Europe funds secure operating system research
itworld.com
itworld.com
http://unqualified-reservations.blogspot.com/2007/07/my-navr...
The lily needed no gilding at all, and it certainly did not need to be nanofabricated from isotopically pure, individually selected gold atoms. Academic CS researchers at the time, for whatever ridiculous reason (probably something to do with microkernels), thought that there should be many more fine-grained security transitions in an OS environment. In fact if anything the trend is away from multiuser computing and toward virtualized or "shared-nothing" designs in which communication between protection domains is minimal.
So we have different meanings of security flaw. Probably because you are thinking of the security of a website, where I am more interested in securing the average users PC.
If a dent is really going to be made in this problem, it's going to happen in Flash Player (or its more recent analogs, like Google NaCL).
However the question on the table is research. We should be researching security models that don't rely on the user to manage the complexity.
Minix, from what I have read, isn't going to be a sufficient enough advance to get the man on the street to adopt it. For that to be true it would have to significantly easier to manage. While he advocates the principle of least authority, he isn't currently innovating on how that authority gets passed on to the programs. A lack of mechanism generally means it is up to the user to do so, which puts some work load and cognitive effort on the user.
Remind me again why we're a member of the EU?