Secure Coding mailing list archives

"Bumper sticker" definition of secure software


From: michaelslists at gmail.com (mikeiscool)
Date: Mon, 24 Jul 2006 08:42:10 +1000

As a result, really secure systems tend to require lots of user training
and are a hassle to use because they require permission all the time.

No I disagree still. Consider a smart card. Far easier to use then the
silly bank logins that are available these days. Far easier then even
bothering to check if the address bar is yellow, due to FF, or some
other useless addon.

You just plug it in, and away you go, pretty much.

And requiring user permission does not make a system harder to use
(per se). It can be implemented well, and implemented badly.


Imagine if every door in your house was spring loaded and closed itself
after you went through. And locked itself. And you had to use a key to
open it each time. And each door had a different key. That would be
really secure, but it would also not be very convenient.

We're talking computers here. Technology lets you automate things.


Crispin

-- mic


Current thread: