TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Inevitability of Failure: The Flawed Assumption of Security in Modern Computing [pdf]

30 pointsby singoldalmost 10 years ago

6 comments

nickpsecurityalmost 10 years ago
A classic. Bell&#x27;s Looking Back Addendum [1] also traces the beginning of high assurance security market (their solution) and how DOD&#x2F;NSA totally killed it. I specialized in extending such high assurance systems or approaches to handle modern problems. That market is gone, though, thanks to DOD&#x2F;NSA policies to use low assurance systems and even pushing them. Post-Snowden, it&#x27;s fair to wonder if it was mismanagement or intentional that they marketed low assurance alternatives (eg DTW, MDDS) to the kinds of OS&#x27;s and guards they couldn&#x27;t beat with 2-5 years of pentesting (esp Boeing SNS Server).<p>Yet, I think I can say we all focused too much on the OS and software security side of things despite what we accomplished. As Brian Snow noted, we&#x27;re really just trying to implement forms of isolation on machines designed for pervasive sharing (read: insecurity). It&#x27;s why I counterpointed Geer here [2] saying our software security crisis isn&#x27;t inevitable: we just need to use hardware and tools that make secure software easier to write. I gave examples from the past of many security-improving features systems had, including immunity to code injection via app attack. Fortunately, at least a few groups (esp DARPA&#x2F;NSF sponsored) took notice and are working on such architectures today.<p>[1] <a href="http:&#x2F;&#x2F;lukemuehlhauser.com&#x2F;wp-content&#x2F;uploads&#x2F;Bell-Looking-Back-Addendum.pdf" rel="nofollow">http:&#x2F;&#x2F;lukemuehlhauser.com&#x2F;wp-content&#x2F;uploads&#x2F;Bell-Looking-B...</a><p>[2] <a href="https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2014&#x2F;04&#x2F;dan_geer_on_hea.html#c5598568" rel="nofollow">https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2014&#x2F;04&#x2F;dan_geer_on_h...</a>
评论 #9743139 未加载
评论 #9742719 未加载
bediger4000almost 10 years ago
The youngest references are from 1998, so I&#x27;m guessing this was written by 2000, before the Very Bad Indeed 9&#x2F;11 incidents. Also, it doesn&#x27;t mention terrorism at all.<p>I suppose this just represents that the NSA at least in the past had various factions inside it, one of which lead to SELinux.
评论 #9745746 未加载
评论 #9741984 未加载
评论 #9741433 未加载
bnewboldalmost 10 years ago
Just downloaded and opened a .pdf from nsa.gov.<p>Oops.
评论 #9742568 未加载
Cieplakalmost 10 years ago
Even if an operating system were provably secure in the software layer, it might still be vulnerable to hardware backdoors:<p><a href="http:&#x2F;&#x2F;www.eteknix.com&#x2F;expert-says-nsa-have-backdoors-built-into-intel-and-amd-processors&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.eteknix.com&#x2F;expert-says-nsa-have-backdoors-built-...</a>
评论 #9744320 未加载
评论 #9745774 未加载
stcredzeroalmost 10 years ago
It should be relatively easy to develop an automated tool to reformat LaTEX papers to a single column format more suitable for web distribution. Actually, LaTEX itself should be able provide all of the infrastructure for this. Given this, isn&#x27;t it odd that papers get published to the web as 2 column PDFs? I know how&#x2F;why it happens, but still.
评论 #9741821 未加载
评论 #9741990 未加载
dredmorbiusalmost 10 years ago
Does anyone have a fix for the missing ligatures problem this PDF exhibits? &quot;fl&quot;, &quot;fi&quot;, and &quot;ff&quot; are blank as viewed under evince and xpdf
评论 #9741998 未加载
评论 #9742065 未加载