Hacker Newsnew | past | comments | ask | show | jobs | submit | ris's commentslogin


This is why we can't have nice things.


I hate this meme.

The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).


Doesn't have to be a literal wrench right? A government can trivially and legally make you miss the itinerary that made your holiday possible that you've saved up for the rest of the year with no restitution that I'm aware of in any jurisdiction. They can confiscate 'evidence' (any computer and (backup) storage media in your house) for years. They can do a heck of a lot that's more annoying than medium amounts of wrench swinging

And as for street thugs, sure it won't be a wrench, more likely they'll flash a knife and unkindly suggest you remove the lock screen

Taken as a metaphor rather than a literal wrench, you don't think it's accurate?


> A government can trivially and legally make you miss the itinerary that made your holiday possible that you've saved up for the rest of the year with no restitution that I'm aware of in any jurisdiction. They can confiscate 'evidence' (any computer and (backup) storage media in your house) for years.

This could be preferable to handing over private data about contacts, communications, sources, client information, etc. Especially if it has life-changing implications for yourself or other people!


The wrench attack is still far weaker than a push-button attack.

In the wrench attack you are aware that you have been attacked, and you're aware of what data the attacker gains.

Additionally there are schemes like deniable encryption which can mitigate the outcomes of such an attack or serve as a red herring.

Furthermore it's dependent on physical intimidation which is expensive to scale and can be met with your own physical intimidation. In order for a wrench attack to scale to an entire society you have to send the gestapo to everyone's house whereas push-button attacks scale by default unbenownst to the victims and enable more nefarious systems to be built on top of them. In the USA this would mean interrogating some well armed citizens.

Lastly, you aren't forced to give up the key by any means. They can torture you to death and there is nothing they can do if you don't want to give up the key. There are some secrets in the game of love and war that are worth taking to - it's why spies are equipped with cyanide pills.


Missing a holiday is usually not such a bad price to save you from whatever the government is considering doing to you.


The United States has famously shot and killed protesters in the Vietnam war era. They have dedicated torture facilities for people suspected, not even convicted, of terrorism. Police officers use lethal violence for no reason every month and rarely get more than a talking to.

In a perfect society, your point makes sense, but I don't see why the authorities in the real world would need to care about committing a worse crime.


They have killed ice protestors in the open, murderers weren't even investigated.


The point of the comic is pretty obviously to make fun of the expectations of cryptography geeks; you know, the sort of people who use 4096 bit RSA keys for the coolness factor. It is a stretch to imply it is suggesting that encryption is somehow futile.


It's nowadays a $10 wrench.


You end up getting hit by a wrench though, that doesn't sound like it ends well for you.


If you're that much of a coward, you won't get hit by a wrench anyways because you will give your keys up immediately. But you will force your enemy to exert additional effort.

It works for the same reason locks on houses work against cops or criminals, despite the existence of lockpicking and locksmiths. There are various layers of physical security, and while no layer can prevent an attack absolutely they each increase the cost of an attack.

The system is only as secure as it's weakest layer.

So in a mixed information/physical system like a smartphone why should we allow the weak point to be the information system? To improve the information system we need only to rewrite the software, so the per-unit cost is nothing in the large.


Liberty is given up in inches, not miles.

The offenses of a regime at its apex would've led to it being stopped had they started out that way, but they didn't.

What you've hit on is the basic problem of treating privacy as a means to an end though: no level of it protects you from fascism, but it is a means by which fascism can be opposed - in many cases at personal cost to yourself.

In theory I have no secrets, and the contents of my phone or life if public would be of no consequence to me. In practice, when the regime starts flustering itself that I have no secrets for them to reveal the hopefully people will oppose it - or I get a decent warning that it's time to bail.


Sounds like something a coward would say, honestly.


Everyone thinks they're brave until they get punched in the face. The fact that a handful of terrorist attacks decades ago were all it took to push society into voting for control freaks who built a worldwide surveillance state to nanny them tells me all I need to know about how brave people really are.


Cool feature, but I'm a little uneasy with UPDATE operations adding new rows to a table. It upsets a lot of a DBA's assumptions.


Tech dependence is nothing compared to the world's dependence on US financial infrastructure.


Hasn't really been true for the past few years with a whole separate infrastructure emerging around BRICS Now.


The EU has a plan to replace all of that in the pipeline already. That isn’t new, they are already like 5 years into it and I think looking to launch it next year. That one I actually don’t think is going to be a problem at all as a lot of it is already built and basically ready to go.


Infineon sales piece.


Corporate IT needs to die.


It's not corporate IT's fault, it's usually corporate leaderships fault who often cosplay leading technology and not understanding it.

Wherever Tech is a first class citizen and seat at the corporate table, it can be different.


Sometimes they have checkboxes to tick in some compliance document and they must run the software that let them tick those checkboxes, no exceptions, because those compliances allow the company to be on the market. Regulatory captures, etc.


Believe me, the average Fortune 500 CEO does not know or care what “SSL MITM” is, or whether passwords should contain symbols and be changed monthly, or what the difference is between ‘VPN’ and ‘Zero Trust’.

They delegate that stuff. To the corporate IT department.


But they also say "Here, this is Sarah your auditor. Answer these questions and resolve the findings." - every year

It's all CyberSecurity insurance compliance that in many cases deviates from security best practices.


This is where the problems come from. Auditors are definitely what ultimately causes IT departments to make dumb decisions.

For example, we got dinged on an audit because instead of using RSA4096, we used ed25519. I kid you not, their main complaint was there wasn't enough bits which meant it wasn't secure.

Auditors are snake oil salesman.


This is 100% it- the auditor is confirming the system is configured to a set of requirements, and those requirements are rarely in lockstep with actual best practices.


where else are you going to find customers that are so sticky it will take years for them to select another solution regardless of how crappy you are. that will staff teams to work around your failures. who, when faced with obvious evidence of the dysfunction of your product, will roundly blame themselves for not holding it properly. gaslight their own users. pay obscene amounts for support when all you provide is a voice mailbox that never gets emptied. will happily accept your estimate about the number of seats they need. when holding a retro about your failure will happily proclaim that there wasn't anything _they_ could have done, so case closed.


Oh yes you can absolutely profit off that but you have to be dead inside a little bit.

And produce a piece of software no one in the world wants and everyone in the world hates. Yourself included.


I think the general idea/flow of things is "numbers go up, until $bubble explodes, and we built up smaller things from the ground up, making numbers go up, bloating go up, until $bubble explodes..." and then repeat that forever. Seems to be the end result of capitalism.

If you wanna kill corporate IT, you have to kill capitalism first.


I’d say there’s nothing inherently capitalist about large and stupid bureaucracies (but I repeat myself) spending money in stupid ways. Military bureaucracies in capitalist countries do it. Military bureaucracies in socialist countries did it. Everything else in end-stage socialist countries did it too. I’m sorry, it’s not the capitalism—things’d be much easier if it were.


Maybe military people are just uniquely stupid


Not at all, no. I gave that example because, first, even in a profoundly capitalist country (whatever that means) the military itself is not particularly motivated by profit; and second, because it’s one of the few bureaucratic organizations that will not (be allowed to) collapse under the weight of its own inefficiencies and so easily grows much larger than is othetwise typical.


I don't believe that. I don't necessarily love capitalism (though I can't say I see very many realistic better alternatives either), but if HN is full of people who could do corporate IT better (read: sanely), then the conclusion is just that corporate IT is run by morons. Maybe that's because the corporate owners like morons, but nothing about capitalism inherently makes it so.


> corporate IT is run by morons

playing devil's advocate for a second, but corpIT is also working with morons as employees. most draconian rules used by corpIT have a basis in at least one real world example. whether that example happened directly by one of the morons they manage or passed along from corpIT lore, people have done some dumb ass things on corp networks.


Yes, and the problem in that picture is the belief (whichever level of the management hierarchy it comes from) that you can introduce technical impediments against every instance of stupidity one by one until morons are no longer able to stupid. Morons will always find a way to stupid, and most organizations push the impediments well past the point of diminishing returns.


> the problem in that picture is the belief (whichever level of the management hierarchy it comes from) that you can introduce technical impediments against every instance of stupidity one by one until morons are no longer able to stupid

I would say the problem in the picture is your belief that corporate IT is introducing technical impediments against every instance of stupidity. I bet there's loads of stupidity they don't introduce technical impediments against. It would just not meet the cost-benefit analysis to spend thousands of tech man-hours introducing a new impediment that didn't cost the company much if any money.


It's because corporate IT has to service non-tech people, and non-tech people get pwned by tech savvy nogoodniks. So the only sane behavior of corporate IT is to lock everything down and then whitelist things rarely.


Apparently capitalism doesn’t pay enough for corporate IT admin jobs.


This rules out some extremely useful sparse memory tricks you can pull with massive mmaps that only ever get partially accessed (in unpredictable patterns).


Zscaler enrages me with their use of the term "zero trust" in marketing, because due to their MitM-ing of TLS, they become a single-point-of-interception for all your organisation's traffic. "100%-trust" would better describe it for me, as you have to have 100% trust of Zscaler and anyone who has admin access to your organisation's Zscaler account.


Using nix to install Ansible, oof you're hurting me..


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: