[Economist] 网络安全的神话(二)

[Economist] 网络安全的神话(二)

作者: Prongs | 来源:发表于2017-10-22 12:18 被阅读9次

    The myth of cyber-security


    Leaving the windows open

    This is not a counsel of despair. The risk from fraud, car accidents and the weather can never be eliminated completely either. But societies have developed ways of managing such risk—from government regulation to the use of legal liability and insurance to create incentives for safer behaviour.


    Start with regulation. Governments’ first priority is to refrain from making the situation worse. Terrorist attacks, like the recent ones in St Petersburg and London, often spark calls for encryption to be weakened so that the security services can better monitor what individuals are up to. But it is impossible to weaken encryption for terrorists alone. The same protection that guards messaging programs like WhatsApp also guards bank transactions and online identities. Computer security is best served by encryption that is strong for everyone.

    首先是政府监管。政府的首要任务就是避免情况变得更加糟糕。像最近发生在圣彼得堡和伦敦的袭击,常常会使得人们想到通过降低加密措施来方便监视人们的一举一动。但我们做不到仅仅是针对袭击者来降低他们的加密措施。运用于 WhatsApp 和银行交易以及在线身份认证的的加密措施并没有什么不同。计算机安全措施平等地服务于所有人。

    The next priority is setting basic product regulations. A lack of expertise will always hamper the ability of users of computers to protect themselves. So governments should promote“public health” for computing. They could insist that internet connected gizmos be updated with fixes when flaws are found. They could force users to change default usernames and passwords. Reporting laws, already in force in some American states, can oblige companies to disclose when they or their products are hacked. That encourages them to fix a problem instead of burying it.




          本文标题:[Economist] 网络安全的神话(二)
