Re: [friam] SOSP History Day

Dan Connolly <[email protected]> Sun, 11 Oct 2015 13:49:48 -0500
Newsgroups gmane.comp.capabilities.general
Message-ID <CAD2YivYwiwXx7tGdDmRkz_FDJHkzmDhqK4o67P_rpOvfG1k+AQ@mail.gmail.com>
On Sun, Oct 11, 2015 at 1:22 PM, Mark S. Miller <[email protected]> wrote:
> On Sun, Oct 11, 2015 at 11:14 AM, Dan Connolly <[email protected]> wrote:
>>
>> Perhaps you could help me understand a little better?
>>
>> I'm having trouble seeing how "any vulnerability in any software
>> someone like myself may invoke, for example the sqrt function, is a
>> threat to delete all my files or contribute to a DDOS or spear
>> phishing attack" is any more or less true than "insecurity anywhere is
>> a threat to security everywhere."
>>
> If the sqrt function you're running is vulnerable, you are at risk. But if
> only the sqrt function I am running is vulnerable, that does not put you at
> risk.

If there's an arbitrary code execution vulnerability in the sqrt
function you are running, then the attacker can forge network messages
from you or your machine. If that sqrt function is on enough machines,
the attacker can can reach out and put me at risk.

> Note that the vulnerability-thru-excess-authority I am focused on here is
> quite distinct from DDOS, which is a resource exhaustion attack on
> availability; or spear phishing, which is a social engineering attack
> involving further human actions.

I don't see the distinction in practice. DDOS attacks and spear
phishing are, in practice, deployed by exploiting
vulnerability-thru-excess-authority as a consequence of conventional
security choices.

It would seem to me that capability approaches don't have the same
explosive* consequences to faults and hence the economics of
propagation would be entirely different.

The other alternative I see is identity-based systems that are
sufficiently locked down to have similar economics. I don't think
botnets of iPads are very likely.

* in the sense of https://en.wikipedia.org/wiki/Principle_of_explosion

-- 
Dan Connolly
http://www.madmode.com/