From: Ian Grant <ian.a.n.grant-gM/Ye1E23mwN+BqQ9rBEUg@public.gmane.org>
To: "Taylan Ulrich Bayirli/Kammer"
<taylanbayirli-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>,
guile-devel-mXXj517/zsQ@public.gmane.org,
lightning <lightning-mXXj517/zsQ@public.gmane.org>,
schellr-EkmVulN54Sk@public.gmane.org,
Richard Stallman <rms-mXXj517/zsQ@public.gmane.org>,
Theo deRaadt <deraadt-T7FYYhErWq4AvxtiuMwx3w@public.gmane.org>,
Linus Torvalds <torvalds-3NddpPZAyC0@public.gmane.org>,
Markus Kuhn
<Markus.Kuhn-kDbDZe0LBGWFxr2TtlUqVg@public.gmane.org>
Subject: Re: GNU Thunder
Date: Mon, 8 Sep 2014 21:00:30 -0400 [thread overview]
Message-ID: <CAKFjmdzOJGA8KUG99xD+JGydXVLcHj6=BWZd_YC716LPy_v4_w@mail.gmail.com> (raw)
In-Reply-To: <87iokzefgv.fsf-uVHYNzLEwI3da1iInxiBqA@public.gmane.org>
[-- Attachment #1.1: Type: text/plain, Size: 2331 bytes --]
On Sun, Sep 7, 2014 at 9:18 AM, Taylan Ulrich Bayirli/Kammer <
taylanbayirli-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org> wrote:
> Also, since we define a simple semantics for which a new evaluator could
> be implemented at any time in any language, it becomes ever more and
> more implausible that *all* tools everywhere have been previously
> "patched" to infect all the evaluators being implemented or
> automatically generated in all kinds of different environments.
>
Dear Taylan,
Thank you. Yours is a concise and accurate statement of what I am
proposing. If I had been able to write something that clear then I doubt
there would have been any misunderstanding between Richard and I.
What I mean by a semantic fixed point is a fixed point of the _actual_
semantics, not the syntactic forms of the textual representations such as
appear on a terminal window or in a text file dump. So we are going to do
this under the assumption that the systems we are using _are in fact
compromised._
One obvious consequence of this is that the assurance we obtain is always
in the form of actual knowledge. So if, say, the debian build team get
together and go through such a validation exercise, then they can state
they have done this, and document and explain the results on a web page,
but this will not give anyone apart from them the knowledge of the security
of the debian build process, because the build team may have been
infiltrated. But if another team of system administrators at a university,
say, were to repeat the debian exercise, using a different implementation
of the reference compiler, one they created themselves, on systems that
were isolated as far as they could determine, and perhaps whilst wearing
tin-foil hats as William recommends, then they would know they shared that
knowledge with the debian team. But no-one else would have good reason to
believe that what _they_ downloaded from the debian mirrors was actually
the real deal. So what we will be publishing is not a certificate of
security, it is a method of _actually knowing_ that the system is _very
probably_ secure. So it is extremely important that we explain very, very
clearly what this form of a trusted computing platform really is.
Thank you for your clarification. And please post any further thoughts you
might have to this thread.
Ian
[-- Attachment #1.2: Type: text/html, Size: 2792 bytes --]
[-- Attachment #2: Type: text/plain, Size: 159 bytes --]
_______________________________________________
Lightning mailing list
Lightning-mXXj517/zsQ@public.gmane.org
https://lists.gnu.org/mailman/listinfo/lightning
next prev parent reply other threads:[~2014-09-09 1:00 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <CAKFjmdzP89qSD03_MGqS1UawQvaq6yvme-abKcmLuA8DfUQE+A@mail.gmail.com>
[not found] ` <E1XKsRt-0002zo-64@fencepost.gnu.org>
[not found] ` <CAKFjmdyUphk2LmDdDE_7gkDSKAu4COurtvafBwO5XwCgyM1OfA@mail.gmail.com>
[not found] ` <E1XLP5I-0005zC-Sn@fencepost.gnu.org>
[not found] ` <E1XLP5I-0005zC-Sn-iW7gFb+/I3LZHJUXO5efmti2O/JbrIOy@public.gmane.org>
2014-08-25 20:59 ` GNU Thunder Ian Grant
2014-08-25 22:56 ` Trusting trust Ludovic Courtès
[not found] ` <CAKFjmdxt4jWAHAYXjzwPeUw+dTUBTPC94YJDNifsO7JVkNHjTQ-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2014-08-31 0:20 ` GNU Thunder Richard Stallman
[not found] ` <E1XNssG-00083e-BB-iW7gFb+/I3LZHJUXO5efmti2O/JbrIOy@public.gmane.org>
2014-09-03 1:52 ` Ian Grant
2014-09-03 12:50 ` Richard Stallman
[not found] ` <E1XPA13-0002hD-Kp-iW7gFb+/I3LZHJUXO5efmti2O/JbrIOy@public.gmane.org>
2014-09-04 1:53 ` Ian Grant
[not found] ` <CAKFjmdyc0D5vYBK=rQKzKNK+WRmWhkkL-RXqBMSHvhOzX3fHiw-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2014-09-05 1:50 ` Richard Stallman
[not found] ` <E1XPifZ-0004g6-KA-iW7gFb+/I3LZHJUXO5efmti2O/JbrIOy@public.gmane.org>
2014-09-06 1:40 ` Ian Grant
[not found] ` <CAKFjmdwEs8TtPZjXWDYKoQXz4FEKy6p3T9+8jWLMY87Onn=VaQ-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2014-09-06 8:32 ` William ML Leslie
[not found] ` <CAKFjmdzzRoTdzWxAOh2byRbWDtszWZtt8Z2k0eLCFYR+qmAC9g@mail.gmail.com>
[not found] ` <CAKFjmdzzRoTdzWxAOh2byRbWDtszWZtt8Z2k0eLCFYR+qmAC9g-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2014-09-07 1:39 ` William ML Leslie
2014-09-07 13:18 ` Taylan Ulrich Bayirli/Kammer
[not found] ` <87iokzefgv.fsf-uVHYNzLEwI3da1iInxiBqA@public.gmane.org>
2014-09-09 1:00 ` Ian Grant [this message]
2014-09-06 15:09 ` GNU Thunder [Comments on Subversins from Ian Grant and Richard Stallman of GNU] Dr. Roger R. Schell
2014-09-06 17:49 ` GNU Thunder Ian Grant
2014-08-24 0:42 Ian Grant
2014-08-24 4:07 ` Richard Stallman
2014-08-24 5:13 ` Mike Gerwitz
2014-08-25 20:23 ` Ian Grant
2014-08-27 2:20 ` Stefan Monnier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://www.gnu.org/software/guile/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='CAKFjmdzOJGA8KUG99xD+JGydXVLcHj6=BWZd_YC716LPy_v4_w@mail.gmail.com' \
--to=ian.a.n.grant-gm/ye1e23mwn+bqq9rbeug@public.gmane.org \
--cc=Markus.Kuhn-kDbDZe0LBGWFxr2TtlUqVg@public.gmane.org \
--cc=deraadt-T7FYYhErWq4AvxtiuMwx3w@public.gmane.org \
--cc=guile-devel-mXXj517/zsQ@public.gmane.org \
--cc=lightning-mXXj517/zsQ@public.gmane.org \
--cc=rms-mXXj517/zsQ@public.gmane.org \
--cc=schellr-EkmVulN54Sk@public.gmane.org \
--cc=taylanbayirli-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org \
--cc=torvalds-3NddpPZAyC0@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).