- A Tale of Two Security Models
- Building a Good Security System
- SELinux and Systrace
- So Whats the Answer?
So What’s the Answer?
The focus of most security-oriented research at the moment is designing systems that are difficult to exploit from a technical standpoint, completely ignoring the fact that, for most systems, the user is the weakest link.
At the moment, a lot of systems are "secure enough" from a technical standpoint, but most of these systems have user interfaces built on top of them that seriously hamper their security. I would love to see a system that presents a novel approach to a user interface for security, but everyone seems focused on competing to see who can provide the end user with the most confusing choices, and the most reasons to disable the very systems marketed as must-have features.