IAB-PrivSec-program / draft-iab-privsec-confidentiality-mitigations

The Internet Draft recording the program's draft on mitigating confidentiality threats
0 stars 3 forks source link

Non-sequitur regarding "universal credentials" #22

Open martinthomson opened 8 years ago

martinthomson commented 8 years ago

Maybe someone was concerned about backdoors, or something, but this statement is entirely without context.

Protocols and security measures protecting against active attacks must also limit the impact of compromise and malfeasance by avoiding systems which grant universal credentials.

If my inferences about this statement are correct, then it should still be removed. In its place, a discussion of the virtues of things like the principle of least privilege and how that might limit the damage from inadvertent or coerced bad behaviour.