(Message inbox:2796)
Return-Path: Saltzer@ATHENA.MIT.EDU
Received: by JASON (5.45/4.7)
	id AA00497; Fri, 28 Nov 86 17:32:17 EST
Received: by ATHENA (5.45/4.7)
	id AA00607; Fri, 28 Nov 86 17:32:25 EST
Received: by HERACLES (5.45/4.7)
	id AA01799; Fri, 28 Nov 86 17:31:00 EST
Date: Fri, 28 Nov 86 17:31:00 EST
Message-Id: <8611282231.AA01799@HERACLES>
To: lerman@ATHENA.MIT.EDU
Cc: directors@ATHENA.MIT.EDU, planning-managers@ATHENA.MIT.EDU,
        lbm@ATHENA.MIT.EDU, henry@ATHENA.MIT.EDU, billb@ATHENA.MIT.EDU
Subject:  comments on "principles of responsible. . ."
From: Jerome H. Saltzer <Saltzer@ATHENA.MIT.EDU>
Originating-Client:  <E40-391A-1.MIT.EDU>

Steve,

Three comments:

1.  (System integrity)  Decryption of passwords is probably not
feasible anyway, so doesn't seem worth mentioning, but placing Trojan
horses or watching the net to steal other people's passwords is.  I
suggest replacing the word "decryption" with "interception".

2.  (System integrity) Does replacing the kernel on a workstation
with a slightly different one count as "intentionally altering
the integrity" if the new kernel works well?   The integrity discussion
may need some more updating to deal with the workstation environment.

3.  (Property rights) I would like to see the additional statement
"For reference, a summary of ownership agreements for Athena-supplied
software and data appears on all Athena systems."  But of course we
shouldn't include that in the writeup until we are ready to implement
it.

					Jerry
