Astute Inequalities
At the 1997 JavaOne conference, the Java Security Architect, Li Gong, gave a presentation on Java security. One of his slides is particularly useful for understanding Java security and cryptography. It contains a list of five inequalities, to which I’ve added explanations.[3]
- Security != cryptography
Adding cryptography to an application will not make it secure. Security is determined by the overall design and implementation of a system; cryptography is a tool for building secure systems.
- Correct security model != bug-free implementation
Even if you have a great design (model), bugs in your implementation can be exploited by attackers. With a correct design, however, you can focus on debugging the implementation. If your design is not secure, you have to go all the way back to the drawing board before you even think about debugging.
- Testing != formal verification
Although testing is a great idea, it won’t prove to anyone that a system is secure. In the real world, “formal verification” means extensive reviews of your system’s design and implementation by knowledgeable security people. A cheap way to do this is to post your application’s source code to the Internet and invite people to poke holes in it.
- Component security != overall system security
System security is a chain, and any link can be broken. Even if the components of a system are secure, they may interact in insecure ways.
- Java security != applet containment
A lot of the buzz about Java security has ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access