Hacker News new | ask | show | jobs
by sph 21 days ago
In computer security, never attribute to ignorance that which is adequately explained by malice.
2 comments

Dunno, if I were to backdoor a piece of my code, I would definitely put in an exploit instead of a deliberate bypass.

Plausible deniability is important.

A lot of the stuff I worked on already had glaring issues like that without me having to add it..

You’ve got the saying backwards:

“Never attribute to malice that which is adequately explained by stupidity.”

https://en.wikipedia.org/wiki/Hanlon%27s_razor

Pretty sure the point was to invert it. :)
Yes, I got their point. My point is that’s the opposite of reality.
His point is that in security, the opposite applies. The supposed "incompetence" is just plausible deniability for a malicious act.
Yes, and my point is that hasn’t been the case in my experience.
It's because you (like me) aren't quite as paranoid as security people are. Personally I couldn't sleep at night if I was security people.

It's really a matter of context. Security people tend to only be involved when things are already nefarious where as boring old normal people like us see get to see the mundane everyday mistakes so not just the nefarious bits.

The main reason I assumed you didn't is because you linked to Hanlon's Razor and explained it in a way that made it seem like you didn't think the other person knew.

I think it's true to some extent that a lot of the backdoors really are just stupidity, like debugging tools put into prod for convenience. Rather than suggesting that it is genuine malice, maybe the right thing to say is that for security, it doesn't matter whether or not it is malice for most purposes. If it did, it would give more incentive to do as much as possible to disguise malicious backdoors as mistakes.

Maybe it's time to take a closer look at reality and correct this meme, which might casually blur the issue and deflect responsibility?

Looking at the IT security landscape we see every layer, every product category if not every product itself riddled with issues at one point or another. At the same time the incentives to put those security issues in are huge, and we know attackers work systematic, creative and persistent to introduce those weak points.

Security is hard and many bugs certainly happen due to mistakes, but I wouldn't assume that all of those security mishaps stem from an endless series of blunders from "stupid" programmers.

So I would go with “Never attribute to ignorance that which is adequately explained by malice.”

> I wouldn't assume that all of those security mishaps stem from an endless series of blunders from "stupid" programmers.

The saying doesn’t mean that all vulnerabilities are blunders. It means we shouldn’t automatically assume vulnerabilities are nefarious.

If closer inspection proves beyond reasonable doubt that it was placed there deliberately and maliciously then that’s different.

But the point is most vulnerabilities are blunders so it’s better to assume that until proven otherwise.

It's usually not possible to prove that something was put in deliberately and maliciously, so that puts the bar very high. We know it for sure in some of the supply chain attacks, and should assume that other kinds of bugs are being introduced by malicious actors across the board, rather than to risk downplaying the issues to "just blunders".
Looks like this time you interpreted the message in a malicious way.
How? Neither their comment nor mine have anything malicious in their tone nor content.
Unfortunately, explaining a joke won’t make it funny afterward I guess.
As someone who really doesn’t take themselves even the slightest bit seriously, if there was ever a chance that your comment was funny then I would have realised it was a joke. ;)