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

‘Secure’ == unable to be compromised.

You seem to be saying ‘secure’ == ‘compromises are able to be fixed’.

Which doesn’t fit any definition of secure I’m aware of.

Every one of those things you mention has been compromised, and then fixed, at various times. Depending on specific definitions of course.

And that is what we see publicly. Typically figure on an order of magnitude more ‘stealth’ compromises.

For a compromise to be fixed, someone has to notice it. Exposing machines to the Internet increases attack surface dramatically. Allowing machines to talk to the Internet unmonitored and unrestricted increases their value to attackers dramatically.

Without careful monitoring, many of the resulting compromises will go undetected. And hence unfixed.

[https://www.cvedetails.com/vulnerability-list/vendor_id-1902...]

[https://www.cvedetails.com/product/47/Linux-Linux-Kernel.htm...]

[https://purplesec.us/security-insights/space-x-starlink-dish...]

[https://www.pcmag.com/news/account-hacking-over-starlink-spa...]



You made a universal statement, namely, "there is no secure software".

If you had written, "99% of software used in anger is insecure," or, "most leaders of most organizations don't realize how insecure the software is that their organizations depend on," or, "most exploits go undetected", I would not have objected.


That is quite explicitly not what I wrote. You might want to re-read my comment.

My point not only stands, but is reinforced by your comments.

If software is eventually compromised, it was not secure. I have yet to see any software that does not eventually get compromised when it gets enough exposure.

That those compromises can get fixed after the fact doesn’t change that.

And ignoring the explicit cases where your examples were disproven doesn’t help your case either.


I find it obnoxious to correspond with you.


The feeling is mutual, apparently.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: