funsec mailing list archives

Re: standards status in the industry - opinion?


From: Barrie Dempster <barrie () reboot-robot net>
Date: Mon, 09 Jan 2006 11:32:45 +0000

On Sun, 2006-01-08 at 22:20 -0500, Valdis.Kletnieks () vt edu wrote:
The first is just user idiocy, and CM Kornbluth told us what the chances of
fixing *that* problem are.

But what retro-monkey programmer on the cutting edge of the Kornbluth Kurve
thought that the API to permit the second was in any possible way a Good
Idea???

When security mechanisms add what feels like too much complexity to a
task the user (and the programmer) will actively circumvent them.

As far as most developers of Windows based applications are concerned,
security became something a developer was responsible for and should
worry about when the book "Writing Secure Code" was published, which was
in 2002.

-- 
With Regards..
Barrie Dempster (zeedo) - Fortiter et Strenue

"He who hingeth aboot, geteth hee-haw" Victor - Still Game

blog:  http://reboot-robot.net
sites: http://www.bsrf.org.uk - http://www.security-forums.com
ca:    https://www.cacert.org/index.php?id=3

Attachment: smime.p7s
Description:

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Current thread: