coda: why most systems get hacked - they authenticate claims
This commit is contained in:
@@ -310,3 +310,19 @@ part of this system may ever accept name-based trust:
|
||||
Succession passes comprehension and obligation, never identity.
|
||||
No successor becomes a ghost of the founder; the dead keep their
|
||||
singular selves and the living take up their own.
|
||||
|
||||
### Coda
|
||||
|
||||
Will:
|
||||
|
||||
"That's why most systems get hacked."
|
||||
|
||||
The corollary, stated as diagnosis: breaches are rarely the defeat
|
||||
of mathematics — AES has never been beaten in battle. Systems fall
|
||||
because they AUTHENTICATE A CLAIM. Passwords are answers to "who
|
||||
are you?", and answers can be phished, guessed, reused, extorted,
|
||||
or talked out of someone. The lock was never the weak point; the
|
||||
QUESTION was. Every system that accepts an identity claim inherits
|
||||
every lie ever told about an identity. Proof-of-possession systems
|
||||
have no such surface: you cannot phish a man out of what he is,
|
||||
only out of what he merely knows about himself.
|
||||
|
||||
Reference in New Issue
Block a user