Blunder Dome Sighting  
privacy 
 
 
 

Hangout for experimental confirmation and demonstration of software, computing, and networking. The exercises don't always work out. The professor is a bumbler and the laboratory assistant is a skanky dufus.



Click for Blog Feed
Blog Feed

Recent Items
 
Ending the Madness: Deja Triple Vu
 
Your%20Message%20Here
 
Just Ducky, Simply Ducky. And You?
 
All Clear: End of Test #1
 
Why Learn Assembly Language
 
Linking the Atom Feeds
 
Button, Button, Where's the Update?
 
Do We Have a Firewall or a Development Web?
 
Attack of the Naughty Bees
 
What Do You Do When Security Software Cocks-It-Up?...

This page is powered by Blogger. Isn't yours?
  

Locations of visitors to this site
visits to Orcmid's Lair pages

The nfoCentrale Blog Conclave
 
Millennia Antica: The Kiln Sitter's Diary
 
nfoWorks: Pursuing Harmony
 
Numbering Peano
 
Orcmid's Lair
 
Orcmid's Live Hideout
 
Prof. von Clueless in the Blunder Dome
 
Spanner Wingnut's Muddleware Lab (experimental)

nfoCentrale Associated Sites
 
DMA: The Document Management Alliance
 
DMware: Document Management Interoperability Exchange
 
Millennia Antica Pottery
 
The Miser Project
 
nfoCentrale: the Anchor Site
 
nfoWare: Information Processing Technology
 
nfoWorks: Tools for Document Interoperability
 
NuovoDoc: Design for Document System Interoperability
 
ODMA Interoperability Exchange
 
Orcmid's Lair
 
TROST: Open-System Trustworthiness

2004-09-01

 

Security is a Programming Problem?

ACM Queue: Why is it we can't seem to produce secure, high-quality code?  This article in ACM Queue managed to be slash-dotted.  I can see why.  Author Marcus Ranum claims that security is a programming problem.  I beg to differ.  Bugs and security vulnerabilities are not the same thing. It seems to be part of the magical thinking around computer-based systems that if we could just get the software right, problems with security would vanish.  I have no objection to getting the software right (or way better, at least).  But seeing elimination of bugs as the silver bullet of security strikes me as near-delusional.  It's also the hard way of getting to improved security.  Think of all the bugs and related defects that don't create openings for exploits.  And consider that serious problems like spam, while exacerbated by exploits, don't depend on hidden defects by which programs fail to meet the measurable requirements set for them. It is not about programming.  It is often about system engineering, operations management, and business practice. It is a mystery for me what value is found in scapegoating programming.  The marvel of it all is that software developers (want to) believe it too.  Why?  What is it we want so badly to be distracted from that we buy into this?

 
Construction Structure (Hard Hat Area) You are navigating Orcmid's Lair.

template created 2004-06-17-20:01 -0700 (pdt) by orcmid
$$Author: Orcmid $
$$Date: 10-04-30 22:33 $
$$Revision: 21 $