3 ms·
Not a security expert here... But Discretionary Access Controls is a standard part of OS design for a very long time. It is certainly possible to go back to D
by lotharcable 1y ago
Not a security expert here...
But Discretionary Access Controls is a standard part of OS design for a very long time.
It is certainly possible to go back to DOS-days and run all your programs without controls as terminate and stay resident programs. But that would be awfully inconvenient.
The concept of "users" isn't just for human users. It is used to do things like prevent your web server from being able to read and edit your password files and such things.
- ytpete 1y agoI'm assuming what they are thinking along the lines of is not that we'd do away with the notion of privilege levels, but more that privilege boundaries would become 1:1 with hardware boundaries. So perhaps you'd have a dedicated CPU core with its own isolated cache for running the kernel, or that sort of thing. Almost like multiple separate systems communicating across client-server boundaries. I guess the question for me though (as neither a deep expert in security nor low-level hw) is, how much less efficient would that be than the kinds of mitigations used today for shared hardware? If it's far more guaranteed-safe and the cost is only just a bit higher than today's mitigations... that would be interesting indeed.