Re: [Full-disclosure] Securing our computers?



mcwidget ?????:
What we *don't* know how to do is make a system that Joe Sixpack is
allowed
to screw around with, and yet prevent security issues from happening.

It's not a user's fault that C-like languages' runtime is vulnerable by
design. And it's certainly not a user's fault that C-like languages are
being widely used.
It's not a user's fault that most of widely used hardware platforms and
OSes are lacking of any advanced secure task isolation. And it's
certainly not a user's fault that the currently available isolation
functionality is being misused and overestimated everywhere.
It's not a user's fault that most of widely used software, including
OSes, and protocols has been designed and implemented mostly without
security in mind.

It's mostly the industry's fault. And the industry earns much from it.
I wouldn't blame users, because they are a minor evil in this story.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Ping Kevin Aylward - re your "scientific paper"
    ... If I design 100 circuits and one fails, ... of the decoding lies on the reader. ... intellectual food chain, but when I read your stuff it's as if I were ... it's my fault it's taking so long to get to the end of the ride. ...
    (sci.electronics.design)
  • Re: Reconciling Garbage Collection with Deterministic Finalization
    ... time (even if there is a disk error, since then the process will be ... concurrency design. ... I don't see how you can argue that the latency of a page fault is ... In one design, each client ...
    (comp.programming.threads)
  • Re: [performance] Is it safe to alter the meaning of STDOUT_FILENO in parent process rather than usi
    ... Poor software design includes poor software design in third-party libraries. ... This is otherwise called fault tolerance. ... fault isolation from each other. ... close all open file handles after fork but before exec. ...
    (comp.unix.programmer)
  • Re: chip-scale GaN fets
    ... it was someone else's fault. ... They changed the design. ... Another example is a temperature controller you designed and sold. ... The customer lowered the max temperature limit of ...
    (sci.electronics.design)
  • Re: Easy PC software tool - Bad experience
    ... In November 09 I had another design due for manufacture so I checked with Support that I had the required software fix and submitted the design for manufacture. ... The result to me was £1500 worth of PCBs being scrapped and an unhappy customer due to a missed delivery deadline. ... From the customer POV i.e. the important POV, the same fault re-occurred. ...
    (comp.arch.fpga)