comma ([identity profile] q10.livejournal.com) wrote in [personal profile] bnewman 2007-02-11 08:14 pm (UTC)

also, security enforcement through the code/data dichotomy is only as good as the engineers involved - there's a long and rich history of discovering bugs which can get stuff imported as data placed someplace it doesn't belong, and subsequently read as code, and also a distinguished history of people creating, apparently without realizing it, ‘data’ formats that are actually code.

and these are going to be government engineers. probably Social Security Administration or IRS engineers.

and then we have to trust said government engineers not to deliberately compromise your security for their own or their masters' evil purposes, although i suppose certain political measures could make that sufficiently unlikely.

Post a comment in response:

This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting