Re: [friam] SOSP History Day

"Mark S. Miller" <[email protected]> Sun, 11 Oct 2015 12:03:23 -0700
Newsgroups gmane.comp.capabilities.general
Message-ID <CABHxS9j8B7DWw+kbT4HRyR7f+uc+=WJvR_0BBN1HTRUPb-+d1w@mail.gmail.com>
On Sun, Oct 11, 2015 at 11:49 AM, Dan Connolly <[email protected]> wrote:

> On Sun, Oct 11, 2015 at 1:22 PM, Mark S. Miller <[email protected]>
> wrote:
> > On Sun, Oct 11, 2015 at 11:14 AM, Dan Connolly <[email protected]> wrote:
> >>
> >> Perhaps you could help me understand a little better?
> >>
> >> I'm having trouble seeing how "any vulnerability in any software
> >> someone like myself may invoke, for example the sqrt function, is a
> >> threat to delete all my files or contribute to a DDOS or spear
> >> phishing attack" is any more or less true than "insecurity anywhere is
> >> a threat to security everywhere."
> >>
> > If the sqrt function you're running is vulnerable, you are at risk. But
> if
> > only the sqrt function I am running is vulnerable, that does not put you
> at
> > risk.
>
> If there's an arbitrary code execution vulnerability in the sqrt
> function you are running, then the attacker can forge network messages
> from you or your machine. If that sqrt function is on enough machines,
> the attacker can can reach out and put me at risk.
>

Only if you are already vulnerable. The vulnerability in my sqrt function
does not itself make you vulnerable, even if it does exploit a
vulnerability you already have.



>
> > Note that the vulnerability-thru-excess-authority I am focused on here is
> > quite distinct from DDOS, which is a resource exhaustion attack on
> > availability; or spear phishing, which is a social engineering attack
> > involving further human actions.
>
> I don't see the distinction in practice. DDOS attacks and spear
> phishing are, in practice, deployed by exploiting
> vulnerability-thru-excess-authority as a consequence of conventional
> security choices.
>

DDOS is an attack only on availability. Deleting files, which is indeed my
example, can be viewed at an attack on either availability or integrity,
depending on how we split hairs. However, my sqrt function can also modify
and thereby corrupt my files, which is clearly an attack on integrity.

Spear phishing depends on triggering new human actions. Humans must
participate for the attack to proceed. The vulnerability is my sqrt
function for not by itself make you vulnerable to spear phishing, even if
it does exploit a vulnerability you already have.


>
> It would seem to me that capability approaches don't have the same
> explosive* consequences to faults and hence the economics of
> propagation would be entirely different.
>
> The other alternative I see is identity-based systems that are
> sufficiently locked down to have similar economics. I don't think
> botnets of iPads are very likely.
>
> * in the sense of https://en.wikipedia.org/wiki/Principle_of_explosion


I had not heard that term before. I like it.

In any case, I agree that caps substantially limit these explosions, and
that is much of the point I was trying to make. But the acl approach is
still *much* less explosive than classic logic, where one flaw destroys the
universe.


>
> --
> Dan Connolly
> http://www.madmode.com/
>



-- 
    Cheers,
    --MarkM

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk