About Avi
Categories
- Chronicles (50)
- Community and Society (76)
- Ecology & Environment (7)
- Essays (32)
- Events (25)
- Gourmet (27)
- Info & Biz Technology (258)
- Linux & Open Source (93)
- Linux Journal Index (14)
- Mobility (16)
- Multimedia (9)
- OpenDocument Format (61)
- Web 2.0 (59)
- Linux & Open Source (93)
- Metaphysics (25)
- Misc (5)
- Music & Podcasts (37)
- Podcast: brazilian jazz (8)
- Podcast: general (13)
- Travels (62)
- Central Asia 2007 (28)
- Vegetarianism (9)
Software Security from a Specialist: Gary McGraw
4
comments
By AviPublished:
Thu, 27 Dec 2007 15:48:11 -0200
Published:
27 Dec 2007
Published:
3:48 pm
Categories: Linux & Open Source
Tags: lang:en tech:ok
Some points he touched:
- Software security is about how to approach computer security if you are a developer or a software architect.
- Security problems come from 2 points: (a) bad or buggy implementation as buffer overflows etc and (b) lack or poor architectural risk analysis. So even if you took a lot of care while writing the code you may have forgotten completely to authenticate users. This is a bad design (b) issue. Both problems — implementation and design — must be mitigated.
- You can’t be 100% secure, but if you have considered security in the design and in the implementation of your software, you will be a lot better than simply shipping software without thinking about security.
- Although people may have very good reasons to think that Open Source software is less secure than closed source because a cracker can see the code and find flaws, the bad guys actually use the binary version of a software to find the flaws, using low level debuggers, stack analyzers, decompilers and other kinds of things. Open Source software is not really in any worse shape that any other kind of software. He also says that Open Source software is not also better, from a security perspective. He does not believe in that theory that everybody is looking at the code and may find and fix bugs. Me neither.
I guess this is my last post of 2007 and I wish everybody a happy new year.




bhdzcv hgtuzle ikauc uztkp
ifahs
jrvez xsora bwgpdt bdahjm
ewjhqx cskqehr