// HACKER NEWS — CYBERSECURITY
Playing whack-a-mole is losing
I want to juxtapose two classes of people in the security industry on the defender side of security engineering for products. The first are the Security as Identity people. This goes back to the security-as-counterculture attitude, glamorized in Hackers and dating back to phone phreaking. It reflects Thompson’s “Workism”, where work is not just a way to earn a living, but a way to build a sense of identity, purpose, and community. In the case of security, this identity tends to be built around being different, seeing things other people do not, and being clever in an edgy and misunderstood way. Someone who is beyond merely a security professional, but has the persona of a Hacker. Stylish outsiders smarter than the system. Detectives finding insights others miss.
There’s nothing wrong with the hacker ethos. The idea of finding places where systems break down and work in unexpected or incorrect ways is obviously extremely valuable. Careers, conferences, and professional communities all reward vulnerability discovery, the more surprising the better. Similarly, the hacker aesthetic is what it is. At this point, it’s mainstream. Around 25,000 people attend DEF CON each year.
Valuing unexpected insights is not only a hacker thing. In the 2000s, the book Freakonomics was extremely popular. It also took the form of proposing surprising explanations for seemingly straightforward or otherwise unremarkable social phenomena. If you can find something unexpected, you must be very smart and cool! But should surprise really be a signal of intelligence? You can take that attitude even farther, and do a Paul Graham style “it turns out” misdirection. Instead of saying you believe in Y, say you expected X, investigated, and it turns out that Y is true. That way, you don’t have to justify Y, you just say X is false.
The identity you choose matters beyond aesthetics. Problem definitions inherently carry an associated worldview, and it’s very difficult to change a worldview, particularly if you’ve built your identity, community, and profession around that worldview. Evidence for solutions that address the underlying problem, but not in a way that validates the worldview, can be rejected. As a concrete example, Nordhaus and Shellenberger address this failure mode for climate change activism in their notorious “Death of Environmentalism” essay from 2004. Environmentalists wanted to get people to agree to protect “the environment” as a supposed “thing”, a special interest deserving of good, that should have technical policy interventions in order to advance it, specifically. This meant solutions needed to take the form of being related to “the environment”, like cap-and-trade and carbon emission limitations. Solutions that resulted in the desired outcome of less greenhouse gases, but were not sufficiently “environmental”, such as decreasing clean energy costs (even with increased usage), higher-yield agriculture (not just organic farm-to-table), and the idea that technological substitution can work better than behavioral modification, were rejected. Ironically, in the two decades since the controversial essay, we can see that many of these rejected solutions are the ones ultimately played out. Improvements in solar and battery technology, alongside electric cars and other renewables, many of which had government subsidies in the 2010s, did more to reduce greenhouse emissions than the policies that validated the accepted worldview of environmentalism in the 2000s.
In security, solutions that do not look like repeatedly discovering, exploiting, and patching technically impressive vulnerabilities may be overlooked if they do not satisfy the worldview of the Security as Identity person, particularly if they would rather act as a detective than as a mechanic. An attacker mindset and a coherent threat model are important to building secure systems. But while necessary, are they complete? And are they even a good starting point? We do not teach people to