Wednesday, June 26

endpoint security

(Note: this post, and some of my adjacent posts, are scattered and disorganized - that reflects my knowledge of the underlying issues, and their secrecy)

One of the issues raised by Edward Snowden is that "endpoint security" is weak on our computer systems.

So what does that even mean? Why is it an issue?

For that matter, what is "security"?

(Here's an example of an insecure endpoint: http://forum.xda-developers.com/showthread.php?t=2048511)

One model of "security" is "death". If someone is dead, they are not a threat. This is dark ages stuff, but keep in mind that our morals and institutions were formed in the dark ages (or earlier).

A related model of "security" has to do with silence. This corresponds to "death" - a silent person is not that much different from a dead person, in some contexts. If a person is annoying you (or leading people against you) and you can get them to shut up, maybe you can stop them, or slow them. Or, for yourself, maybe you can sneak up on them (followed, presumably, by doing something so awful to them that they will then be silent, themselves).

Do we have anything better?

Our bodies have "pain nerves". These are slow, interior nerves which relay signals to our brains somewhat more slowly and more robustly than our regular nerves. If we receive information which is inconsistent between our different nervous systems, we perceive that as pain.  If you hurt yourself, and you pay attention, you will probably be able to notice a delay between when you are injured and when you start feeling pain.

This concept, I think, is relevant in security discussions. We do not need (or want) detailed security which is independent of our normal mechanisms for thought and action but we do need summary security information so we can tell when things are going bad.

Note also that a ton of political discussions are about inconsistencies between statements and actions.  (But most of that seems to be triggered by jargon differences and specialty differences - people talking past each other and not getting the other side's point of view - and only some of it seems to me to be triggered by what I perceive as "significant problems". Not that misunderstandings are not destructive - they are destructive.)

So, taking a concrete example - if I had hardware on my computer network interfaces which counted how many smtp requests my computer issued I would sometimes be able to just see if my computer was spamming people.  There are some problems with this example, but the key thing is "out of band" (or "unpredictable") awareness.

But I never really defined "security". In the context of computer systems, my definition of a "secure computer" is "the device is doing what the person responsible for the device thinks it's doing, and not doing things that the person responsible thinks it's not doing".

In other words, my concept of "computer security" sounds very like "education" or "knowledge". And, it's related to the computer UI principle of "least surprise". Of course, it's also related to death - for example, dead people can't be surprised (or at least, that seems to me to be difficult).

So I'm going to say something that might surprise some people. This is not me violating any security principle, this is me taking someone (maybe you, maybe not) from a slightly less secure state of existence:

Computers are electronic gear. That means they radiate information. We take advantage of this in building our computer networks (and this is related to things like radio broad casting, tv broadcasting and cell phones), but they also radiate information in other less efficient ways, just of because what they are. It's possible to design a system to mostly eliminate this kind of radiation, but this is expensive and no one cares to pay for that.

So, from my point of view, if you want to be secure, in a medieval sense (silence, or death), you will not be using a computer. If you want to be secure in a more modern sense, you will educate yourself on how your computer works. This doesn't need to be detailed knowledge (though that can be a very good thing), but it should be something.

So, exercise: find a way of detecting whether your computer is broken and see if it triggers when exposed to a threat. (This seems like a huge waste of time, since if things go wrong you might need to recover from backups and maybe your backups are broken.)

Exercise: how do you recover a compromised computer system (reboot! reinstall stuff! throw it away and get a new one!) ... hopefully you can talk with someone who has an interest in fixing your system and a good track record of having done so.

That said, nowadays, it's probably wise to assume your system is already compromised and work on ways to detect what's broken and how to fix it. And, then, try to track down the source and make it stop - hopefully without resorting to medieval measures.

So... why are medieval measures bad? isn't silence a good thing? And, no, I don't think it is - remember, we detect when things are wrong by looking for inconsistencies. Inconsistencies alone do not tell us what's wrong nor how to fix it, but they start the process. And silence does not make things consistent.

Meanwhile, modern computer systems and communication systems allow us to be sensitive to inconsistencies, and our reaction to non-networked peoples is a sort of numbness - they do not interact with us. If it's deep enough, we might not even notice, and there's some unpleasantnesses (and, fortunately, pleasures) in encountering other people's points of view. But in a modern well connected society, hiding is a lot harder than it used to be. And this is probably a good thing. But I think we need to something like tolerance to replace this lack of privacy.

So... endpoint security?

First, you need the endpoints (e.g. a cell phone or a computer). If it doesn't exist, that's not secure (except in a medieval sense).

Second, whoever is responsible for an endpoint needs to understand that endpoint. So this means that our computer systems need to be designed to educate the user about the system (at a sustainable and reasonable pace).

* * * * *

rules of the internet, derived from http://notabug.com/2002/drums-archive/3465:

Rule 1: You SHOULD be liberal in what you accept, and be conservative
        in what you produce.

Rule 2: You SHOULD NOT use potentially harmful constructs (even
        if they are allowed in the restricted case you are using them
        for).

Rule 3: You SHOULD NOT munge (do not change protocol you get and
        resend, in particular do not try to correct incorrect protocol
        elements).

Rule 4: Systems SHOULD be designed to educate the user about their function,
        and about how they are operating.

(The page I referenced just had the first three rules and did not mark the rules as "SHOULD" rules. These are "SHOULD" instead of "MUST" because all of these issues require judgement calls.)

* * * * *

Looking for a reference that expresses what I want to say, I found this:

http://www.veteranstoday.com/2012/11/26/greatest-threat-to-democracy/

"Greatest Threat To Democracy

Is it ignorance or apathy? Hey, I don’t know and I don’t care.–Jimmy Buffett"


* * * * *

Endpoint security is a problem because we have not been designing our systems to teach the user about key underlying abstractions. We need a more diverse set of awarenesses and cross specializations if we are going to have computer systems which do not surprise people.

And the "NSA"? They have problems, absolutely, and hopefully we and they can be honest enough for them to resolve their biggest problems. But if you care about privacy, I think that attacking the NSA because of their problems is like ripping a bandage off a bleeding wound because it hurts.

Restated: you have bought a computer that is compromised, and you don't even know it. "Fixing the NSA" won't make your computer be not compromised. And if you needed sensationalism to become aware of the issues?

And, as a bonus, understanding how things work is a great way to come up with ideas for being more productive, more useful and higher salaried. These ideas will not always work (and, if they are predatory you should expect to be slapped down, perhaps in an unfair fashion, and that slapping process might itself also be predatory and need to be fixed) but if they make people's live's better, that's a good good thing.

* * * * *

Another problem: At least 24 million people in the U.S. are unemployed (want jobs, do not have jobs, and have been without jobs for a short enough time to be on the records as wanting jobs), and these are frequently in rural areas (with low network access). If they were all connected we could perhaps talk them through solutions to their problems (finding people that need their help that can reciprocate, finding ways to get food, just being friends and loving them for being who they are).  And the scale of the problem outside the U.S. is much bigger.

So maybe it's important also to realize that we have bigger problems than "endpoint security".

* * * * *

This is just my current point of view. I expect that there will be people who do not connect with the ideas as I have expressed them here. I may change my mind at a later date.

Sunday, June 23

China and secrets?

(additions in italics.)

At the moment, I'm seeing a lot of suggestions that China is responsible for Snowden's actions.

If that is true, I think it might also be fair to claim that the U.S. intelligence structures (which NSA is a "visible" aspect of) is something that China is responsible for. China is known, after all, for its vast bureaucratic structures, for its love of secrets, and for its relatively stable civilizations. And, as a structure, the NSA (or, rather, the shadowy vastness which the NSA is a visible component of) seems to be a reflection of this kind of thinking.

So is this a good thing, or a bad thing? Or is that even the right question? (And is it even true? Note that we might blame the drug war on China - China, after all, was defeated by a drug war back in the 1800s and it's just natural that people will take a tactic which was successfully used against them and try to use it in their defense. On the other hand, it was a British tactic in the first place, and also we've been making major mistakes in our math both in the context of economic theory and in the context of medical theory.)

My current thought is that secrets make for inefficiencies. Sometimes inefficiencies can be seen as good (sales people typically like to keep their contact list secret, for example, because they do not want competitors to be more efficient than themselves, in dealing with the people that they have relationships with). Sometimes inefficiencies can be seen as bad (they do, after all, block certain kinds of actions and innovations).

I also find China's censorship system distasteful. I can understand some motivations that might be behind it (preventing discord, squelching falsehood, and/or exercising people's abilities to overcome adversities), and in some respects it's a fairly gentle system (it's slow, and people can often exchange information before it kicks in). Still, when combined with other things which cause fear, it conveys the message that the government might kill you if you say the wrong kind of thing. And I fear that that limits people's abilities and thoughts.  Also its most notable feature - the suppression of calls to action - is about government stability but also suggests a lack of tolerance for the exchange of ideas. And, most especially, it institutionalizes support for "editing history". And I think respect for history is crucial for the health of a nation. This feels to me like the difference between "learning from our mistakes" and "hiding our mistakes".

People try to solve problems which will prevent them from surviving.

Anyways... my thoughts on this subject are uncertain. Secrecy, after all, is enforced ignorance. Which seems odd, because ignorance is not something we have any shortage of.

On the other hand, privacy and secrecy go hand-in-hand - they are different words describing much the same thing.

But, also, over the long run, secrecy tends to erode, as does knowledge. We converge on a steady state where issues become exposed and details get lost. And I suspect that advances in communication techniques shift this steady state - new ways of expressing ideas allow for understandings which were not previously possible, and lack of support for older information storage formats allow for new ways for information to be lost.

It also seems to me that keeping strategies secret is a mistake. How do you even know if you are cooperating with a strategy if you do not know what it is? But operational secrecy - keeping secret the precise details of how you have implemented a strategy - can sometimes be a good thing. And this kind of thing is probably the distinction between "secrecy" and "privacy".

Meanwhile... about that "NSA" thing... it seems to me also that modern computer architectures leak information at a rate quite a bit higher than most people understand. People fall into the trap of thinking about "solutions" and don't quite realize the mechanisms being used. But computers are electronic mechanisms and they radiate quite a lot of information in the electronic spectrum in various ways. And, at a fine level of detail they execute sequences of instructions which only achieve a purpose in an aggregate and in a context.

So, from my point of view, the "NSA" has been trying to adapt to this situation without changing it. Their mission - stopping really outrageously horrid things - in some ways becomes easier and in some ways becomes harder with modern computer architectures and engineering. But you can't really operate without having some effects, both direct and indirect.

Meanwhile, we see the problems created by elaborate government secrecy more clearly, in the context of the NSA than we do in countries where it's just accepted that people are going to be doing secret things. And regardless of what the best way of doing things is, we have to live with the situation we find ourselves in.

So...

My current thought is we take advantage of the efficiencies that come from being aware of government secrecy. In the U.S.A. we should probably institutionalize this - U.S. courts are designed to be publicly visible, and our contribution to the world is based on our concepts of fairness and rights.

Of course, we have a long way to go, both within the U.S. and outside. We need to learn how to turn negative criticism into positive criticism. We need to re-engage in our economy those who have been lost to us through various mistakes in deregulation and banking. We have been trying to support a large number of other countries - supplying military to Germany and Japan because 70 years ago we did not trust them to supply their own but as a side effect removing that burden from their economies. But also we have been supplying food to a variety of countries, and so on. But we need to recognize that gifts alone are not a solution to problems (and that relates to our own internal struggles).

So... taking a few steps back, I'm going to say some things which I hope are not so obvious as to be annoying:

We need people engaged and active in trading for each other's benefit. We need children to be raised with adequate nutrition and good language and math skills. We need people thinking about real problems and not bored because they have been shielded from the things that matter to them. We need to respect and support those that work hard for our benefit, because our lives depend on them. We need to break out of the "enemy" mind sets where we view conflicts as something inherent in the person rather than the problem.

And here's one that I think should be obvious but seems to be sadly controversial:

We need to get rid of the idea that celibacy is a virtue - I think we should require that our leaders first be good parents.

Since I think that that one is controversial, I think I should try to talk a bit about the mechanisms and the social conflicts hiding behind that statement. But I am not a parent myself, so I'll just mention that issues include dealing with exhaustion, the ability to set relevant priorities, and an appreciation for our lives. (Note also that I am not particularly concerned about the genetic aspects of parenting, I am more concerned about supporting and valuing children (and the elderly, for that matter) - I think that if we can't sort out these issues for ourselves that we should not be telling other people what to do with their lives.)

Anyways, back to national secrets.

My current thought is that strategic secrecy is harmful but that operational secrecy is something we have to accept and allow for. My reasoning here boils down to: We simply do not have the brain power to comprehend all that goes on at a detailed level, and we have visceral needs for privacy (albeit, socially constructed needs) but if we don't agree about some things at some general level we can't even make sense of what we are saying when we talk with each other.