Re: [Lit.] Buffer overruns

From: BRG (brg_at_nowhere.org)
Date: 12/13/04


Date: Mon, 13 Dec 2004 19:49:12 +0000

Karl Malbrain wrote:

[snip]
>
> does influence the security and/or safety of the resulting design. But
> from what Doug has said it would be reasonable to conclude that he does
> not.
>
> In my view you "create" the "language" you need with C as part of the
> process.

Nevertheless you accept that the language used does influence the safety
and/or security of the resulting design. Which was the point of my
original question to Doug.

>>>>The fact that this is not the most important issue involved does not
>>>>mean that we should ignore it.
>>>
>>>There is nothing wrong with using C to address these issues from.
>>
>>This thread suggests that this is a matter of opinion.

> Not materially -- C is far and away the language of choice.

I interpret the thread differently in this respect.

    Brian Gladman



Relevant Pages

  • Re: gets() is dead
    ... Failing to analyze and design (in my opinion you analyze the problem ... Although secure and safety critical are independent attributes. ... I have worked on safety critical SW where security was not ... also having sufficient permissions to not need to attack are really small. ...
    (comp.lang.c)
  • Re: [Lit.] Buffer overruns
    ... What gives safety and security on the one side is PROTOCOL and on the ... However it seems that you accept that the programming language used does ... influence the security and/or safety of the resulting design. ...
    (sci.crypt)
  • Re: [Lit.] Buffer overruns
    ... the language used is specific to the needs of the higher level ... > concepts specified in the design. ... Safety & security come through the ...
    (sci.crypt)
  • Re: UL/ETL Choking the market
    ... If they mandate safety levels, it will take a LOT longer to do the tests ... due diligence and proper design analysis ... don't need to be tested, for example, I've attended Standards ... | Europe specific, but is much more sensible and there is no financial ...
    (sci.engr.lighting)
  • Re: Security and EOL issues
    ... OS software resources are designed that reserved ram and disk space among other resources, to reflect what current hardware size is available. ... (There was a security patch a few years ago that could not be applied to NT4 as it required more resources then NT4 could provide. ... Installing air bags requires that the automobile manufacturer design, test, ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)