Hacker News new | ask | show | jobs
by tekacs 1 day ago
This is completely backwards. Cybersecurity has an attacker-defender asymmetry that heavily, HEAVILY favors defenders.

For starters, a defender gets to pick the surface area, an attacker has to work with what they're given.

5 comments

The saying that stuck with me was "defenders have to be right 100% of the time, while attackers only have to be right once".

You are suggesting this isn't correct?

> a defender gets to pick the surface area

What do you mean? You don't pick what you need to defend. Unless you choose not to build a feature. But that's a product design choice... Not a cybersecurity strategy.

It's correct but defenders also choose where that happens. 100% of the time on the locations and conditions that the defenders choose / allow. As a defender i need to be right 100% of the time, sure, but i can make it so that the things i have to be right about are very well known to me, unknown to others, maybe even extremely unlikely to be to known by others, difficult to get to know, (...). So that saying is true but over simplifies the situation. I know monkey brain likes simple phrase. But monkey not live in savannah anymore. Need to adapt and open mind to complex.
Today’s surface areas are gigantic and many of them will - in a typical company - not be chosen by cybersecurity experts. How do I hide the physical location of an office that offers physical access to the company’s network? How do I hide which OS the company is using? How do I hide the underlying technology of customer-facing systems? How do I hide which SaaS services I use?
Very well said, thank you! The triple clause here is exactly what I mean.
> The saying that stuck with me was "defenders have to be right 100% of the time, while attackers only have to be right once".

> You are suggesting this isn't correct?

The intuition behind that is applicable only when correctness is stochastic. If you need to be waved in by a security guard, then one fake mustache might be the difference between being granted or denied entry. However, a keypad either works or it doesn't; entering the wrong PIN is guaranteed refusal.

The other breach of that intuition is defense in depth. Secure systems don't generally rely on a single binary trusted/untrusted status; the classified building still locks its interior doors. This is the part that has – in my view temporarily – changed most with frontier models, in that they are much more skilled at chaining together vulnerabilities than previous models (and much faster about it than human experts, even if potentially less skilled). If a system has a latent (0-day) vulnerability 50% of the time, then 10 independent layers would imply a ≈ 1/1000 chance that a critical compromise is possible.

However, these independent layers don't currently happen in practice because it's easier to write insecure code than secure code. With luck, modest discipline, and defensive use of frontier models I think that this gap will narrow with time, in much the same way that it would be plainly crazy to deploy root access via telnet today.

This is the same mentality that drives companies to sue cybersecurity researchers for exposing vulnerabilities in their software instead of fixing the software, or to insist on keeping software closed source for "security reasons".

If AI makes finding software vulnerabilities easier, then we should deploy it widely to find as many vulnerabilities as possible and fix them, not bury our heads in the sand and pretend the vulnerabilities don't exist as long as nobody knows about them. That's just the same "security by obscurity" strategy that has been tried and failed time and time again.

> "defenders have to be right 100% of the time, while attackers only have to be right once"

If you have an adaptive system that can react to attacks flexible (say, your own AI agent), then no, that's not correct. It is correct in the classical conception of cybersecurity where the defender is basically static.

Doesn’t this “adaptive system” just become part of the static defense? The same way that a bit of code that checks passwords against a db is “dynamic”, the options are either to beat the dynamic system (guess/phish a password, trick the AI) or find a way around it (use “forgot your password”, find a place that isn’t covered by the endpoint protection feeding the AI). I don’t see how inserting an agent somewhere fundamentally changes anything
It changes how many attempts you get until the attack surfaces changes to react to a failed attack, and it does so in a way that is not predictable to the attacker.
They downvote you cus you're right.
This makes no sense. Why do defenders get to pick the surface area? You can be attacked from anywhere.
I think the point you're trying to make is that you can always make your exposed surface area smaller

But that, of course, is not going to survive contact with reality

And here I thought management picked the surface area.
Not really, the only reason I (or any other programmer) haven't ever hacked into a system to make my life easier (not to do bad things) is because it's illegal.

It was always easier than making a system secure.