Early ’90s conceptions of security—both what makes it and how relevant it is/for whom—don’t match our expectations or what we consider state of the art today.
Early ’90s conceptions of security—both what makes it and how relevant it is/for whom—don’t match our expectations or what we consider state of the art today.
TCSEC Level C2 was intentionally designed to be a “baby’s first security certification” level meant to allow existing known insecure products to get a (low) rating so that commercial vendors could get familiar with the concept [1]. It, at no point, was ever meant to indicate any meaningful level of security was achieved, just that you filed the paperwork. In fact, Level B1, the level above C2, was meant to be the “training wheels” level. Microsoft has still never achieved a security certification in the successor standard, the Common Criteria, that has reached the “training wheels” level.
Microsoft security is a joke now and was a joke then, nothing has changed.
[1] https://www.stevelipner.org/links/resources/The%20Birth%20an...
You are wrongly extrapolating that the lowest levels of certification, that were literally designed to allow people incapable of more than box ticking to be rated on a unified scale, somehow applies to the levels that were designed to evaluate actual security.
That is like saying the Richter scale is useless because you can not even feel a 1.0 earthquake. That is the entire point. The scale can measure from very low to very high. You are complaining that the scale is useless because the lowest ratings are easy to get, yeah, duh, that is why they are low ratings.
However, you are correct for SOC. That is because the highest ratings are easy to get and are mere box ticking exercises. If the highest rating is easy, then the standard is useless for evaluating anything beyond that. This logic does not apply when a low rating is easy to get; that just means anything which can only get a low rating sucks.
(CompCert, a "formally correct C compiler", has had bugs found in it.)
Or are you arguing that these standards which require proofs of correctness are useless because proofs of correctness are much less impressive than box ticking?
Furthermore, I don't think anything except box ticking exercises exists or could ever exist.
You can only write down ways to make a process worse, not better.
One can, of course, apply proof of correctness to simple curcuits, where all possible inputs and outputs can be enumerated.
You can not prove non-trivial properties about all programs that could could ever exist with no false positives or false negatives.
You can prove non-trivial properties about almost every program.
For instance, if I want to disallow programs that will not halt, I can just reject any program with a unbounded loop. I may also reject programs with a unbounded loop that will halt, a false negative, but I do not care. I just want to be certain that I will never run a program that will not halt. I just decided: “will definitely halt for my purposes” even though the halting problem is unsolvable in general.
This is generically true and is why formal methods work at all.
But not as secure as the classic Mac OS!
https://web.archive.org/web/19991128124149/http://www.dtic.m...
> However, he said the Army has moved its web sites to a more secure platform. The Army had been using Windows NT and is currently using Mac OS servers running WebSTAR web server software for its home page web site. Unger said the reason for choosing this particular server and software is that according to the World Wide Web Consortium, it is more secure than its counterparts.
That’s a rather dubious conclusion if based on that criteria.