Re: [friam] SOSP History Day

Raoul Duke <[email protected]> Sun, 11 Oct 2015 17:44:21 -0700
Newsgroups gmane.comp.capabilities.general
Message-ID <CAJ7XQb5UhMKz-1PD_app4OeyqKtTOAFZrb=WTx5h4huDo2bzZA@mail.gmail.com>
On Sun, Oct 11, 2015 at 12:03 PM, Mark S. Miller <[email protected]> wrote:
> On Sun, Oct 11, 2015 at 11:49 AM, Dan Connolly <[email protected]> wrote:
>>
>> On Sun, Oct 11, 2015 at 1:22 PM, Mark S. Miller <[email protected]>
>> wrote:
>> > On Sun, Oct 11, 2015 at 11:14 AM, Dan Connolly <[email protected]> wrote:
>> >>
>> >> Perhaps you could help me understand a little better?
>> >>
>> >> I'm having trouble seeing how "any vulnerability in any software
>> >> someone like myself may invoke, for example the sqrt function, is a
>> >> threat to delete all my files or contribute to a DDOS or spear
>> >> phishing attack" is any more or less true than "insecurity anywhere is
>> >> a threat to security everywhere."
>> >>
>> > If the sqrt function you're running is vulnerable, you are at risk. But
>> > if
>> > only the sqrt function I am running is vulnerable, that does not put you
>> > at
>> > risk.
>>
>> If there's an arbitrary code execution vulnerability in the sqrt
>> function you are running, then the attacker can forge network messages
>> from you or your machine. If that sqrt function is on enough machines,
>> the attacker can can reach out and put me at risk.
>
>
> Only if you are already vulnerable. The vulnerability in my sqrt function
> does not itself make you vulnerable, even if it does exploit a vulnerability
> you already have.
>
>
>>
>>
>> > Note that the vulnerability-thru-excess-authority I am focused on here
>> > is
>> > quite distinct from DDOS, which is a resource exhaustion attack on
>> > availability; or spear phishing, which is a social engineering attack
>> > involving further human actions.
>>
>> I don't see the distinction in practice. DDOS attacks and spear
>> phishing are, in practice, deployed by exploiting
>> vulnerability-thru-excess-authority as a consequence of conventional
>> security choices.
>
>
> DDOS is an attack only on availability. Deleting files, which is indeed my
> example, can be viewed at an attack on either availability or integrity,
> depending on how we split hairs. However, my sqrt function can also modify
> and thereby corrupt my files, which is clearly an attack on integrity.
>
> Spear phishing depends on triggering new human actions. Humans must
> participate for the attack to proceed. The vulnerability is my sqrt function
> for not by itself make you vulnerable to spear phishing, even if it does
> exploit a vulnerability you already have.
>
>>
>>
>> It would seem to me that capability approaches don't have the same
>> explosive* consequences to faults and hence the economics of
>> propagation would be entirely different.
>>
>> The other alternative I see is identity-based systems that are
>> sufficiently locked down to have similar economics. I don't think
>> botnets of iPads are very likely.
>>
>> * in the sense of https://en.wikipedia.org/wiki/Principle_of_explosion
>
>
> I had not heard that term before. I like it.
>
> In any case, I agree that caps substantially limit these explosions, and
> that is much of the point I was trying to make. But the acl approach is
> still *much* less explosive than classic logic, where one flaw destroys the
> universe.
>
>>
>>
>> --
>> Dan Connolly
>> http://www.madmode.com/
>
>
>
>
> --
>     Cheers,
>     --MarkM
>
> _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
>