Regardless as to wether or not Ethos is the next widespread OS, that line rings very true.
Regardless as to wether or not Ethos is the next widespread OS, that line rings very true.
"Security" is an invisible quality, by which I mean it cannot be easily observed and because of that it cannot be easily compared and because of that is not going to drive adoption.
This is in contrast to visible qualities: price, performance, availability of the source code and its licensing terms, size of the ecosystem (number of applications for the OS, number of books, articles, conferences, programmers who know how to program for it) etc.
How exactly will you demonstrate that Ethos is more secure than, say, OpenBSD?
One idea that could improve both security and the ecosystem would be a capability based design. Separating components through standard protocols/interfaces could enable something like current mobile permissions to be backed by different implementations (including virtualized/sandboxed ones), in some cases swapped out by users like commands in a shell pipeline.
I haven't seen much work in this direction; does anybody think this would or wouldn't work?
http://sandstorm.io http://kentonv.github.io/capnproto/ http://plash.beasts.org/powerbox.html http://css.csail.mit.edu/mylar/ https://www.meteor.com
For web-based service pipelines under user control:
N: So will I have to change all my passwords?
ME: Yes, you should.
N: That's a lot of work.
ME: Yes, but if you don't someone is likely to break into at least some of your accounts. At least make sure you've changed the password to your mail account, and set up two factor auth [very simplified explanation of what two factor auth involved], and check that all accounts you care about use that mail account for password recovery.
N: I'm not sure if I can be bothered.
This is a relatively technically experienced user.
It fits with other experience I've had, that security is perceived as a hassle until it's too late and then users do the bare minimum, even in the face of ongoing threats.
Corporate users might help drive adoption, but only if the cost and hassle is limited enough, and the damage of not going there is high enough.
OpenBSD has un-typed IO. Typed IO gives you guarantees that un-typed IO can never give you. For starters, a number that doesn't validate properly as an Int, for instance, will simply not be able to pass through, potentially stopping if not Heartbleed then bugs like Heartbleed.
Don't you think companies and other interests would like stronger guarantees, especially when they're running applications that protect information that hackers and foreign governments and other companies would love to see?
Demonstration is not the only means by which someone can be convinced.
Consensus among experts that the fundamental building blocks offer a superior security model will convince a lot of people (directly or indirectly).
Would living in a world where events like Heartbleed will occasionally occur, but one where we still have the relative freedom to modify, examine, and generally "hack" our software and hardware in ways the original creators didn't approve of, be better than one of "absolute security" and highly restricted, locked-down devices controlled by corporations (and possibly the government)? I think the whole security situation has reached a point where people have to really start thinking about the tradeoffs that are happening, and realise that all this technology - as much as it can protect against external attacks and defend the users - can also be just as easily employed by others to oppress them. Once again, the infamous Ben Franklin quote comes to mind.
Yet Microsoft XP/7/8 are arguably the most insecure operation systems, and the BSD flavors are arguably the most secure, yet have the lowest adoption rate.
People don't care about security they care about usability and simplicity.
But this is at odds with your previous observation, that BSDs have low adoption. They are vastly more simple than typical linux distros, a fact that linux users complain about when trying out a BSD system.
Of course design matters, a system designed from groun-up to be secure but even a Linux server with properly configured kernel patchets (grsec), process accounting, iptables, IDS, etc. Can be virtually impenetrable. Same goes for OpenBSD.
Secure operating systems are not new. IIRC Vax/VMS was build from ground-up with security in mind and was deployed by the military. Then exploits security issues started popping up.