[PLUG] The lion in Salem
david pool
dpool at hevanet.com
Wed Aug 27 07:43:02 UTC 2003
Paul Johnson wrote:
> On Tue, Aug 26, 2003 at 03:04:02PM -0700, Cliff Wells wrote:
>>David, perhaps if you gave a reason for asking such things, people
>>wouldn't assume the worst. If I go to an airport and start asking
>>"innocent" questions about security, you can be certain it will raise
>>hackles.
>
> No kidding. I don't work an airport, but still there's questions you
> just don't ask if you don't want the nth degree. Like how many of us
> are on duty or what the coverage is.
I'm ok with the nth degree, but I think there are two approaches to
security. One is to discourage discussion and hope that one's
vulnerabilities go un-noticed. The other is to discuss stuff openly and
then take the precautions of the best minds available on the subject.
I think people who are afraid of the discussion or assume malice on the
part of those who ask questions are in the first camp. That camp's name
is "Security through obscurity".
Paul used the airport analogy. Let's extend it. If someone had gone to
the FBI before 9/11 and started asking questions about air defenses, yes
it would have raised hackles. Whether you think the asking of questions
would have then caused the 9/11 tragedy probably depends on which camp
you are in.
In general, Linux/Unix people have tended to prefer the second camp.
(whose name is... security through applied intelligence and testing?) In
cases of extreme national security, like Los Alamos, I think there's an
argument to be made for obscurity. But, it's a short term argument. Even
with full scale cold war type obscurity, the Soviets laid their hands on
the atomic blueprints within months of Hiroshima.
david
More information about the PLUG
mailing list