Jump to content

Makes me wonder if some "new idea" is needed...


davej

Recommended Posts

There have been discussions about a new internet with other priorities in mind. Security wasn't one of the goals of the original internet, it was just a way to transfer data. The vast majority of security issues are not with the transport layer, they are with the application layer, i.e. servers not responding correctly to malicious requests, or web applications that were not designed with security in mind.

Link to comment
Share on other sites

Yes, but it isn't just the 1980's internet protocols that are causing the security problems. It is bad design, after bad design, after bad design.

Link to comment
Share on other sites

Well, there does seem to be an endless amount of confusion regarding what the root of the problem is. Maybe there is no "root of the problem?"

 

However, I don't understand why some obvious things can't be done. For example when your pc boots up -- why doesn't it boot off of a read-only disk partition? The core of the OS could be read-only. The core code could then validate the hash signatures of everything else.

Link to comment
Share on other sites

Any OS gets updated, so that partition is going to need to be written to at some point. An attacker may be able to use the same mechanism. There are a lot of good technical solutions to various problems, but the issue is that many of the problems are not technical problems, they're human problems.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...