|
|
|
|
|
by wyager
3491 days ago
|
|
> There is no good reason to avoid implementing extended access controls when the greater security and control they provide is irrefutable. Disagreed. MAC is a crutch and a hack, not a solution. We should prefer not to rely on half-assed, overcomplicated, and formally unverifiable palliative measures. If you want security, you fundamentally must use secure software. No amount of sandboxing or access control wrapped around a vulnerable garbage heap is going to stop the garbage heap from getting hacked in the first place. |
|
The refrain of OpenBSD supporters is, "It's not necessary and won't help..."
The reality in field deployments, "It was and did."
QED.