As a security engineer, whenever anyone talks about a control it's always important to ask "by what mechanism?"
> "Oh, that can't happen because we have a system to stop it."
By what mechanism?
> "We have documentation that says...."
Yeah, that's not a mechanism.
People keep saying, "Trump can't do that!" But like... by what mechanism?
> "The constitution says..."
Yeah... a documented list of rules is not self-enforcing. What is the mechanism?
What makes this impossible? Oh, it's possible under certain conditions? Oh, it's always possible and you're completely relying on the idea that there will never be a malicious actor? Yeah, that's gonna get exploited. Oh shit, now you're owned.
What do you do with a system that's completely owned? Once it's compromised it can never be trusted again. What would you tell a client who told you, "Patching is really hard, so we're just gonna ban the attacker's IP."
What, you're not even gonna reinstall?
I assume we've all had the "burn everything down and start again" client. I wonder how many of us thought we would see the US government ask for them to hold it's beer.
#USPol