Return to BSD News archive
Path: euryale.cc.adfa.oz.au!newshost.anu.edu.au!newshost.telstra.net!act.news.telstra.net!psgrain!news.uoregon.edu!news.emf.net!overload.lbl.gov!lll-winken.llnl.gov!news.larc.nasa.gov!news.msfc.nasa.gov!newsfeed.internetmci.com!primus.ac.net!news.cais.net!news.fc.net!usenet From: Linas Vepstas <linas@teleportal.com> Newsgroups: comp.os.linux.development.system,comp.os.linux.misc,comp.os.linux.networking,comp.unix.bsd.freebsd.misc,comp.unix.bsd.netbsd.misc,comp.unix.bsd.bsdi.misc,comp.security.misc Subject: Re: need secure OS to entrust millions to Date: 27 Feb 1996 03:58:42 GMT Organization: Freeside Communications, Inc Lines: 22 Message-ID: <4gtvhi$9a2@villa.fc.net> References: <4gi6t6$3h9@lace.colorado.edu> <nc0453Dn96w6.93F@netcom.com> <y5ad974s4v4.fsf@graphics.cs.nyu.edu> <4gqf17$1lr@cynic.portal.ca> <4gqgj5$r1g@zip.io.org> NNTP-Posting-Host: teleportal.com Xref: euryale.cc.adfa.oz.au comp.os.linux.development.system:18309 comp.os.linux.misc:89228 comp.os.linux.networking:30090 comp.unix.bsd.freebsd.misc:14598 comp.unix.bsd.netbsd.misc:2359 comp.unix.bsd.bsdi.misc:2509 comp.security.misc:22783 cbbrown@zip.io.org (Christopher B. Browne) wrote: > > > b) If you're paying the extra bucks for a B-1 or B-2 secured OS > environment, then you certainly *do* get a representation from the > manufacturer that the software has that level of security. Umm, yes, you may get that, but you do NOT get any assumption of liability, which is the argument that started this thread. If you loose a million dollars because of a bug in AIX, Solaris, HP/UX, Irix, don't think for a moment that the manufacturer will reimburse you for your losses. This has nothing to do with B-1, B-2 or B-3. I have yet to see any software license that provides this sort of warrenty. You *MIGHT* find an insurer who might be willing to insure against losses, although I've never heard of such a thing. I would also assume that insurers would be more comfortable with a B-2 rated system, compared to B-1 compared to unrated. --linas