funsec mailing list archives

Re: standards status in the industry - opinion?


From: James Kehl <shykta () dione ids pl>
Date: Mon, 9 Jan 2006 13:50:56 +0100 (CET)



On Mon, 9 Jan 2006, Barrie Dempster wrote:

On Sun, 2006-01-08 at 22:20 -0500, Valdis.Kletnieks () vt edu wrote:
The first is just user idiocy, and CM Kornbluth told us what the chances of
fixing *that* problem are.

But what retro-monkey programmer on the cutting edge of the Kornbluth Kurve
thought that the API to permit the second was in any possible way a Good
Idea???

When security mechanisms add what feels like too much complexity to a
task the user (and the programmer) will actively circumvent them.

Another aspect might be the cost/tax to get your drivers certified.
I don't know the process myself, but chances are you would have
to pay, pay big, and pay whenever you released an update.

(Has anyone seen a certified Windows driver that wasn't bundled with a MS
product?)

I'm surprised nobody's skipped the hassle and just installed their own
root cert. The fact the installer's running as Administrator implies Game
Over in security terms, anyway.

James
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: