ars aranea. the web, the way we make it. | |
Post discussion# Hacking and the real worldPosted: Mar 13, 2008, under IT today, Security. Add a comment!I was reading an article by Adrian Spinei and, not for the first time, it made me think about how our society likes to consider computer hacking similar to physical aggression, invasion of personal space or privacy violations. It wouldn’t be so bad if just the uninformed masses had the wrong idea. But it doesn’t seem [...]
You can add a comment:
2 comments
| Important
Categories
Authoring
(1)Books (2)Cross platforms (2)DHTML (12)Graphical design (3)IT today (12)Morals&Politics (10)ODP (1)Random stuff (3)Romania (16)Security (7)SEO (2)Software (8)SQL (1)Standards (7)Technology (3)WordPress (4)[În română] (4)[This website] (2)Time-jump Syndication Need hosting?I've been a happy user of LunarPages since 2005. |
Copyright ©2005–2008 Zuavra | |
Why is the hacker penetrating a server more "ethical" than a common burglar entering a home ? Just because he's smarter ?!?
Yes in an ideal world doors cannot be broken, cars cannot be started without their keys and servers are correctly secured.
But we do not live in an ideal world, we live in a real one where we have to juggle with variables like cost, time, business competition, available human resources.
PS Banks' vaults get broken, too.
Hackers are not more ethical or noble than common thieves and I did say they should not be treated any better.
Yes in an ideal world doors cannot be broken, cars cannot be started without their keys and servers are correctly secured.
I do not want to lump these things together.
In the first two examples the burden of security is placed primarily on the user. That is largely unfair to them and a major disruption of normal life. We cannot live our lives in fear, and that is why societies have moved away from prevention and focused on punishing and recovery after the fact.
The digital world is different. It is possible to do security properly before anything bad happens. This is in fact how digital security should be done. Prevention and security by design are possible and should be enforced. And the burden on the user should be minimal.
It's a myth that proper security is harder or more expensive to do than the kind of half-assed "security" we get nowadays. It is in fact often easier and cheaper, both up front and in the long term. Those that would like you to believe otherwise are either self-interested, incompetent, or have to deal with legacy systems which were not designed properly to begin with.