Hacker News new | ask | show | jobs
by rlt 964 days ago
Gentle reminder: the absence of evidence is not evidence of absence.
2 comments

> Despite what the expression may seem to imply, a lack of evidence can be informative. For example, when testing a new drug, if no harmful effects are observed then this suggests that the drug is safe.

https://en.m.wikipedia.org/wiki/Evidence_of_absence

Seems a very liberal use of the word “safe” unless I’m misunderstanding. It could mean either the drug is 100% safe, or that our methods of observation were insufficient to find the risk. Safe until proven unsafe and the class action lawsuits start, as it goes with many drugs.

Doesn’t seem like a particularly strong counter-argument, unless the point is that sometimes we humans like to err on the side of recklessness in the name of progress.

I think you are misunderstanding, the article doesn't just say "safe", the article says "suggests it is safe" (the "suggests" part implies not being 100% certain).
> , if no harmful effects are observed then this suggests that the drug is safe

or the harmful effects were missed, and the drug is dangerous

To be fair, evidence of absence is close to impossible in the space of infrastructure and network security.
As someone who's entire job is to maintain a gigantic qradar cluster (IBM won't sell us larger licenses), I sure hope 1p have to logs to back their claims because I know that it is possible that they do.
Full PCAP, process auditing and centralized logs are not only a thing, they have been for decades.

It just simply isn't worth the investment for CIO/CTO/CISO types because it isn't sexy. To say it's impossible is just factually inaccurate.

I know more than a few places doing 40gbps and 100gbps full packet capture for 30+ days. And relatively speaking, the investment isn't that large (for tens of petabytes it isn't as expensive as you might think).

We did this 5+ years ago at a managed hosting company, just for 3 days worth of data. Was still invaluable for figuring out complex events.
OTOH every tech CEO knows this and they always say "We have no evidence of compromise" right before they discover evidence of compromise