FHE would be nice, but there's a lot of products that could be E2EE today. Plenty of breaches are just server-side files and dumps, there's no excuse for not using E2EE cloud storage.
Databases are much more tricky, but if we're talking a significant shift, it is as good a plan as any. Clearly server trust is not working.
AI is accelerating both sides for defenders and attackers, but mobile clients are already way ahead of typical desktop. Android's desktop mode exists in the OS now but needs a lot of work and more powerful chips before it can replace desktops.
For security against remote attacks, I'd rank clients roughly: GrapheneOS, iOS/iPadOS, stock Android on Pixels, ChromeOS, macOS, Windows, desktop Linux. Prefer more secure clients, always, but now the client is all that's left to trust for content.
Native clients avoid the web E2EE problem and are easier than ever to build. With AI, you can audit the source as often as you want and reproducible builds mean you know that's what you're running.
Haha, we are ahead of you. We realised we were gonna get owned a long time ago, since business and engineering teams prioritised speed over security. And also that it is genuinely hard to secure everything.
This is why there are so many resilience initiatives in serious organisations. Assume it is gonna happen. Limit blast radius, ensure effective recovery.
... How does that change, from the security advice of 2008?
Pwn2Own was demonstrating no stack as secure back then, too. People were told defense in depth, recovery methods, rapid spin up and lockdown, for the last few decades.
AndrewKemendo · · focus · HN ↗
You need to find a new way to do business with the assumption that you’re 100% eventually going to get pwned
So just assume that going forward and you’ll start to rethink your architecture
Cider9986 · · focus · HN ↗
Databases are much more tricky, but if we're talking a significant shift, it is as good a plan as any. Clearly server trust is not working.
AI is accelerating both sides for defenders and attackers, but mobile clients are already way ahead of typical desktop. Android's desktop mode exists in the OS now but needs a lot of work and more powerful chips before it can replace desktops.
For security against remote attacks, I'd rank clients roughly: GrapheneOS, iOS/iPadOS, stock Android on Pixels, ChromeOS, macOS, Windows, desktop Linux. Prefer more secure clients, always, but now the client is all that's left to trust for content.
Native clients avoid the web E2EE problem and are easier than ever to build. With AI, you can audit the source as often as you want and reproducible builds mean you know that's what you're running.
AndrewKemendo · · focus · HN ↗
Overall though the point is any particular hole that you have will be exploited
so what used to be a game of “patch the hole” is going to need to change entirely
s0rrymybad · · focus · HN ↗
[dead]
MattPalmer1086 · · focus · HN ↗
This is why there are so many resilience initiatives in serious organisations. Assume it is gonna happen. Limit blast radius, ensure effective recovery.
shakna · · focus · HN ↗
Pwn2Own was demonstrating no stack as secure back then, too. People were told defense in depth, recovery methods, rapid spin up and lockdown, for the last few decades.