60 likes | 153 Views
Outrageous Opinion: Nothing We Do Can Improve Security. Edward W. Felten Secure Internet Programming Lab Dept. of Computer Science Princeton University. The Lesson of Anti-Lock Brakes.
E N D
Outrageous Opinion:Nothing We Do Can Improve Security Edward W. FeltenSecure Internet Programming LabDept. of Computer SciencePrinceton University
The Lesson of Anti-Lock Brakes •Anti-lock brakes (ABS) were supposed tomake cars safer.•But people with ABS just drove faster, and closer together.•Result: no real change in accident rates•Users traded away safety for speed
Nothing We Do Can Improve Security •Security mechanisms will always beconfigurable by users.•Users trade off security vs. function•Typical user approach:–Maximum functionality; “good enough” security•If we provide better security, users willtrade it away for functionality.•Ergo, security will not improve
Objection:Security Isn’t “Good Enough” Yet •Not really an exception to the rule–“turned off” is a configuration choice•If we improve base-level security, peoplewill find riskier uses for systems•Invariant: most users operate at theragged edge of “secure enough”
Objection:We’re Still Doing Good • •Even if users trade away security, they’retrading it for something they value•But: tradeoff makes it even harder tomeasure how we’re doing•Maybe we’re actually doing a good job ?!?