Sunday, August 31, 2008


It is interesting to compare this with security architectures which are very long lived. Kerberos was done in the late 80s, certificates in the 70s and 80s, along with the basic cryptographic underpinnings like RSA. So there is not much new under the sun on the security side.

The problems are of course that 1) as you point out the software architectures change

and 2) the threat models change. Think the folks in the 70s foretold Amazon?

I put together a chart on this


This tells me that security folk need to spend a lot more time adapting deployment models.

