Re: [Lit.] Buffer overruns

From: David Wagner (daw_at_taverner.cs.berkeley.edu)
Date: 01/29/05


Date: Sat, 29 Jan 2005 05:08:29 +0000 (UTC)

Hank Oredson wrote:
>If the project is to design a secure system, then the project
>plan darn well better have that level of testing.

If security is the goal, no amount of testing is sufficient.
If the job is security, testing is generally the wrong tool for the job.



Relevant Pages

  • Re: Security and EOL issues
    ... OS software resources are designed that reserved ram and disk space among other resources, to reflect what current hardware size is available. ... (There was a security patch a few years ago that could not be applied to NT4 as it required more resources then NT4 could provide. ... Installing air bags requires that the automobile manufacturer design, test, ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)
  • Re: I need a system the U.S. government cannot hack
    ... By way of a further excuse, using words such as 'hack', 'government' or ... The security requirements are driven in part by the costs associated with ... The bulk of the cost of box and wire systems is in the infrastructure --> ... While I can, and will, and am trying, to move ahead with my own design, ...
    (microsoft.public.security)
  • Re: I need a system the U.S. government cannot hack
    ... By way of a further excuse, using words such as 'hack', 'government' or ... The security requirements are driven in part by the costs associated with ... The bulk of the cost of box and wire systems is in the infrastructure --> ... While I can, and will, and am trying, to move ahead with my own design, ...
    (microsoft.public.security)
  • Re: Well Andrew, "3" count them "3" security patches for VMS in five
    ... Whenever you discuss security with VMS guys ... be a fully patented methodology by OpenVMS Engineering. ... calling standard which rules out "by design" the primary cause of ... - design privilege assignments to be attached to a mode. ...
    (comp.os.vms)
  • Re: Microsoft finally acknowledges the security drumbeats
    ... > was formerly in charge of design for VMS (a quite securely designed OS, ... intel/alpha/mips/powerpc) and easy security audit (which is no more: ... Even Ford doesn't give you a whole new car when they issue ... Here comes the fact of management taking "technical" ...
    (comp.security.unix)

Quantcast