Hacker News new | ask | show | jobs
by mikewarot 1698 days ago
Here's a tortious causal chain that I think explains everything.

Computing evolved up the point of Multics. The military has always been a driver of computing research to some extent. The deployment of computing resources to help plan airstrike missions showed a critical need for developing a system in which a single computer could handle multiple levels of secure data. The research resulted in capability based security, which was in the process of being folded into Multics.

The folks at Bell labs happened to have a spare DEC machine, and having seen the complexity of Multics, decided to eschew capabilities, and instead relied on a much simpler, and quicker to implement system based on group and user IDs into Unix. This quickly spread to be the defacto multi-user model of security across the academic world.

Over time, PCs came to dominate the low end of computing. When it came time to implement multi-user and network systems, the Unix model, or a slightly upgraded model, based on access control lists (as in Windows) effectively ate the world.

Eternal September happened, and the internet went commercial. With this, we now have persistent internet, and are stuck with the oversimplified security model from Linux and Windows dominating everything. As such, no computer is actually secure.

Because computers aren't secure, you can't trust programs that run on them to be secure. Because of this, you can't trust the web browser on your computer to not get you into trouble if you click on the wrong link. This results in a very strong tendency to avoid clicking on links from unknown domains and sites among the general public.

Because the audience has settled into a few walled gardens, most of the authors of content have had no choice but to move to do the same.

And here we are, because capability based security is seen as too complicated (it doesn't have to be, in fact it can be simple to use), we're all stuck with facebook, twitter, etc.

2 comments

I generally don't like to bring any attention to language, but I do wonder if you mean tortious.
Yeah, I really don't think you should (and neither should I), since we're never as smart as we think we are.

The author did not mean tortious, but instead tortuous. But one immediately gathers this from the context anyway. Who cares what the spelling is?

"Tortious" is just as self-deprecating in that sentence. Is it an unfair slight to identity-based security systems, or a overlong Rube Goldbergian explanation of how the current state of the internet came to be?

> Who cares what the spelling is?

People trying to figure out whether an author means "tortious" or "tortuous."

I think it's very respectful to the author to make sure you're reading what they intended to write. When it comes to anything I write/say, please don't separate the art from the artist - just ask the artist what he meant to say.

Thanks to you I just learned the word tortious!
misspell one word... and it goes of on a tortuous tangent ;-)