Reply to post: Re: About time

Antivirus tools are a useless box-ticking exercise says Google security chap

Warm Braw

Re: About time

the benefit of that is in doubt

Well you're right in everything you say, which probably explains the downvote.

User-based permissions are not terribly useful when there is effectively only one user on the machine. Application whitelisting is a step in the right direction, but of course that's just an invitation to compromise whitelisted applications.

Each application should have a set of authorisations to do just enough to accomplish its job and it needs to get those authorisations transparently and, for the most part, explicitly - for example a user clicking "open" in a file dialog provided by the operating system would authorise access to a specific file - rather than by implicitly inheriting a user's authority and later using it against him. While too much user annoyance could be avoided by sensible defaults (specific locations where preferences, temporary files, etc, can be accessed), better security does depend to some extent on a bit more user inconvenience and I'm not sure this is something users will ultimately accept.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon