[cap-talk] Ivan Krstic sells POLA at AusCert 2007

Ivan Krstić krstic at solarsail.hcs.harvard.edu
Wed Jun 13 17:37:25 EDT 2007


Toby Murray wrote:
> shame it wasn't picked up on other popular tech media though.

>From what I recall, CNet, ComputerWorld, ZDNet and the Sydney Morning
Herald/The Age covered it. The view that modern desktop security
measures fundamentally aren't good is pretty unpopular, though, and gets
a lot of people upset.

> Nothing new for this list of course.  

Right, it's not meant to be new to anyone here. I've been very up-front
about having studied various historical capability systems before coming
up with Bitfrost, which tries to have some advantages of those systems
without using actual capabilities. I've explicitly mentioned capability
systems in all the talks I've given about this, including the AusCERT
one. MarkM and MarcS are on the One Laptop per Child security working group.

> The historical perspective (1971 Unix story) seems a bit
> weak to me

I'd like to hear more about what you find weak. It reflects my
understanding of the situation, and hasn't been disputed by various
people I've talked to who were interested in security around that time.

Cheers,

-- 
Ivan Krstić <krstic at solarsail.hcs.harvard.edu> | GPG: 0x147C722D


More information about the cap-talk mailing list