Interview, Podcast
A security expert on why we MUST vote on paper | Bruce Schneier (2019)
- Machine learning systems are expected to identify and patch software vulnerabilities over the next 20 years, potentially rendering them obsolete.
- Authentication mechanisms are forecasted to shift from human-centric to device-centric models, enabling "thing-to-thing" communication in real-time via 5G networks without human intervention.
- Networks will increasingly require monitoring of "old cruft," including 40-year-old consumer software and low-cost embedded devices that remain in service for decades without patching, creating significant security risks.
- AI algorithms may automate the discovery of software weaknesses and vulnerability patterns, allowing humans to transition to roles that cannot be computed out, though this could lead to hundreds of thousands of unfilled computer security jobs.
- AI systems are anticipated to process surveillance data to identify specific traits without human interpretation, making surveillance states more efficient but potentially temporary fixes for catastrophic risks.
- Cameras and sensors are predicted to become so small and distant that they will be invisible to the human eye within 20 years, complicating detection of surveillance infrastructure.
- Policymakers are expected to increasingly rely on surveillance as a response to catastrophic biological risks, though this approach may only delay problems for a few years before becoming useless as technology becomes widely accessible to individuals.
- Governments may engage in "active defense" by hacking back attackers to disrupt campaigns, a strategy predicted to gain traction in the United States by 2018.
- Supply chain security is viewed as an insurmountably hard problem due to international complexity, with subversion risks extending from chip manufacturing to shipping.
- Air gaps are expected to fail quickly, with viruses capable of jumping classified or private air-gapped networks like SIPRNet within 24 hours.
- AI training data and resulting models are likely to be treated as trade secrets to prevent rivals from exploiting them or gaming the systems.
- Economic factors, including the high cost of fixing security flaws versus the cheaper cost of losses, drive corporate behavior, particularly in banking where liability laws may need to change to incentivize repairs.
- The distinction between internet policy and other sectors is predicted to vanish, integrating security into consumer, automobile, airplane, and medical device policies.
- Google is expected to maintain secrecy around its AI algorithms for security and commercial reasons, similar to the protection of the PageRank algorithm.
- The debate between security and surveillance is predicted to diminish as the security value of protecting systems becomes vastly greater than the utility of eavesdropping.
- "Movie plot threats" involving simultaneous system failures are acknowledged as possible, though the focus remains on current risks like unpatched IoT devices and the shift to device-centric vulnerabilities.
- Criminals are expected to target high-value assets rather than average users, making identity transfer a viable defense strategy for the general population.
- Technology is anticipated to be remade by policy errors, necessitating greater involvement of technologists in policy-making to bridge the gap between technical realities and regulation.
- Deep fakes are predicted to become so prevalent that younger generations will become inert to their effects, reducing their immediate psychological impact.
- Security value is expected to increasingly favor making systems eavesdropproof rather than eavesdroppable, given the critical nature of systems to society.
- Economics, psychology, and sociology are projected to influence future system design as heavily as technology itself, particularly for platforms like Facebook.
- Spam is predicted to be resolved through economic shifts rather than technological solutions, despite the existence of earlier tech fixes.
- Human morality is expected to eventually prevail regarding technology and democracy, despite a noisy and messy transition period.
- Air-gapped private classified internet systems are expected to be breached by viruses within 24 hours, indicating that air gaps are not a panacea.
- Machine learning will be utilized to find weaknesses in unfixable legacy systems and monitor insecure devices to prevent their use in networks.
- The export of surveillance control technologies by nations like China is feared to facilitate a world where dystopia is easier to achieve.
- Public interest technology is expected to scale beyond individual stars or organizations to become a viable field.
- Ideas regarding security are predicted to be replicated rapidly by competitors globally within two weeks to a month.
- Attack is expected to remain easier than defense for organizations facing attackers with significant budgets, requiring strategies to make attacks prohibitively difficult.
- Software is deliberately excluded from normal product liability laws to avoid slowing down a profitable industry, a decision made by policymakers.
- The accumulation of precursor technologies for AI and robotics is expected to bring existing security risks to the forefront.
- Machine learning is expected to help find vulnerabilities in a very general sense, leading to defensive algorithms that can operate at computer speeds.
- The cost of losses is cheaper than the cost of fixing for banks, explaining why they often delay fixing security flaws until liability laws change.
- Policymakers are expected to create a world where surveillance is useful but buys only a few years of security before the technology becomes accessible to individuals.
- Ideas are not hard to come up with, and competitors will likely replicate successful concepts within a very short timeframe.
- Air gaps are not a panacea, as viruses can jump those gaps within 24 hours.
- 5G will enable thing-to-thing authentication at a scale currently unmanageable, moving beyond simply faster internet access.
- Low-cost systems like routers and light bulbs will remain in networks for decades without patching, creating a security nightmare.
- Economics, psychology, and sociology will matter just as much as technology in designing future systems like Facebook.
- Spam is not a problem at all because the economics of email changed, even though tech solutions existed earlier.
- Software is deliberately excluded from normal product liability laws and this was done because policymakers didn't want to slow down this important and very profitable industry.
- Internet policy is no longer a separate thing but is now part of consumer policy, automobile policy, airplane policy, medical device policy.
- Technology is remaking the world and we will never get the policy right if policymakers get the technology wrong.
- Policymakers will reach for surveillance as a tool for future catastrophic risks, similar to what the FBI is doing today.
- Surveillance is useless when the technology is as accessible to individuals as guns are today.
- Human beings will eventually figure this out regarding surveillance and democracy, even though the process will be noisy and messy.
- We need more technologists to get involved in policy to fix the separation between the two worlds.
- Public interest tech needs to scale beyond a few stars or a few organizations to become viable.
- Supply chain security is an insurmountably hard problem because the industry is very international.
- Machine learning can help by having computers working alongside humans to find vulnerabilities at computer speeds.
- AI and intelligent robotics are the accumulation of several precursor technologies whose security risks are already with us.
- Vulnerabilities are a thing of the past in 20 years if we develop automatic systems to find and patch them.
- Most criminals don't want me unless I am a high-value target, meaning transferring works great for average users.
- Google has spent a lot of time being secure against nations and probably considers itself secure against most nation state attacks.
- Training data and the resulting model for AI will tend to be secret for two reasons: to prevent rivals from using them and to prevent gaming.
- Air-gapped private classified internet systems like SIPRNet have viruses that tend to jump that air gap within 24 hours.
- Low-cost, embedded, not-maintained old systems will be a security nightmare in the future.
- 5G is not about faster Netflix but about things talking to things without your intervention.
- Supply chain subversion is so easy that we can't trust every aspect of it from chips to shipping.
- Economists and techies will work together to research economic models that drive computer security.
- Human beings are inherently moral and we eventually do the right things regarding technology and democracy.
- AI systems will soon be able to find vulnerabilities in a very general sense to make defensive algorithms.
- Machine learning can help find weaknesses in unfixable things like old IoT devices.
- Machine learning can help monitor these insecure systems from being used in the network.