|
|
|
|
|
by tptacek
2370 days ago
|
|
This is kind of a strange analysis. Sort of infamously, Dan Bernstein, who is sort of a pioneer in these privilege-separated defensive designs, foreswore them in a retrospective paper about qmail. Really, though, I'm not sure I'm clear on the distinction you're drawing between attack surface reduction and privilege separation, since both techniques are essentially about reducing the impact of bugs without eliminating the bugs themselves. You might more coherently reduce security to "mitigation" and "prevention", but then that doesn't make much of an argument about the topic at hand. |
|