Published Jul 15, 2024

The six dumbest ideas in computer security (News)

Adam Stacoviak and Jerod Santo dive into computer security's six enduringly flawed concepts, drawing from Marcus J. Ranum's critiques, while also questioning the use of story points in software development and reflecting on simplicity and collaboration in software engineering with insights from Poul-Henning Kamp's experiences.
Episode Highlights
The Changelog logo

Popular Clips

Episode Highlights

  • Overview

    In this episode of The Changelog, and revisit Marcus J. Ranum's 2005 post on the six dumbest ideas in computer security. They explore how these ideas remain relevant today, highlighting the industry's tendency to prioritize flashy solutions over common sense. notes that security practitioners should challenge conventional wisdom, as the current rate of system compromises suggests that traditional approaches are failing 1.

    Your job as a security practitioner is to question, if not outright challenge, the conventional wisdom and the status quo.

    ---

    The hosts outline the six ideas, including default permit, enumerating badness, penetrate and patch, hacking is cool, educating users, and action is better than inaction 1.

       

    Analysis

    The episode delves deeper into the absurdity of these ideas, particularly focusing on "default permit" and "penetrate and patch." criticizes the "default permit" approach, which involves granting permissions and seeking forgiveness later, as a flawed security strategy. adds that "penetrate and patch," where new code is used to fix old vulnerabilities, is a never-ending cycle that fails to address root causes 1.

    Dumb idea number one, default permit, which is giving permission and asking for forgiveness.

    ---

    These practices, they argue, reflect a broader issue in computer security where quick fixes are favored over sustainable solutions 1.

Related Episodes