funsec mailing list archives

Re: Curious questions...


From: Gary Warner <gar () askgar com>
Date: Mon, 24 Oct 2005 13:43:58 -0500

OK, Kowsik, I'll play . . .

Yes, I have contributed to code systems with more than 1 million lines of code.

All of my code was perfect.  (because this is FUNsec, right?)

However, many of the other millions of lines were not. I was not allowed to test that code. Most of the time, i was not even allowed to see the code which would call my code or see the functions that my code called. I could only see the "function interface specs" because of "Intellectual Property Concerns." In a great many circumstances, calls made according to the "function interface specs" failed to function. This resulted in many many hand-written notes in our printed copy of the "function interface specs", which was not allowed to leave the building.

(Most of us assumed that the "Intellectual Property Concerns" were that a thorough review of the code would demonstrate a lack of Intellectual Property on behalf of the original coders, who wrote spaghetti FORTRAN code somewhere in South Africa. The other concern was that the company may not have exactly owned all of the code that we were calling. My tenure with this organization was as a contract programmer, and I ended the relationship very quickly.)

For the record, all of my code is STILL perfect, which is why I write so little of it. It helps to increase the value if it is a scarce commodity.

_-_
gar


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: