Ilya Zonov
host
host
host
guest
The Distributed Systems finale focuses on security. After confidentiality, integrity, and availability, it moves to threat modeling: identify assets, threats, and forbidden outcomes before selecting policy and mechanism. Authentication, authorization, and audit remain separate responsibilities.
Secure-design principles become decisions. Fail-safe defaults deny access unless allowed; separation of privilege keeps a critical action away from one authority; complete mediation checks every access. Open design and simplicity reduce complexity, while defense in depth limits the damage from a breached layer.
The cryptography section compares symmetric and asymmetric encryption, key distribution, and application-layer protection. Authentication combines knowledge, possession, and inherence factors; using several reduces compromise risk. Continuous checks revalidate session context, while reflection attacks show why protocols need nonces and distinct keys.
The discussion then covers blockchains, authorization, and delegation. RBAC connects permissions to roles, ABAC adds arbitrary attributes, and capabilities transfer bounded authority. Firewalls protect the outer boundary; detection and monitoring work inside it, where recall must be balanced against precision and alert fatigue.