Re: [Full-Disclosure] automated vulnerability testing

From: Frank Knobbe (frank_at_knobbe.us)
Date: 11/29/03

  • Next message: bscabl: "[Full-Disclosure] moving"
    To: full-disclosure@lists.netsys.com
    Date: Sat, 29 Nov 2003 16:32:35 -0600
    
    
    

    On Sat, 2003-11-29 at 15:10, Michael Gale wrote:
    > The right being security first and reliability / speed second.

    I don't know about that. I prefer code with minimal "failure
    conditions". Failure conditions, or faults, have impact on both,
    security and reliability. I don't think a program can exist that is
    reliable, but not secure, or secure, but not reliable.

    Performance seems to counter security. The trick is to find a good
    balance between security and performance. There can never be 100%
    security as long as humans (or machines derived from the work of humans)
    are involved. Finding that sweet spot is hard since it's not a simple
    equation. Some even manage to write code which is neither secure nor
    performs well.... but that's beside the point.

    People have to learn not to think in absolute terms. There is no black
    and white in life, only shades of gray....

    Cheers,
    Frank

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: bscabl: "[Full-Disclosure] moving"

    Relevant Pages

    • Re: More on garbage
      ... Lessing performed both trading and accounting tasks, ... stopped before the bank went broke. ... there is a difference between security and reliability. ...
      (sci.crypt)
    • Re: Is MSIE dead as a browser - if Microsoft does not patch it then it is as far as I am concerned!
      ... > currently 3 identified IE vulnerabilites. ... IE has grown up a lot in speed, functionality, and reliability. ... years the patches were by and large all about more features, better speed, ... improved security simply was not what the public was crying for and the OS ...
      (microsoft.public.security.virus)
    • Re: Were losing the battle
      ... Wake me up, if you can, when the non-MF platforms can multi-task with literally thousands of tasks and still get reasonable work done in a reasonable time frame. ... And whether we like it or not, the MF still has very high reliability, excellent security and a pretty D*** high degree of recoverability. ...
      (bit.listserv.ibm-main)
    • Re: IBM fingerprint reader
      ... My new TP 43p is my second IBM machine with a fingerprint reader and works as designed. ... Not only the reader has turned out to be reliable but the security suite that comes with it is ironclad as well. ... IBM aside, I've been working with various forms of biometrics for a long time - oh, last 12 years or so, before the word "biometrics" meant anything to GP - and can vouch for its reliability. ...
      (comp.sys.laptops)
    • Re: More on garbage
      ... > That is not the case in the real world, and the distinction is yet ... there is a difference between security and reliability. ... > design, a lot of logic goes on the diagnosis. ...
      (sci.crypt)