Re: [friam] SOSP History Day
Raoul Duke <[email protected]> Sun, 11 Oct 2015 17:44:21 -0700
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAJ7XQb5UhMKz-1PD_app4OeyqKtTOAFZrb=WTx5h4huDo2bzZA@mail.gmail.com> |
On Sun, Oct 11, 2015 at 12:03 PM, Mark S. Miller <[email protected]> wrote: > On Sun, Oct 11, 2015 at 11:49 AM, Dan Connolly <[email protected]> wrote: >> >> On Sun, Oct 11, 2015 at 1:22 PM, Mark S. Miller <[email protected]> >> wrote: >> > On Sun, Oct 11, 2015 at 11:14 AM, Dan Connolly <[email protected]> wrote: >> >> >> >> Perhaps you could help me understand a little better? >> >> >> >> I'm having trouble seeing how "any vulnerability in any software >> >> someone like myself may invoke, for example the sqrt function, is a >> >> threat to delete all my files or contribute to a DDOS or spear >> >> phishing attack" is any more or less true than "insecurity anywhere is >> >> a threat to security everywhere." >> >> >> > If the sqrt function you're running is vulnerable, you are at risk. But >> > if >> > only the sqrt function I am running is vulnerable, that does not put you >> > at >> > risk. >> >> If there's an arbitrary code execution vulnerability in the sqrt >> function you are running, then the attacker can forge network messages >> from you or your machine. If that sqrt function is on enough machines, >> the attacker can can reach out and put me at risk. > > > Only if you are already vulnerable. The vulnerability in my sqrt function > does not itself make you vulnerable, even if it does exploit a vulnerability > you already have. > > >> >> >> > Note that the vulnerability-thru-excess-authority I am focused on here >> > is >> > quite distinct from DDOS, which is a resource exhaustion attack on >> > availability; or spear phishing, which is a social engineering attack >> > involving further human actions. >> >> I don't see the distinction in practice. DDOS attacks and spear >> phishing are, in practice, deployed by exploiting >> vulnerability-thru-excess-authority as a consequence of conventional >> security choices. > > > DDOS is an attack only on availability. Deleting files, which is indeed my > example, can be viewed at an attack on either availability or integrity, > depending on how we split hairs. However, my sqrt function can also modify > and thereby corrupt my files, which is clearly an attack on integrity. > > Spear phishing depends on triggering new human actions. Humans must > participate for the attack to proceed. The vulnerability is my sqrt function > for not by itself make you vulnerable to spear phishing, even if it does > exploit a vulnerability you already have. > >> >> >> It would seem to me that capability approaches don't have the same >> explosive* consequences to faults and hence the economics of >> propagation would be entirely different. >> >> The other alternative I see is identity-based systems that are >> sufficiently locked down to have similar economics. I don't think >> botnets of iPads are very likely. >> >> * in the sense of https://en.wikipedia.org/wiki/Principle_of_explosion > > > I had not heard that term before. I like it. > > In any case, I agree that caps substantially limit these explosions, and > that is much of the point I was trying to make. But the acl approach is > still *much* less explosive than classic logic, where one flaw destroys the > universe. > >> >> >> -- >> Dan Connolly >> http://www.madmode.com/ > > > > > -- > Cheers, > --MarkM > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk >