The Emperor's old armor

Bob Blakley · 1996

The traditional model of computer security was formulated in the 1970’s, when computers were espensive, solitary, heavy, and rare. It rests on three fundamental foundations: management of security policy describing the set of actions each user is entit.led to perform, integrity of the physical system, its software, and especially its security-enforcing mechanisms, and secrecy of cryptographic keys and sensitive data. The modern computing environment, with its rapidly accelerating complexity, connectivity, and miniaturization, is undermining all three of these foundations. Nevertheless, the newest “secure ” computer systems continue to be built on them. This paper argues that the traditional model of computer security is no longer viable, and that new definitions of the security problem are needed before the industry can begin to work toward effective security in the new environment. 1

Read the paper · More papers on PaperTik