[LINK] Schneier on Storm Worm

Craig Sanders cas at taz.net.au
Mon Oct 8 06:49:08 AEST 2007


On Sun, Oct 07, 2007 at 07:57:37PM +0200, Kim Holburn wrote:
> I don't think we really disagree on much.  I just think that a lot of work 
> needs to be done so that computers do all the really hard part of the work 
> on security.

i think we disagree on a pretty fundamental point from which all the
rest follows. you think that a complicated, infinitely tool like a
computer CAN be made as simple as a toaster or a car.  I don't.

in fact, i think that that ideal of simplification is a big part of the
problem.

sure, bad technology is also a big part of the problem and better
technology WILL help a lot, but over-simplification and protecting the
user from all the "too-hard" details is a form of bad technology.

unfortunately, the phrase "irreducible complexity" has been hijacked by
loony creationists but computers are the area where the term actually
applies...it is only possible to simplify them so far until you sacrifice
the utility (or security or whatever) that you are aiming for.

Windows is insecure only partly because of bad technology (sloppy
programming AND bad design). another part of the reason is the misguided
urge to protect the user from all the nasty details.

craig

-- 
craig sanders <cas at taz.net.au>

My advice to the women's clubs of America is to raise more hell and fewer
dahlias.
		-- William Allen White



More information about the Link mailing list