3 ms·
#1 "the system is either secure or insecure" - only according to the particular system's threat model. Your counter-argument falls flat because it assumes all c
by explorigin 10y ago
#1 "the system is either secure or insecure" - only according to the particular system's threat model. Your counter-argument falls flat because it assumes all computers share one universal threat-model. "more secure" refers to probabilities built into a particular threat-model. If you're going to make security a binary thing, then without absolute knowledge of the entire system...it is insecure and we're wasting our digital ink.
#2 depends on #1
#3 if the subject is "things the NSA does do to make us less secure" then it is the subject.
- ryao 10y agoSecurity like temperature. It has an absolute limit. We are really only talking about how insecure a system is. That becomes obvious when reading about things like seL4.
- Jweb_Guru 10y agoWhile I agree with you in principal and am sympathetic to your position, it is not the case that security is "absolute" without taking threat model into account. As a specific example, SeL4 does not take timing channel vulnerabilities into account.
- ryao 10y agoIf you are doing formal verification, then you can make your own model, create software and attempt to prove that the software has issues within that model. seL4 is just one example of someone doing that.
- Jweb_Guru 10y agoUh, I know. My point is that you won't always know all the security vectors you have to deal with. There's no way of just asserting that your model is free of side-channel attacks without (minimally) intimate knowledge of the hardware it's going to run on.