3 ms·
You're forgetting a step in your "reasonable approach". How do you expect a user to know whether or not they should grant access for HN.exe to talk to 127.0.0.1
by jfrunyon 5y ago
You're forgetting a step in your "reasonable approach". How do you expect a user to know whether or not they should grant access for HN.exe to talk to 127.0.0.1 or for mikewarot.exe to access some file?
The reality is the sort of system you suggest almost inevitably ends up being the same as broad permission-based security like current mobile OSes have, because the only scalable decision is "give it access to all resources in a category if it asks and that seems appropriate".
However, those systems DO exist in both Windows and Linux.
- mikewarot 5y agoConsider cash in your wallet... you quite easily hand out tokens to clerks for transactions. Instead of a dialog box run by an application to open a document, you have the OS do the same thing, and enforce the decision of the user. As far as the user interface, the same steps would happen, but security would be radically improved. Broad based permissions are horrible kludges, and make explaining fine grained capabilities much harder to do, but I don't have a better term for it. If some random application wants to phone home, you could allow it, or not, or give it X amount of bandwidth, the options are limitless. I don't know what the optimal conventions we'll settle on will be. I know if I were to specify them, they'd definitely be the wrong ones. ;-)
- jfrunyon 5y agoOh, that's great. Good to hear that the user interface will totally be the same. ring ring Hey mikewarot, my computer is asking me if I should grant TotallyAGoodApp.exe access to C:\WINDOWS\system32\config\sam. I went ahead and said yes because I wasn't sure. Clearly you've never worked in any kind of remotely user-facing position.