News: 1601651707

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Complexity has broken computer security, says academic who helped spot Meltdown and Spectre flaws

(2020/10/02)


Complexity has broken cybersecurity, but a reappraisal of computer science can keep us safe.

So says Daniel Gruss, assistant professor in the Secure Systems group at Austria's Graz University of Technology. Gruss and his colleagues discovered some of the biggest recent security snafus, including the [1]Meltdown and Spectre microprocessor design flaws, a working [2]Rowhammer exploit, attacks on Intel SGX including [3]Plundervolt , and many more besides.

Speaking at the Black Hat Asia conference, held virtually on Friday in the Singapore time zone, [4]Gruss outlined his belief that while it is possible to make a system provably secure – with great effort – this is seldom done in production, and in any case, the world has become accustomed to using mazes of interlinked, unproven, and often not-publicly-documented systems.

We'll have job security for everybody working in security analysis. I suppose that is a good thing.

The resulting complexity makes it hard to say all parts of a system are secure because it is composed of many subsystems, and all of their possible interactions cannot be considered or secured. Even if the design faults buried in that thicket of systems require the deft investigations that Gruss and his colleagues have used to hunt for subtle side-channel data leaks, the insecurity remains.

The assistant professor also advanced his theory that as Moore's Law runs out, we'll use more and more systems with more and more processor and accelerator cores all interacting with each other, which means even more security risk. Building simpler systems is not an option, he believes, because humanity now has an expectation of pervasive, high-performance computing.

All of which lands us in a world where individual systems are not secure, interactions among them can't be secured, we build and link more computers every day even though we know that just increases risk, and we can't or won't change.

Happily, Gruss thinks there's a way to stop that mess of contradictions proving catastrophic.

His first suggestion is that computer science needs to change. Today, he said, the subject is considered a formal science. Gruss said that needs to change, for two reasons.

For starters, he said, the complexity of computers and networks now approaches that of structures, organisms, and populations seen in biology. His other reason is that adopting empirical methods is a better way of testing systems and their interactions. "Our systems are getting more and more complex so we have to invest more and more time into studying them like nature," he said.

[5]

Gruss's three takeaways from his Black Hat Asia talk ... Click to enlarge

Gruss thinks that may be good news for security pros because the world will clearly need more of them, and plenty will have new skills to learn. "In 30 years I would expect we have more people studying and analysing systems, and more variety of security jobs," he told the virtual event.

He also hedged a little, saying it's not yet possible to predict the perspective from which we will need to assess security in the future.

Woo-yay, Meltdown CPU fixes are here. Now, Spectre flaws will haunt tech industry for years [6]READ MORE

"Without the internet, ransomware would not flourish as well as it does," he said, illustrating how a change in usage patterns can bring about completely unforeseen problems.

He also suggested that insurers will therefore have more of a role to play because the empirical method may reveal more risks. And insurers do love designing products that ameliorate risk. Insurance cannot, of course, reduce the need for vigilance.

"We'll have job security for everybody working in security analysis," Gruss said. "I suppose that is a good thing." ®

Get our [7]Tech Resources



[1] https://www.theregister.com/2018/01/02/intel_cpu_design_flaw/

[2] https://www.theregister.com/2017/10/05/rohwammer_defences_defeated_by_opcode_flipping/

[3] https://www.theregister.com/2019/12/10/intel_sgx_youve_been_plunderstruck/

[4] https://gruss.cc/

[5] https://regmedia.co.uk/2020/10/02/daniel_gruss_blackhat_screenshot.jpg

[6] https://www.theregister.com/2018/01/05/spectre_flaws_explained/

[7] https://whitepapers.theregister.com/

Hmm...

Snake

So it takes an "expert" to state the obvious before people will believe in it, even though [1]I've been saying it for more than quite a while now . It is not a surprise, the only "surprise" is that this, being so obvious, wasn't an acknowledge truth throughout the tech world - the arguments of "this system is more secure that that!" would have been far less...astringent...because fundamentally no system is "secure" as we simply can no longer examine all possible system interactions of hardware, firmware and software. The best that we, as failure-prone humans, can strive for, is "best try".

[1] https://forums.theregister.com/forum/all/2020/08/07/qualcomm_chips_brimming_with_somewhat/#c_4086209

Re: Hmm...

Anonymous Coward

But as things get more and more complex, the risks involved with them will only increase, to the point that the overall risk (especially when taken in compound again and again) starts becoming too high to ignore? Plus, all these systems are raising the potential damage should something get through, meaning even a low risk can't be ignored if the damages from that risk occurring are high enough to worry.

Re: Hmm...

Version 1.0

While I'd agree that no system is "secure" there are systems that have virtually never been hacked, e.g. CP/M, RT11 and RSX11M etc. One factor that the article mentions is that these were small systems, it's a lot easier to secure a system that's 10k, 100k, or 5Mb, than an operating system like Windows 10 needing 15Gb to install. The bigger the operating system is then the more opportunities for holes.

Even if the operating system is 100% secure, you can't install an application, or access the internet, without risking completely compromising your security.

El Reg - I'm still waiting for a new icon (a pair of wire cutters) to define security!

Re: Hmm...

a_yank_lurker

No system that has connections with the outside world is truly secure; some are more secure than others. This even true in biology and the paper based world. At best you have a defense in depth that is sufficiently robust to give you time to react and stop the attack.

Doctor Syntax

"the complexity of computers and networks now approaches that of structures, organisms, and populations seen in biology"

For some value of approaches.

As has been said for some time ...

Captain Kephart

In 400BC Herodotus said "If one is sufficiently lavish with time, everything possible happens" ...

Which somehow feels relevant? Anyway, great quote!

Ciao, Captain K

PS: On those formal systems, anyone read Gödel's 'Incompleteness Theorem' recently ... it proves, rigorously, that absolute security was NEVER achievable ... see: https://en.wikipedia.org/wiki/G%C3%B6del%27s_incompleteness_theorems

Seems that this article prizes hindsight.....just what we need!!!!

Anonymous Coward

Quote: ".....possible to make a system provably secure – with great effort ...."

*

No mention of the relationship between risk and effort? As in -- the higher the risk, the greater the need for security resources.

*

Which begs the question: Is anyone doing comprehensive risk analysis? Say at Intel? Or at Amazon? Or at Equifax?

*

Just saying!

Recurving:
Leaving one job to take another that pays less but places one
back on the learning curve.
-- Douglas Coupland, "Generation X: Tales for an Accelerated
Culture"