Re: Slides

Guido Witmond <guido-EBfTt96odT/[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
On 06-08-13 08:45, Jed Donnelley wrote:

> _________________________
> 
> I'm quite sympathetic to this message - not surprising.  Of course I
> also find it discouraging
> that the message isn't better received, but after all these years I'm
> not surprised.
> 

I don't know when I learned about the concepts of capability theory. I
do know that I was quite disappointed with the protections that Posix
had to offer against malicious code when some fellow student
demonstrated he could access my $HOME from a bug in a server I wrote,
way back at college, around 199x.

I was clear that MAC wasn't the answer. There had to be a better way. It
became the voice in my head to judge other systems' security properties.
I went on a quest to find better solutions. I've compiled and run Eros-os.

I was very pleased to see Polaris. It did exactly what I wanted. Too bad
- for me - it was on Windows. Most impressive, the demo *showed* it was
able to block malware.

The talk was too academic for most non-academic programmers out there.
Rob mentions the risks but it lacked the concrete example.

Thinking about it, the example could go like this:
- show bitcoin wallet with some money in it.
- close bitcoin app.
- open trojaned LibreOffice document. (it does its work silently)
- close LO, open bitcoin app and see the money disappear (with 10 minute
confirmations to rub it in that the money is really gone)

Then show the malicious payload and how it works. (Explain ambient
authority).

Then show what people need to do to keep their bitcoins safe:
- encrypt the wallet (important but a hassle, that no one does)
- run bitcoin in a VM (impossible to set up for ordinary users)
- install MinorFS,
- show that the same LO-document gives an error at the payload.
- Profit.

That would drive the message $HOME. Pun intended.

Rob, if you are interested, I'd love to help to create that exploit (or
a fake one) for your next presentation. Even with a fake exploit you can
get the message across.

With regards, Guido.

PS. Please don't feel offended about my enthusiasm. I'm waiting for a
solution for 20 years. With your talk, you've convinced me that MinorFS
is a solution that would work on short term on my current system. I'd
love to help you with it.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.