Interesting to read in retrospective, at least, now security managers are generally considered to be a dead end. You can see the assumptions it was built on, how they arrived at the design, and how it failed.
They mostly failed, specially in Java (JAAS) and .NET (CAS) case, because almost no one bothered to actually configure them properly, beyond the gotchas that they also had.
So it is up to using OS features instead, which are also struggling to reinvent themselves, beyond user/admin legacy models into more sensible ones.
3 comments
[ 5.4 ms ] story [ 24.3 ms ] threadvery endearing persona
So it is up to using OS features instead, which are also struggling to reinvent themselves, beyond user/admin legacy models into more sensible ones.