|
|
privacy |
||
|
Hangout for experimental confirmation and demonstration of software, computing, and networking. The exercises don't always work out. The professor is a bumbler and the laboratory assistant is a skanky dufus.
Blog Feed Recent Items The nfoCentrale Blog Conclave nfoCentrale Associated Sites |
2004-09-01Security is a Programming Problem?ACM Queue: Why is it we can't seem to produce secure, high-quality code? This article in ACM Queue managed to be slash-dotted. I can see why. Author Marcus Ranum claims that security is a programming problem. I beg to differ. Bugs and security vulnerabilities are not the same thing. It seems to be part of the magical thinking around computer-based systems that if we could just get the software right, problems with security would vanish. I have no objection to getting the software right (or way better, at least). But seeing elimination of bugs as the silver bullet of security strikes me as near-delusional. It's also the hard way of getting to improved security. Think of all the bugs and related defects that don't create openings for exploits. And consider that serious problems like spam, while exacerbated by exploits, don't depend on hidden defects by which programs fail to meet the measurable requirements set for them. It is not about programming. It is often about system engineering, operations management, and business practice. It is a mystery for me what value is found in scapegoating programming. The marvel of it all is that software developers (want to) believe it too. Why? What is it we want so badly to be distracted from that we buy into this?
|
||
|
|
You are navigating Orcmid's Lair. |
template
created 2004-06-17-20:01 -0700 (pdt)
by orcmid |