The myth of cyber-security

Computers will never be secure. To manage the risks, look to economics rather than technology
973 words

  1. COMPUTER security is a contradiction in terms. Consider the past year alone: cyberthieves stole $81m from the central bank of Bangladesh; the 4.8bn takeover of Yahoo, an internet firm, by Verizon, a telecoms firm, was nearly derailed by two enormous data breaches; and Russian hackers interfered in the American presidential election.

takeover: when one company takes control of another by buying more than half its shares
derailed: To derail something such as a plan or a series of negotiations means to prevent it from continuing as planned. (JOURNALISM)


  1. Away from the headlines, a black market in computerised extortion, hacking-for-hire and stolen digital goods is booming. The problem is about to get worse. Computers increasingly deal not just with abstract data like credit-card details and databases, but also with the real world of physical objects and vulnerable human bodies. A modern car is a computer on wheels; an aeroplane is a computer with wings. The arrival of the “Internet of Things” will see computers baked into everything from road signs and MRI scanners to prosthetics and insulin pumps. There is little evidence that these gadgets will be any more trustworthy than their desktop counterparts. Hackers have already proved that they can take remote control of connected cars and pacemakers.

extortion: Extortion is the crime of obtaining something from someone, especially money, by using force or threats.
baked: If you bake, you spend some time preparing and mixing together ingredients to make bread, cakes, pies, or other food which is cooked in the oven.
prosthetics: The branch of medicine or surgery that deals with the production and application of artificial body parts.弥补术,修复术
insulin pumps: A portable device for people with diabetes that injects insulin at programmed intervals in order to regulate blood sugar levels.胰岛素注射器
pacemakers: 心脏起搏器

2)除了这些头条新闻,一个利用电脑敲诈勒索,黑客雇佣和数字商品销赃的黑市正在蓬勃发展。问题即将进一步恶化。计算机不仅越来越多地处理诸如信用卡详细信息和数据库之类的抽象数据,而且还越来越多地涉及真实世界的物品和脆弱的人体。现代汽车是轮子上的电脑;一架飞机是一台带翅膀的电脑。 “物联网”的到来将会把电脑在所有东西上,从路标和核磁共振扫描仪,到假肢胰岛素泵。没有什么证据表明这些装置比台式机更值得信赖。黑客已经证明,他们可以远程控制联网的汽车和起搏器

  1. It is tempting to believe that the security problem can be solved with yet more technical wizardry and a call for heightened vigilance. And it is certainly true that many firms still fail to take security seriously enough. That requires a kind of cultivated paranoia which does not come naturally to non-tech firms. Companies of all stripes should embrace initiatives like “bug bounty” programmes, whereby firms reward ethical hackers for discovering flaws so that they can be fixed before they are taken advantage of.

wizardry: impressive ability at something or an impressive achievement
vigilance: careful attention that you give to what is happening, so that you will notice any danger or illegal activity
paranoia : an unreasonable belief that you cannot trust other people, or that they are trying to harm you or have a bad opinion of you
of all stripes/of every stripe: of all different types
whereby: by means of which or according to which


  1. But there is no way to make computers completely safe. Software is hugely complex. Across its products, Google must manage around 2bn lines of source code—errors are inevitable. The average program has 14 separate vulnerabilities, each of them a potential point of illicit entry. Such weaknesses are compounded by the history of the internet, in which security was an afterthought.

compounded: To compound a problem, difficulty, or mistake means to make it worse by adding to it. (FORMAL)
afterthought: something that you mention or add later because you did not think of it or plan it before


Leaving the windows open

  1. This is not a counsel of despair. The risk from fraud, car accidents and the weather can never be eliminated completely either. But societies have developed ways of managing such risk—from government regulation to the use of legal liability and insurance to create incentives for safer behaviour.

counsel: advice


  1. Start with regulation. Governments’ first priority is to refrain from making the situation worse. Terrorist attacks, like the recent ones in St Petersburg and London, often spark calls for encryption to be weakened so that the security services can better monitor what individuals are up to. But it is impossible to weaken encryption for terrorists alone. The same protection that guards messaging programs like WhatsApp also guards bank transactions and online identities. Computer security is best served by encryption that is strong for everyone.

refrain: to not do something that you want to do
encryption: the activity of converting data or information into code


  1. The next priority is setting basic product regulations. A lack of expertise will always hamper the ability of users of computers to protect themselves. So governments should promote “public health” for computing. They could insist that internet-connected gizmos be updated with fixes when flaws are found. They could force users to change default usernames and passwords. Reporting laws, already in force in some American states, can oblige companies to disclose when they or their products are hacked. That encourages them to fix a problem instead of burying it.

gizmos: a small piece of equipment - used when you cannot remember or do not know its correct name
disclose: to make something publicly known, especially after it has been kept secret = reveal


Go a bit slower and fix things

  1. But setting minimum standards still gets you only so far. Users’ failure to protect themselves is just one instance of the general problem with computer security—that the incentives to take it seriously are too weak. Often, the harm from hackers is not to the owner of a compromised device. Think of botnets, networks of computers, from desktops to routers to “smart” light bulbs, that are infected with malware and attack other targets.



  1. Most important, the software industry has for decades disclaimed liability for the harm when its products go wrong. Such an approach has its benefits. Silicon Valley’s fruitful “go fast and break things” style of innovation is possible only if firms have relatively free rein to put out new products while they still need perfecting. But this point will soon be moot. As computers spread to products covered by established liability arrangements, such as cars or domestic goods, the industry’s disclaimers will increasingly butt up against existing laws.

disclaimed: to state, especially officially, that you are not responsible for something, that you do not know about it, or that you are not involved with it = deny
moot: Without legal significance, through having been previously decided or settled.【法律】 不具合法意义的:没有法律上的重要性,通过先例决定的或解决的
butt up against : to hit or push against something or someone with your head


  1. Firms should recognise that, if the courts do not force the liability issue, public opinion will. Many computer-security experts draw comparisons to the American car industry in the 1960s, which had ignored safety for decades. In 1965 Ralph Nader published “Unsafe at Any Speed”, a bestselling book that exposed and excoriated the industry’s lax attitude. The following year the government came down hard with rules on seat belts, headrests and the like. Now imagine the clamour for legislation after the first child fatality involving self-driving cars.

excoriated : to express a very bad opinion of a book, play etc
lax: not strict or careful enough about standards of behaviour, work, safety etc = slack
fatality: a death in an accident or a violent attack

10)公司应当意识到,如果法院不强制(推行)法定责任,公众舆论也会这么做。许多计算机安全专家对比了20世纪60年代美国汽车行业,该行业几十年来忽视了安全问题。1965年,拉尔夫·纳德(Ralph Nader)出版了《任何速度都不安全》,这本畅销书揭示并痛斥了汽车制造业懒散的态度。第二年,政府采用严格手段,出台了安全带、头枕等方面的规定。现在想象一下,自动驾驶导致首例儿童死亡后要求立法的呼声(会是如何)。

  1. Fortunately, the small but growing market in cyber-security insurance offers a way to protect consumers while preserving the computing industry’s ability to innovate. A firm whose products do not work properly, or are repeatedly hacked, will find its premiums rising, prodding it to solve the problem. A firm that takes reasonable steps to make things safe, but which is compromised nevertheless, will have recourse to an insurance payout that will stop it from going bankrupt. It is here that some carve-outs from liability could perhaps be negotiated. Once again, there are precedents: when excessive claims against American light-aircraft firms threatened to bankrupt the industry in the 1980s, the government changed the law, limiting their liability for old products.

premiums: the cost of insurance, especially the amount that you pay each year
prodding: to make someone do something by persuading or reminding them that it
recourse : something that you do to achieve something or deal with a situation, or the act of doing it is necessary, especially when they are lazy or unwilling
carve out: remove from a larger whole


  1. One reason computer security is so bad today is that few people were taking it seriously yesterday. When the internet was new, that was forgivable. Now that the consequences are known, and the risks posed by bugs and hacking are large and growing, there is no excuse for repeating the mistake. But changing attitudes and behaviour will require economic tools, not just technical ones.






