Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why do you assert that all threat models have no temporal component?

A realistic attack that compromises a low privilege session may not be able to leverage that into higher privileges. Therefore, limiting the use of high privilege to a smaller window of time definitely reduces the attack surface.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: