Operating system security. The consensus seems to be that Users, Hackers, and Microsoft are responsible for the current crisis in "cyber security". Any mention of the need for a better underlying security model, such as capabilities, is dismissed as quickly as possible.
In the past, our hardware was too dumb, and we didn't have persistent networking, so we could get away with things that are obviously stupid in today's context.
No current OS can be made secure, and remain usable. It doesn't have to be this way. We can have safe and secure general purpose computing. If we don't push in that direction, the government is going to regulate things down to the bit level, and it still won't be safe.
My main way of helping right now is to keep pushing awareness of capability based security. If people don't know something is possible, they don't reach for it as a solution to problems.
Genode seems to be the closest to general use, followed closely by Google's Fuchsia.
Comments
Operating system security. The consensus seems to be that Users, Hackers, and Microsoft are responsible for the current crisis in "cyber security". Any mention of the need for a better underlying security model, such as capabilities, is dismissed as quickly as possible.
In the past, our hardware was too dumb, and we didn't have persistent networking, so we could get away with things that are obviously stupid in today's context.
No current OS can be made secure, and remain usable. It doesn't have to be this way. We can have safe and secure general purpose computing. If we don't push in that direction, the government is going to regulate things down to the bit level, and it still won't be safe.
Any idea on organizations working on this or ways to get involved?
My main way of helping right now is to keep pushing awareness of capability based security. If people don't know something is possible, they don't reach for it as a solution to problems.
Genode seems to be the closest to general use, followed closely by Google's Fuchsia.