Hacker News new | ask | show | jobs
by Karrot_Kream 1842 days ago
> Because the lessons of capability based security were ignored for decades, and not taught, the common consensus is that computers can never be made secure, and your best hope is to hire the smartest people in the world, at less than the average market rate, to secure your systems.

I presume the OP is a fan of capability-security and while I'm not an expert on capabilities, I agree they can go a _long_ way to mitigating risk. Unfortunately, none of the mainstream OSs even offer a smidge of a way of actually working with capabilities. Google's recently laughed Fuschia _does_ support capabilities out of the box, but they have a long way to go before they're regarded as mainstream.

1 comments

Yes, I am a long time (2005) fan of Capability Based Security.

Yes, Fuschia and Genode both have a way to go before they are good enough for general purpose use.