Nilay Khandelwal

  • Archive
  • RSS
  • Ask me

The UNIX security model sucks

.. It assumes that attacks come from the outside, and is designed to protect the user from other users on the same system. In the UNIX model, everything run by a particular user has the same rights as the user. In practice, that just isn’t a viable security model anymore ..

.. A modern security model must be fundamentally built on the principle of distrust. Distrust everything. Any app could potentially become malicious at any time, whether because the app developer put in a backdoor or because somebody exploited a buffer overflow. It is, therefore, the responsibility of the operating system to not only protect the user from other users on the system, but also from flaws in other applications being run by the same user ..

    • #UNIX
    • #security
    • #sandboxing
  • 9 months ago
  • 1
  • Permalink
  • Share
    Tweet

1 Notes/ Hide

  1. nilayk posted this
← Previous • Next →
Member of The Internet Defense League

About

life is a playground

Twitter

loading tweets…

  • RSS
  • Random
  • Archive
  • Ask me
  • Mobile

Effector Theme by Carlo Franco.

Powered by Tumblr