3 ms·
The point of secure operating systems is not to reduce the number of flaws in the kernel. It is to make the authority gained by exploiting any single program mi
by Agent101 17y ago
The point of secure operating systems is not to reduce the number of flaws in the kernel. It is to make the authority gained by exploiting any single program minimal. So it should make flaws less horrible.
- tptacek 17y agoWhen I said "miles away from the kernel", I meant that the opportunity for the kernel to address problems in the application layer were minimal. There's little the kernel can to do, say, make SQL Injection less horrible.
- Agent101 17y agoPersonally I consider the fact that a random downloaded game run, by default, could delete all your personal data a pretty big security flaw that can be dealt with at the kernel level. So we have different meanings of security flaw. Probably because you are thinking of the security of a website, where I am more interested in securing the average users PC.
- tptacek 17y agoRead Dan Bernstein's retrospective on qmail, where he essentially disavows "least privilege" controls on his programs (which were the heart of his security model). Modern operating systems all offer some degree of privilege revocation and code-level access control; none of them get used, because users needs are too complex. If a dent is really going to be made in this problem, it's going to happen in Flash Player (or its more recent analogs, like Google NaCL).
- Agent101 17y agoI'll grant you that current (and most proposed capability based) security systems are too complex for the user to manage. However the question on the table is research. We should be researching security models that don't rely on the user to manage the complexity.