Hacker News new | ask | show | jobs
by adricnet 3642 days ago
In line with the principle of charity I'd like to point out that your declaration here that network IDS provides only "minor cost savings" is controversial to the point of almost being aggressive towards folks working in information security. In the same vein, I'm simply disregarding the politically charged motive you assign to the technology.

If that was your intent (to start a political argument), then so be it, but if instead of picking a fight you would like to understand the problem space better there are plenty of smart folks on HN and elsewhere who can provide use cases and data ... to say nothing of vendors who will argue from either side depending on what they are selling.

hth, adric

2 comments

Well, I removed "minor cost savings", because even that is being too charitable. Silicon is cheap, and it wouldn't take much of it to create a separate network processing domain on each node, which would perform all the functions of an IDS on cleartext, but working for the node's owner rather than whomever supplies them network transit. It's also better security with regards to heterogeneous nodes, telecommuting, unenumerable Internet links etc.

Information architectures can't help but being simultaneously technical and political. The original "End to End principle" came out of utterly technical concerns. But codified into a principle, it becomes "political". This is inevitable, because the drawbacks of poor engineering aren't felt immediately, and in fact can be quite beneficial in the short term.

There are of course plenty of vendors selling top-down "security". Right in this paper, they say "the market for such DPI devices is expected to grow to over $2B by 2018". Power tends to centralize until it collapses, which is why we as individuals must work to rebuke such trends.

Actions can be deeply political, weither you acknowledge that fact or not. Do you think providing dpi capabilities to nations like china, where the information is used to tourture and kill people is in any way politically neutral?

Closing your eyes and pretending the politics don't exist dosen't make them go away.