Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Make software secure-by-default, make it difficult to override defaults by accident, easy to override on purpose. This is the thought process that seems to be behind, for example, CyanogenMod's recent decision to disable root access by default.

To me, the essence of that quote is that any sane security model must include the vendor as a threat, but when I do not have control over my own hardware and software, I have little to no ability to respond to that threat. Moreover, without access to source code, I have little to no ability to audit my own security. Fundamentally, I do not believe in the idea that security can reasonably exist without auditability.



>must include the vendor as a threat

Or anyone who gets access to the vendor's database.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: