Re: "Perfect" or "Provable" security both crypto and non-crypto?
From: Anne & Lynn Wheeler (lynn_at_garlic.com)
Date: Fri, 17 Sep 2004 11:05:17 -0600
"Roger Schlafly" <firstname.lastname@example.org> writes:
> I don't know what Doug had in mind, but there are lots of ways
> that buffer overruns can occur in any language.
> Consider a program that reads from a data stream (such as a
> file or internet socket), and writes to another stream.
> It reads a particular data field, for which the specs say
> that it will be null-terminated and less than 64 bytes long.
> The program reads the data into a larger data structure,
> and ignores the 64-byte limit because it assumes that the
> null terminator will be there. Then all sorts of bad things
> can happen.
> Such buffer overflow bugs can occur in Java or Perl or
> anything else, and such bugs are common. Those languages
> are a lot safer than C because a simple string copy is not
> going to blow the stack, but there can be other buffer overrun
but assertion is that c programming conventions can increase the
occurance of such overrun bugs by a factor of one to two orders of
the multics (written in pli) study claims that there was never such a
problem in multics system.
previous post in thread ...
http://www.garlic.com/~lynn/2004l.html#21 "Perfect" or "Provable" security both crypto and non-crypto?
part of the issue is security proportional to risk .... if the risk is
one hundreds times greater ... then people might be included to pay
more attention to it than other security risks that might have
significantly lower rate of occurance.
some recent threads in other n.g. discussing relation between programming
language and predisposition to buffer over run/flows:
http://www.garlic.com/~lynn/2004j.html#37 Vintage computers are better than modern crap !
http://www.garlic.com/~lynn/2004j.html#38 Vintage computers are better than modern crap !
http://www.garlic.com/~lynn/2004j.html#58 Vintage computers are better than modern crap !
http://www.garlic.com/~lynn/2004k.html#2 Linguistic Determinism
http://www.garlic.com/~lynn/2004k.html#5 Losing colonies
http://www.garlic.com/~lynn/2004k.html#6 Losing colonies
http://www.garlic.com/~lynn/2004k.html#20 Vintage computers are better than modern crap !
-- Anne & Lynn Wheeler | http://www.garlic.com/~lynn/