Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Comment Re:Mr. shattered hope (Score 3, Insightful) 389

don't have a magical fix. My latest pet theory is that, at a Federal level, there should be a specified number of politicians. Rather than state-by-state, gerrymandered-district-by-gerrymandered-district, shit should be direct. Is there 3% of the US population who are pot-smoking tree-humping eco-dweebs? Then 3% of the politicians should be from the Nature Molestin' Party. Sure, we wouldn't have the 'hope and change' of meaningless party swaps over individual seats. We might get locked into some terrible shit if the majority of the country are, in fact, clueless assholes. But it'd be better representation.

A much "simpler" change (in terms of concept, not ease of execution) would be to go re-learn the concept of Federalism and take a bunch of power away from the Federal government and give it to state and local ones. The less the Federal government has responsibility over, the less harm unaccountable Congresscritters can do.

Comment Re:Seems reasonable (Score 4, Insightful) 119

everyone accepts that (for a given purpose; bank vaults and nuclear installations get judged differently than houses) there is some level of 'reasonable security', which reflects appropriate caution on the policyholder's part; but is known to be breakable.

I agree with your post. I'll just add that a big problem with IT security is that companies cannot rely on the same level of protection from governments in preventing intrusion.

For example, if I have a safe in my house, the means an attacker would have to penetrate it are going to be limited. Since my township has police and neighbors that wander around, they can only spend so much time there before they're likely to be detected. They can generally only carry in stuff that will fit in the doors and is man-portable, since if they have to cut a hole in the house and lower their equipment using a giant crane somebody is likely to notice. If they want to use explosives they will have to defeat numerous regulatory and border controls designed to prevent criminals from gaining access to them, and of course they will be detected quickly. Some destructive devices like nuclear weapons are theoretically possible to use to crack a safe, but in practice as so tightly controlled that no common thief will have them. If the criminal is detected at any point, the police will respond and will escalate force as necessary - it is extremely unlikely that the intruder will actually be able to defeat the police. If the criminal attempted to bring a platoon of tanks along to support their getaway the US would mobilize its considerable military and destroy them.

On the other hand, if somebody wants to break into my computer over the internet, most likely nobody is going to be looking for their intrusion attempts but me, and if they succeed there will be no immediate response unless I beg for a response from the FBI/etc. An intruder can attack me from a foreign country without ever having to go through a customs control point. They can use the absolute latest technology to pull off their intrusion. Indeed, a foreign military might even sponsor the intrusion using the resources of a major sate and most likely the military of my own state will not do anything to resist them.

The only reason our homes and businesses have physical security is that we have built governments that provide a reasonable assurance of physical security. Sure, we need to make small efforts like locking our doors to sufficiently deter an attacker, but these measures are very inexpensive because taxpayers are spending the necessary billions to build all the other infrastructure.

When it comes to computer security, for various reasons that secure environment does not exist.

Comment Re:Seems reasonable (Score 2) 119

If a company cuts corners on security, then in the same way that if I leave my door unlocked and get burgled, I can't make a claim. There's going to be a good living for lawyers establishing what is the required level of security. But if this incentivises senior managers to ask the right questions, then it's probably a good development.

Maybe. If you're buying an insurance policy to cover leaks of information, then almost by definition any claim is going to be the result of lax security. So, why bother buying insurance at all if the insurer can get out of it? The likely result is that those harmed won't be able to collect damages since there will be no insurance, and the company that lost the data will simply declare bankruptcy.

I think there are better precedents. For example, my company is routinely audited by its insurers or other certification bodies. If they spot a blocked electrical panel, that has consequences for the company. The purpose of the audits is to PREVENT bad things from happening, and of course passed audits will support later claims if something bad things happen anyway.

So, why not do the same with "cyber policies" or whatever they're calling them. The insurer states some standard that the policyholder is to be audited against. The policyholder agrees to be audited. If the audit passes, they're in the clear.

And that is what insurance is about - elimination of risk. If you are in charge of some big company you can get the blessing of the appropriate auditors and now it isn't you're fault if something bad happens. It is a bit like having an IT team with skin in the game.

Sure, you can hire what you think is a good IT security team, but how do you really know if you've gotten one? If you buy a cyber insurance policy you're getting that IT audit, but then if you're declared clean and you get burned anyway, that insurance company comes in and puts their money behind their words and pays for your loss. THAT is what insurance is supposed to be.

Comment Re:For those in Power,oversimplification is the Po (Score 1) 327

Plus, oversimplification can be used to justify all kinds of short-sighted behavior, with all the plausible deniability you describe.

I remember learning my company's brand of six sigma, and they stressed not having more than a few CTQs for any process. It made for really nice-looking powerpoint slides (which seemed to be the main output of my company's six sigma efforts). It also made for some really broken processes in some cases, because the stuff the company was making was really hard to make. There were cases where somebody would optimize out some $10 part and end up destroying a million dollars worth of product from time to time due to a failure to deliver an acceptable level of quality. But, when you only focus on 3-5 key quality attributes, it is hard to justify every little $10 part in the multi-million-dollar manufacturing process.

I'm fairly convinced that far more was lost in market share due to an inability to meet demand than was ever gained from optimizing out the odd $10 part.

"For every complex problem there is an answer that is clear, simple, and wrong."
--H. L. Mencken

Comment Re:New fangled technology (Score 2) 86

My 25-year-old Mazda* has a tape deck, and I'm perfectly happy with that. (Okay, I do have a minor quibble that there's no line-in port, but that's no big deal. At least it doesn't have a CD player instead; if that were the case then I'd actually have to get an aftermarket stereo.)

(*Don't knock it; it's very much on the "classic sports car" end of the spectrum, not the "old junky econobox" end.)

Comment Re:well that was sudden (Score 2) 206

That it got this far without being summarily rejected is problematic all by itself.

The FTC does not, and should not, do summary rejections. Even evil corporations have a right to due process.

In general I would agree with you, but not in this case. That they are natural monopolies would be grounds for a summary rejection. There's no reason that cannot be a special exception.

Comment Re:Corporate media doesn't act in public's interes (Score 1) 113

As to comedians being better at the news... no. Comedians are as good at science as they are at reporting the news. They talk about what they think is funny and what will get the crowd on their side.

In medieval Europe, it was only the court jester who could, without [much] fear, speak uncomfortable truths to the king.

You've sadly fallen into the trap of thinking the daily show is an actual news program.

You misunderstand me: I'm well aware that it's not. The problem is that the "real" news programs are much, much worse!

Comment Re:Played for a few hours and got bored (Score 1) 86

2) IRL it's very complex to value sprawling cul de sacs of suburban development. When first built they're great because the people who live there are the kind of people who almost never need the government, and have a fairly good income. If they weren't both they wouldn't be able to afford to buy into a suburb. This means a miniscule tax rate is enough to run the city. Then life happens, and 50 years later you've got houses designed to standards nobody wants, owned by people who were too poor to move out, which means that a) they need lots of government services, and b) they can't pay for those services with the miniscule tax rate, leading to c) the City Manager scrambling around to save the city while the long-time residents are convinced that it's still an upper-income enclave. Quite a few very smart people have pointed out that it's much easier to build new suburbs then build a new Brooklyn because of the way the Feds give out grants.

You missed out on (arguably) the most important factor, which is that suburban sprawl is a gigantic pyramid scheme.

When a developer builds a new subdivision, he not only pays to construct the infrastructure for it, but also spends a bunch of money on building permits and (theoretically) impact fees, which go into the city's coffers. (I say "theoretically" because some particularly short-sighted, pro-development cities might undercharge on the impact fees.)

Those fees are supposed to go towards maintaining and upgrading the rest of the city's infrastructure to pay for the development's impact, but they don't. Instead they get used to balance the budget this year. In a couple of decades when that subdivision's infrastructure needs to be repaired or replaced, where does the money come from? If the city is lucky, it comes from the impact fees of whatever new neighborhood is being built then. If not, then the city is screwed.

The growth of the suburbs really exploded around WWII, so we're just now really starting to see the consequences of Ponzi development. If you think older, inner-ring suburbs are in a bad state now (except for the ones that managed to gentrify, and have all those mid-century ranches torn out and replaced with McMansions), just wait. It'll get worse before it gets better.

Slashdot Top Deals

"If I do not want others to quote me, I do not speak." -- Phil Wayne

Working...