upvote
> Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”.

I work in secure systems and it’s shocking how many people believe this - the incentives from management are all about it too.

reply
<< And as such, it’s much more expensive. And nobody wants to pay.

Eh. If only it was that simple. I mean, yes, money is always a factor, but not nearly as big of a factor as 'my convenience outweighs pretty much everything ( until it causes sufficient amount of havoc.. and even then.. )'. You can see it in just about everything. It is not just the money. It is the convenience that drives most of the unsecure behavior.

reply
The bank has the best doors, the best locks, and the best cameras, and it is patrolled by a guard who props the doors open to so he doesn't have to keep fooling with the locks and points the cameras the other way to extend his smoke break. SeL4 would be another system used by humans.
reply
It's always possible to break a perfect system by moving an additional layer of abstraction outward, and attacking one of the assumptions upon which it's built. Some of our era's highest security systems - game consoles - have been broken by undervolting them until the logic failed.
reply
There's absolutely no way to account for humans, who can be tricked, or pressured, or just make human sized mistakes.
reply
I once worked on AUD 450M banking project, the root password was kept in a kickstart file and unchanged, root SSH was allowed. The bank didn't care until I told the external security auditor who included it as part of their report.
reply
[dead]
reply