drwex: (pogo)
drwex ([personal profile] drwex) wrote2013-10-18 06:30 pm
Entry tags:

Another of those analogies

https://freedom-to-tinker.com/blog/felten/a-court-order-is-an-insider-attack/

Ed Felten poses the simple proposition that "a court order is an insider attack." The point he's making is that - from the point of view of system design - you cannot know the motivations nor context of an insider extracting data from a system. One example is a legal court order for a suspect's email; the analogous example is an extortionist's demand made against a vulnerable employee. Technologically, if you design a system to permit the first use you cannot then design it to prevent the second.

[identity profile] r-ness.livejournal.com 2013-10-19 04:57 am (UTC)(link)
Yeah, Bruce Schneier posted about that recently. The comments section is the usual sometimes off-the-wall, sometimes insightful collection of notes by various security geeks.