5 ms·
CAs are a horrendous weakness, but are still a "pillar" weakness and not even a "base" problem. In other words the threat exists not because of a base technolog
by nonrandomstring 1y ago
CAs are a horrendous weakness, but are still a "pillar" weakness and
not even a "base" problem. In other words the threat exists not
because of a base technological capability or necessity, but because
we _choose_ to stick our fingers in a blender and play with the
switch. Like the liquidity deadlock persisting the post 1929
depression these things happen because humans, collectively are
clinically insane in surrendering before systems (hubris, pride,
social control). No one dares to override the system. In reality
decisive emergency action can mitigate such sticky situations.
We also worry about existential threats from "class" points of
weakness. Like a mathematical breakthrough that makes factoring large
primes or mapping elliptic curves trivial. Again here, one can imagine
that were it possible to entirely switch-off encryption and return to
early 1990s operation, even a catastrophic class failure would not be
that bad - we'd just have a massive cybercrime and infosec problem
instead of a systemic failure.
Real dangers come from systems where logical regression is strictly
not possible. A base weakness like a backdoor or fault in every ARM or
Intel processor that could brick half the devices on Earth is a likely
cause of widespread civic harm - because it could be unrecoverable,
turning devices into e-waste overnight. Crowdstrike had a flavour of
this because it reminded us that computers are actually pieces of
hardware in data centres that can need manually rebooting or need
human physical intervention at scale.