Elektrine lite

← Feed

@zmanion@infosec.exchange

2026-06-30 15:27 UTC

@adamshostack@infosec.exchange @pgl@infosec.exchange @jayjacobs@infosec.exchange I'm initially a fan of the explicit/implicit security policy violation, I think we'd need both: Someone could explicitly declare that they allow remote, unauthenticated access or control of a system, but everyone else may treat that as an implicit violation.

Replies (1)

  • @zmanion@infosec.exchange @pgl@infosec.exchange @jayjacobs@infosec.exchange Thanks, and yes, we absolutely need both. This is the value of a published threat model: you can decide that based on a prior commitment. For example, Wikipedia works while allowing remote unauthenticated changes, most other folks don't do so. Also, as I somehow managed to get through MS PR, "Autorun isn't a bug, it's a feature." As much as the world would have liked to, you can't credibly slap a CVE on a questionable design choice. Which leads to a wrinkle for your definition: Autorun had an understood possible disposition towards abuse. (I think Charlie Kaufman had an internal paper on that in the runup to XP or maybe SP2.)

    Open ##3517552