I scanned the introduction, but failed to see any concrete information on the expertise of the authors on security. Can anybody speak to the expertise of the authors on security?
In particular, I am interested in specific projects or initiatives they directed or lead. The state of systems before and after these projects. If there were any long-term regressions after their involvement.
To be even more concrete if possible:
1. What was the project and what would occur in the event of unmitigated compromise?
2. What was the threat model?
2a. Why was that the appropriate threat model given the possible outcomes?
3. How did they validate that the project met its goals in mitigating the threats in the threat model?
4. What level of resources would be necessary to compromise the systems they were trying to protect?
4a. Would the system prevent compromise by a red team with a $1 Billion, $1 Million, $1000, $1 budget?
4b. What resources did the red teams have?
Personal questions for the responder:
1. Would you feel comfortable using the processes you have used in the past to develop a system where compromise would result in the loss of human life?
2. If you answered yes, what project and process and why do you believe that it sufficient?
3. If you answered no, do you have any first hand knowledge of systems that achieve that standard?
4. What is the best system that you have first hand knowledge of that has achieved at least that standard? Is there a non-theoretical gold standard?