Human error in .NET framework

From: Doman Maciejko (doman.is@home.se)
Date: 03/30/03

  • Next message: Linus Martinsson: "Reflection"
    From: "Doman Maciejko" <doman.is@home.se>
    Date: Sun, 30 Mar 2003 11:44:23 +0200
    
    

    I have a question about the security in .NET in general.

    As more I read about the security in .NET, the more I understand that the
    code programmer and the local administrator have a very significant role.

    It's up to the programmer to use the options that comes with permissions,
    lock out permissions you don't need etc, in general make the assemblies as
    specific for the purpose as possible, without loosing al flexibility. The
    administrator will probably have to give specific permissions to specific
    programs on the co-workers demand and have to adjust the security to the
    demands they have, jeopardizing the security.

    I don't mean that this is a new problem in general, but haven't the focus in
    .NET on being a flexible platform made this problem more significant?

    Metadata is supposed to give information to the code access security model,
    to be a part in the security architecture in general. Is that the main
    reason why Microsoft has focused so much at metadata, or is the flexibility
    for the programmers in focus? How will the next step look like? Is this step
    succesfull one? Or do we have to take a step backwards and start all over?

    /Doman Maciejko


  • Next message: Linus Martinsson: "Reflection"

    Relevant Pages

    • Re: Is it time for secure C ?
      ... This is certainly possible (especially with C99 VLAs ... but is the proposed "security" worth ... array out with NUL bytes is removed! ... the programmer to provide output character arrays big enough to hold ...
      (comp.lang.c)
    • Re: security enhacement to C runtime library (XXX_s)
      ... In the below link MS announces a security update to the C runtime ... Every buffer overflow error that was made before can still be ... strings in C the way they are used in every other programming ... how can we increase the programmer ...
      (comp.std.c)
    • Re: pid from startet process
      ... programmer expects. ... generate new candidates for PIDs by incrementing a counter. ... have not, however, yielded on the claim of a security threat posed ... the introduction of a system with randomized PIDs increased ...
      (comp.lang.perl.misc)
    • Re: [Full-Disclosure] Antigen Path Disclosure
      ... Im not a part of the security industry itself, im a programmer. ... But Still decided to uploaded 2 dodgey files and a jpg like he was ...
      (Full-Disclosure)
    • Re: need free support in IT? [Glasgow]
      ... I am a Sun Certified Programmer for the Java 2 Platform, ... GNU/Linux operating system administration (security, samba, Apache, ... interested in Open Source operating systems and software, networking, ... If you think, that your company could take advantage of my skills, and, ...
      (uk.local.glasgow)