Any IT device can be hacked. We completely missed the evolutionary opportunity to have secure computing devices. Proper object capability machines would make it possible. But quick and dirty and by Friday is what we got instead.
Technology
A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.
Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.
Subcommunities on Beehaw:
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
A security advisor at work recommends migrating to SaaS so we don't have to manage any of the infrastructure. This makes me wonder.
These topics often get "why is it even connected to the internet" comments. This makes me wonder if they're buying a "complete system solution" where it's not an operator decision but a manufacturer decision, and maybe even reasonable in regards to generally being accessible and manageable, with critical systems separated within the whole-bundle system. But often, the necessary safeguards and system separation are not in place anyway. Offloading responsibility doesn't mean it gets done well, unfortunately.
A security advisor at work recommends migrating to SaaS
The security advisor doesn't care about handling security. He cares about handling the responsibility of a security fuck-up.
SaaS sucks. Outsourced IT is only good for the vendor not the client signing up for it.
That's so ironic. Remember stuxnet. This could even be some false flag attack.