Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The Devil And The Deep Blue Sea
Jon Lasser, 2002-07-17

Why Microsoft's Palladium project threatens to send Linux and open-source into exile.

Comments Mode:
And the major security goals don't need hardware 2002-07-18
Nicholas Weaver (1 replies)
Assuming you trust the owner of the computer, the hardware offers effectively no additional security over just constructing the software right. The OS can enforce code signing and similar restrictions, it can construct the same sandboxes for untrusted code, and do everything else paladium claims to do to help the user.

The only thing the OS can't do is to keep secrets from the owner of the machine. Thus the hardware is useful for ligitimate DRM and less legitimate fair use restrictions, preventing piracy by authenticating, etc, under the assumption that it is much harder for the box owner to manipulate the hardware instead of the OS.

This is the biggest tipoff that paladium isn't really intended for the benefit of the users: It doesn't TRUST the machine owner, the machine owner is the enemy. Do we want the systems we buy to not trust us?


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/96/14402#14402
The Devil And The Deep Blue Sea 2002-07-18
Anonymous (6 replies)
The Devil And The Deep Blue Sea 2002-07-18
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous (1 replies)
The Devil And The Deep Blue Sea 2002-07-23
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
The Devil And The Deep Blue Sea 2002-07-22
Anonymous
The Devil And The Deep Blue Sea 2002-07-18
Anonymous
Unbelieveable 2002-07-18
Anonymous (5 replies)
Unbelieveable 2002-07-19
Anonymous (2 replies)
Unbelieveable 2002-07-20
Anonymous
Unbelieveable 2002-07-21
Anonymous
Unbelieveable 2002-07-19
Anonymous
Unbelieveable 2002-07-19
Martin Schoch
Unbelieveable 2002-07-20
Anonymous
Unbelieveable 2002-07-20
Anonymous
The Devil And The Deep Blue Sea 2002-07-18
blacklight (1 replies)
The Devil And The Deep Blue Sea 2002-07-23
Anonymous
Take a chill pill 2002-07-18
Anonymous Bastard (3 replies)
take your own advice 2002-07-19
rsullivan@art-line.com (1 replies)
Re: take your own advice 2002-07-19
Anonymous Bastard (2 replies)
Re: take your own advice 2002-07-19
Anonymous (2 replies)
happy x86 processor world? riiiiight... 2002-07-19
Anonymous (1 replies)
Re: take your own advice 2002-07-21
Anonymous
Re: take your own advice 2002-07-19
Anonymous
Re: Take a chill pill 2002-07-19
Jm4n
Take a chill pill 2002-07-21
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous (1 replies)
OSS version of Palladium 2002-07-20
Abri
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
SkyLeach
Palladium and buffer overflows 2002-07-19
Anonymous (6 replies)
Palladium and buffer overflows 2002-07-19
Anonymous
Palladium and buffer overflows 2002-07-19
Anonymous
Palladium and buffer overflows 2002-07-20
bufferoverwhelmed
Palladium and buffer overflows 2002-07-20
Anonymous
Palladium and buffer overflows 2002-07-21
Anonymous
Pride goeth before a Fall 2002-07-19
Anonymous
No evidence for these claims 2002-07-19
Tamperbell (2 replies)
No evidence for these claims 2002-07-22
Anonymous
No evidence for these claims 2002-07-23
Anonymous
The Devil And The Deep Blue Sea 2002-07-19
Anonymous
Alternate hardware 2002-07-20
Anonymous
The Devil And The Deep Blue Sea 2002-07-20
Anonymous
THE DEVIL AND THE DEEP BLUE SEE 2002-07-20
NSS ( Network Ssecurity Systems)
It's all about trust 2002-07-20
Anonymous
The Devil And The Deep Blue Sea 2002-07-21
Anonymous
The Devil And The Deep Blue Sea 2002-07-22
Anonymous
The Devil And The Deep Blue Sea 2002-07-22
Anonymous (1 replies)
The Devil And The Deep Blue Sea 2002-07-23
Anonymous
The Devil And The Deep Blue Sea 2002-07-22
Anonymous
The Devil And The Deep Blue Sea 2002-07-23
Anonymous (1 replies)
The Devil And The Deep Blue Sea 2002-07-23
Anonymous
Copyright and Anti-piracy laws 2002-07-29
Anonymous
It is time for "security enhanced linux" to be put on the front burner NOW! 2002-07-29
100% of distros should be 100% SE Linux







 

Privacy Statement
Copyright 2009, SecurityFocus