⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 15525

📁 神经网络昆斯林的新闻组分类2006
💻
字号:
Newsgroups: sci.cryptPath: cantaloupe.srv.cs.cmu.edu!crabapple.srv.cs.cmu.edu!bb3.andrew.cmu.edu!news.sei.cmu.edu!fs7.ece.cmu.edu!europa.eng.gtefsd.com!gatech!howland.reston.ans.net!usc!sdd.hp.com!nigel.msen.com!yale.edu!yale!cs.yale.edu!news-mail-gateway!daemonFrom: Grant@DOCKMASTER.NCSC.MIL (Lynn R Grant)Subject: Another key registration body bites the dust (IMHO)Message-ID: <930420210707.956366@DOCKMASTER.NCSC.MIL>Sender: Grant.CA1@DOCKMASTER.NCSC.MILOrganization: Yale CS Mail/News GatewayDate: Tue, 20 Apr 1993 21:07:00 GMTLines: 46One of the candidates that has been suggested for a key registrationbody is the ACLU.  I think this is poor choice.   The ACLU isessentially a group of auditors: they audit how people's civilliberties are administered.  Traditionally, auditors do not like to getinvolved in the design or operational aspects of things, and with goodreason.When I was a systems programmer, it always infuriated me that theauditors would come in and tell us our implementation stunk from asecurity point of view, but wouldn't tell us how to fix it.  I alwaysfigured they just liked to critcize, without doing the work to help fixthe problem.Then I took a stint as an auditor, and I found out the real reason.Auditors don't like to recommend solutions, because it puts them in abad position if they have to criticize the implementation later.  Theauditee can say, "Well, you told us this way would be OK."  Itcompromises the independence that is a necessary part of the auditor'sjob.Taking the case at hand, suppose ACLU becomes a key half registrar.Suppose that, perhaps through some error on ACLU's part, a key half getsaway that shouldn't, and is used to deprive someone of her civilliberties.  The ACLU gets wind of this, and wants to take it to court.But they end up being at the same time on the side of the defendantand of the plaintiff, which is not an easy position to be in.There are exceptions to the complete independence of auditors: at oneplace where I worked, when payroll checks were printed, they were signedautomatically by a signature drum on the bursting machine.  This drumwas kept by the auditors (who also kept the check stock), andwas brought down to Data Processing when it was time to do the checks.I believe the difference between this situation and the key registrationsituation is that it is fairly obvious when it is time to do the payrollchecks:  if they were done yesterday, and someone wants to do them againtoday, he better be able to produce yesterday's checks so that they canbe destroyed.  Determining which of the many requests for key halves arelegit is a trickier process, one much more prone to mistakes that couldput the ACLU in a protecting-the-client versus protecting-the-ACLUconflict of interest.As always, my opinions are my own.Lynn GrantGrant@Dockmaster.NCSC.MIL

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -