Your Cyber Path: How to Get Your Dream Cybersecurity Job · Kip Boyle

EP 109: SDP 7: Complete Mediation

·21 min·1 clip
Windows SRM checks access control lists every time you touch a protected object.
1. Your Cyber Path EP 109 covers the security design principle called complete mediation. 2. Kip and Jason host the episode, and Jason’s role matters because he reacts to the title while Kip translates the principle into Windows and web examples. 3. The episode asks how often a system should check access to an object, and why the answer is not always “every time.” 4. Kip says the paper’s definition is that the protection mechanism should check “every access to every object.” 5. Airport screening is used as a real-world example, with every person and object inspected at the security checkpoint. 6. Jason compares the idea to his children asking his wife for a snack from the kitchen, then having to ask again later for more grapes. 7. Kip maps the principle to logins for email, computers, programs, files, websites, and network ports. 8. He then identifies the Windows Security Reference Monitor, or SRM, as the component that checks whether an access control list allows the action. 9. Kip says early Windows versions treated repeated access as a burden because full mediation made the system feel slow. 10. He explains that Microsoft compromised by letting the SRM rely on prior authentication for a period instead of rechecking every access. 11. Jason says Kerberos tickets, golden tickets, and silver tickets fit the same shortcut logic in Windows. 12. Jason also says older systems could keep a ticket for 24 hours or even seven days, while current systems often limit them to about an hour. 13. Kip connects that shift to zero trust networking, which moves back toward more frequent checkpoints. 14. Jason says browser session cookies and authentication tokens are also shortcuts that attackers may try to steal. 15. Kip warns that if a web app cannot support complete mediation, the design team still has to make the compromise “smartly.” 16. Jason says the principle is not a hard compliance rule and gives the Accolade website redesign as an example of making tradeoffs between security and delay. 17. The tone is conversational, with Kip explaining definitions and Jason interrupting with practical examples and objections. 18. The format is an instructional back-and-forth that moves between academic wording and operational tradeoffs. 19. Cybersecurity students and system designers who want concrete architecture examples. 20. Listeners wanting a story-driven episode may skip it.
Listen to the show on