3 ms·
> something we've needed since the 1970s, but everyone dismissed as too complex, slow, or unnecessary What are some scenarios where Capability Based Security m
by MaknMoreGtnLess 5y ago
> something we've needed since the 1970s, but everyone dismissed as too complex, slow, or unnecessary
What are some scenarios where Capability Based Security might be thought of as unnecessary (but isn't/wasn't)?
- mikewarot 5y agoThat was back when computers had limited RAM and hard disk, and networking wasn't a thing. We made due with band-aids for a long time, but they've reached their limits. Virtualization, Containerization, were all approaches that offered extremely course grained capabilities, in that they allowed you to specify a virtual disk for the machine, and no other access. We tried enumerating all the bad programs - virus scanners. We tried blaming the users - "You clicked on a bad link", Why did you open that attachment, etc. We tried blaming the programmers - You need to write "secure code" We tried blaming the compilers - Rust, etc. We blamed everything except the Operating Systems that were not fit for purpose. That needs to change, or we'll never be able to secure or data.