[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Hack Microsoft?
It should be possible to FOIA the evaluation that
led to the C2 status on this. That would be one good
avenue to start looking at it.
At the end of the process there should be a document
that shows how the OS meets each of the C2 requirments
and what aspects of the software were considered as
well.
Things like the state the OS was running under at the
time, (network vs. non-network etc.) are important
considerations in evaluations.
And I would not be too surprised at all if the "C2"
designation was relativly bogus. This sort of thing
can get much like the anti-crypto crowds arguments.
Highly political with little basis in rationality.
Since I've seen stuff like a ported version of Unix's
"ps" utility, and know NT runs a microkernel, I can think
of a hell of allot of ways it'd be possible to fail
it right out of the box... Considering that it has the
cpacity to do all sorts of network stuff, including FTP
& the like, I wonder how the hell they passed any audit
requirements. Probably a "Well it runs in a single user model,
we don't need to have strong audit requirments".
My point basicly being that I would consider the C2 designation
for this to be broken coming out of the box unless I saw
proof that it was otherwise. To operate it in a C2 required
environment without consideration of how & under what
conditions the rating was achived would be criminaly
irresponsible.
Tim Scanlon
________________________________________________________________
[email protected] (NeXTmail, MIME) Tim Scanlon
George Mason University (PGP key avail.) Public Affairs
I speak for myself, but often claim demonic possession