-
Read more...
“Assurance is best addressed during the initial design and engineering of security systems, NOT as an after market patch. The earlier you include a security architect in your design process, the greater the likely hood of a successful and robust design. As the quip goes, he who gets to the (module) interface first wins.”
Brian Snow, Former Technical Director of the US National Security Agency (NSA), "We need Assurance", AusCERT 2008 -
Read more...
"Even a relatively small quantum computer, one that had a few tens of thousands of qubits, could consider so many different values at once that it would be able to break all known [ed: RSA, D&H, ECC, AES-128] codes commonly used for secure Internet communication.”
Prof Seth Lloyd of MIT, MIT Review 2008
-
Read more...
“Consider the use of smart cards ... for especially critical functions. Although more costly than software, when properly implemented the assurance gain is great. The form-factor is not as important as the existence of an isolated processor and address space for assured operations – an ‘Island of Security,’ if you will. Such devices can communicate with each other through secure protocols and provide a web of security connecting secure nodes located across a sea of insecurity in the global net.”
Brian Snow, Former Technical Director of the US National Security Agency (NSA), "We need assurance!", 1999-2008
| quote: Robert Morris, Systems built without requirements cannot fail |
Robert Morris, former Chief Scientist of the US National Security Agency (NSA), National Computer Security Center,1995 |
