Re: "Perfect" or "Provable" security both crypto and non-crypto?

From: Douglas A. Gwyn (DAGwyn_at_null.net)
Date: 09/16/04


Date: Thu, 16 Sep 2004 21:01:00 GMT

David Wagner wrote:
> The task of verifying lack of buffer overruns is trivial if your language
> renders it impossible to even express a buffer overrun (e.g., Java is
> memory safe; there is no way to write code that has a buffer overrun,
> and hence is safe).

That's a common misconception.



Relevant Pages

  • Re: Another book
    ... language to program in, constantly trying to keep track of who is ... pain and simply forgets to apply best practices regarding array access. ... The way to avoid buffer overrun is to go the opposite direction, ... must-be-secure applications). ...
    (comp.lang.lisp)
  • Re: another day, another patch ...
    ... programmer to take extra effort to prevent them is faulty. ... which you should be applying to to any language that you use.. ... I'm still waiting for someone to post an example of a buffer overrun ...
    (comp.os.vms)

Quantcast