| ▲ | josephg 19 hours ago | ||||||||||||||||||||||
> SeL4 or proof assistant are not panacea. They do not help if assumptions about the task are wrong. And correctly formulating the task in real world is very messy. Nobody said sel4 was a panacea. My claim is that doing this kind of computer security is possible. It's just expensive and inconvenient. We know how to make computers a lot more secure than they are today. The limiting factor isn't humanity's knowledge. The limit is that barely anyone wants to pay the bill. | |||||||||||||||||||||||
| ▲ | mentalgear 17 hours ago | parent | next [-] | ||||||||||||||||||||||
The main issue is that market evolution will always surfaces the most cost-efficient entities within the ecosystem pressures. That means designing the ecosystem pressures is crucial: things more meaningful than just pure capitalist private-profit logic must by enforced by thoughtful regulation or otherwise the ecosystem converges for private-profit of a small sliver of individuals (billionaires) to the detriment of all other ecosystem members (99% of the world population). This holds for anything broader than pure private gain, may it be security, social fairness or ecological topics. Sole monetary-value optimization for private gain must be properly constrained or else it results in pure predatory capitalism that implodes society from within, may it be through leaky security, poisoned environments or social unrest. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | alt227 18 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
> The limit is that barely anyone wants to pay the bill Do you even have any experience with how most companies work? SMEs barely have the cashflow to cover their daily expenses, let alone suddenly pay thousands for regular professional security audits and overhauls of their code. This is why security is an afterthought. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | tremon 7 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
> My claim is that doing this kind of computer security is possible. But your evidence does not support that claim. SeL4 has proven that it is possible to design a secure microkernel and prove its security guarantees. It does not prove that you can build entire systems (filesystem+database+web server+browser) on top of that kernel while maintaining the same security guarantees. I'm all for improving the state of computer security, and I'd love for capability systems like SeL4 to become more prevalent. But it's only a microkernel, and it's by no means certain that the PeopleSoft vulnerability exploited here required a kernel-level compromise. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | close04 15 hours ago | parent | prev [-] | ||||||||||||||||||||||
> just expensive and inconvenient You mean something is theoretically possible, but in practice only works at small scale and is otherwise effectively impossible. You only have so many resources for all those big topics. And after you spent all the world's resources on the "perfect", formally bug-free software, you get hacked via social engineering or malicious insider. | |||||||||||||||||||||||