Better security through shame

From: Michael Bacarella (mbacat_private)
Date: Thu Nov 14 2002 - 10:00:28 PST

  • Next message: secureat_private: "[CLA-2002:547] Conectiva Linux Security Announcement - syslog-ng"

    STAFF: Humbly submitted for your subscribers.
    
    The Peon's Guide To Secure System Development
    
    Abstract:
    
    Increasingly incompetent developers are creeping their way into
    important projects. Considering that most good programmers are pretty
    bad at security, bad programmers with roles in important projects are
    guaranteed to doom the world to oblivion. The author feels that a step
    towards washing himself clean of responsbility is by writing this
    document. Checking your memcpy() and malloc() calls have been lectured
    to death. It's not working. The approach used by this document is to
    instead shame developers into producing better systems. Enjoy.
    
    
    To save bandwidth, the interested parties may find the rest at
    the following URL, in several formats:
    
        http://m.bacarella.com/papers/secsoft/
    
    Thanks
    
    -- 
    Michael Bacarella  | Netgraft Corp
                       | 545 Eighth Ave #401
     Systems Analysis  | New York, NY 10018
    Technical Support  | 212 946-1038 | 917 670-6982
     Managed Services  | http://netgraft.com/
    



    This archive was generated by hypermail 2b30 : Sat Nov 16 2002 - 21:21:59 PST