10 ms·
> accept all its adversaries already have backdoors This is actually a really useful hypothetical standpoint to work out security from. Designing systems that
by nonrandomstring 2y ago
> accept all its adversaries already have backdoors
This is actually a really useful hypothetical standpoint to work out
security from.
Designing systems that start from the assumption of insecurity helps
us build more robust protocols and management. Qubes OS starts from
the position that all VMs are or soon will be compromised. Zero-trust
in network design assumes the bad guys already have the whole
network. Plenty out there would like to shrug and say "the endpoints
are all rotten too" (especially with phones which are a veritable hell
to secure) and move trust into the application via trusted execution
methods.
> and nothing can be done about it?
No, That doesn't follow. It's prudent to be realistic about threats.
but there's always a way out, at a cost. The cost, in a complexity
crisis, is throwing away a lot of what we've done.
- pdimitar 2y agoYeah I am completely with you and I agree. But it seems that reducing costs is more important even compared to preventing people on life support in hospitals from dying. What a world.
- warkdarrior 2y ago> Qubes OS starts from the position that all VMs are or soon will be compromised. Zero-trust in network design assumes the bad guys already have the whole network. So what does Qubes OS do to protect against a hypervisor bug? Those must exist. How do you ensure that your systems are still working and retrieving data from databases, etc, when bad guys have the whole network and can block all communications?
- nonrandomstring 2y agoThe answer to both those questions is you can't. So you you either need to make other provisions at different levels of the stack or design your architecture to make them irrelevant to your security model.