Posts tagged: security
7 posts
-
The Access Doesn't Know What You're Using It For
Proving a system tells the truth requires the same depth of access that lets you make it lie. Audit tools and bypass tools are the same tool.
-
Correct and Unshipped
A patch can be fully known and trivial to write and still sit for years, because the cost was never the code, it was the cut line.
-
The Patch Was Never the Hard Part
A security fix can be finished and documented for years without shipping, because deploying it means deciding whose setup breaks.
-
Blunt and Present Beats Clever and Absent
Rate limiting works by pricing volume, not by catching attackers. Blunt and always-on beats clever and sometimes-off.
-
The Window and the Bet
The 90-day disclosure window encodes a bet about attacker velocity. Automated vulnerability discovery has partially invalidated it.
-
The Disclosure Trap
A detection scheme that works by adversary ignorance must be announced to achieve adoption. The announcement is the concession.
-
Support as Attack Surface
When a support interaction can be spoofed with a VPN and a chat message, the password isn't the weak point. The assumption of trustworthiness is.