4 ms·
Computer security is a solved problem, and has been since the 1980s. Unfortunately adopting it requires us to abandon the ambient authority model of applicatio
by mikewarot 2mo ago
Computer security is a solved problem, and has been since the 1980s.
Unfortunately adopting it requires us to abandon the ambient authority model of application development and our operating systems that support it. Currently when you tell an application to open a file, it can actually do almost anything. There are operating systems that enforce your choices, not many, they're very niche, for now.
We're at the point where the power grid would be if nobody ever used fuses or circuit breakers. All power could rush to any fault. The same is true with any application a user might run under Linux, Windows, etc.
To save a lot of grief: I'm not suggesting we use Windows UAC, AppArmor, or any other administratively driven security measures. Think power boxes[1] that replace file dialog boxes, and the give file capabilities to the application per the users will, in a secure, transparent and easy to understand manner.
[1] https://wiki.c2.com/?PowerBox https://wiki.c2.com/?PowerBox