cyber-"terrorism"?
David Wagner
daw at mozart.cs.berkeley.edu
18 Sep 2002 21:51:22 GMT
Brian Gladman wrote:
>I think a small security kernel running on a VM
>machine can improve security significantly when compared with what we have
>now.
I agree with this. However, I think we'd get 95% of the improvement
by adding just the small security kernel, without the secure boot.
>If we can get
>strong process separation and full control of memory and peripheral access
>we don't need anything more from hardware.
[...]
>I am sad that David and Peter don't see this as I think its a fundamentally
>better way to go than the whole of TCPA.
Oh, if I had to choose between your proposal and TCPA, I'd take your
proposal: it does seem better than TCPA. If nothing else, semi-coercive
applications would be harder to build with your proposal than with TCPA.
Taking away some pieces of TCPA would be great.
I must have misunderstood your position. I thought you were supporting
TCPA, rather than suggesting an alternative to TCPA. My apologies for
my confusion.