[52594] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: RISKS: Princeton discovers another Netscape security flaw

daemon@ATHENA.MIT.EDU (Lucky Green)
Mon Mar 25 01:39:30 1996

Date: Sun, 24 Mar 1996 22:43:03 -0800
To: perry@piermont.com, stevenw@best.com (Steven Weller)
From: shamrock@netcom.com (Lucky Green)
Cc: cypherpunks@toad.com

At 23:48 3/24/96, Perry E. Metzger wrote:
> When you build something large and complex, and
>you require that the entire thing work for you to be secure, there are
>just too many failure modes.

That just about sums it up.

Chisel these in granite:

o Thou shall not execute untrusted code. Java or no Java.
o Privileges that an user doesn't have can't be abused.
o The only safe firewall is a non-networked computer.
o A feature that doesn't exist won't introduce security holes.

Yes, I know that there is a balance between functionality and security.
Where to draw the line depends on the application.


-- Lucky Green <mailto:shamrock@netcom.com>
   PGP encrypted mail preferred.



home help back first fref pref prev next nref lref last post