[PLUG] The lion in Salem

david pool dpool at hevanet.com
Wed Aug 27 07:43:02 UTC 2003


Paul Johnson wrote:
> On Tue, Aug 26, 2003 at 03:04:02PM -0700, Cliff Wells wrote:
>>David, perhaps if you gave a reason for asking such things, people
>>wouldn't assume the worst.  If I go to an airport and start asking
>>"innocent" questions about security, you can be certain it will raise
>>hackles.
> 
> No kidding.  I don't work an airport, but still there's questions you
> just don't ask if you don't want the nth degree.  Like how many of us
> are on duty or what the coverage is.

I'm ok with the nth degree, but I think there are two approaches to 
security. One is to discourage discussion and hope that one's 
vulnerabilities go un-noticed. The other is to discuss stuff openly and 
then take the precautions of the best minds available on the subject.

I think people who are afraid of the discussion or assume malice on the 
part of those who ask questions are in the first camp. That camp's name 
is "Security through obscurity".

Paul used the airport analogy. Let's extend it. If someone had gone to 
the FBI before 9/11 and started asking questions about air defenses, yes 
it would have raised hackles. Whether you think the asking of questions 
would have then caused the 9/11 tragedy probably depends on which camp 
you are in.

In general, Linux/Unix people have tended to prefer the second camp. 
(whose name is... security through applied intelligence and testing?) In 
cases of extreme national security, like Los Alamos, I think there's an 
argument to be made for obscurity. But, it's a short term argument. Even 
with full scale cold war type obscurity, the Soviets laid their hands on 
the atomic blueprints within months of Hiroshima.

david





More information about the PLUG mailing list