Webs of Trust vs Trees of Trust

20 Apr
1993
20 Apr
'93
10:46 p.m.
I have worked with the NCSC (National Computer Security Center) on certifying operating systems according to the "Orange Book". As I understand RIPEM there is a tree of agencies such that everyone must trust all elements of the tree between him and the root. This is much ingrained in all of the legally mandated security systems that I am aware of. It assumes, at first glance, that there is a root, an inner sanctum, which is totally trusted by all. The Orange Book for operating system security has such assumptions embedded deeply. We had to essentially weeken our security features by disableing our "mutually supicious user" logic to meet their requirements.
It is a pervasive mind-set in military security.
11755
Age (days ago)
11755
Last active (days ago)
0 comments
1 participants
participants (1)
-
norm@netcom.com