logo       


Re: Paper for the "Weeding out security bugs" Debconf6 workshop: msg#00007

Subject: Re: Paper for the "Weeding out security bugs" Debconf6 workshop
On Thu, Apr 06, 2006 at 01:55:11AM +0200, Javier Fern?ndez-Sanguino Pe?a wrote:

> I have finished writting the paper for the security workshop I proposed for
> Debconf6: "Weeding out security bugs". I would *really* appreciate if
> somebody could read it and comment on it, you can find it here:
> http://people.debian.org/~jfs/debconf6/#security

  I've just been re-reading old mails and remembered this one, so
 apologies for a late reply.

  For some reason gpdf wasn't happy with the PDF version so I
 read the lyx file.

  I loved the introduction, and thought the complete paper was
 nicely written.

  There were a couple of sentences which stood out as being
 worded clumsily, but they were little things like this:

    "It has been direct responsible" should be "directly".

    "makes it inevitable to have a large number of security bugs in it."
    might be better as "makes it inevitable that a large number of
    unfound security issues are present in each release".

  I'll give a comple diff later if that is useful, offlist?

  I think it might be nice to focus more on the non-traditional
 classes of bugs.  Since the standard buffer overflows, whilst
 not exhausted, seem to be occurring less often.

  Things like your own temporary file auditing (more news on
 that soon), Ulfs work on syslog issues, etc.

  I liked the offer of auditing by us for package maintainers
 and liked the idea of listing things to be wary of.  I'd suggest
 including "Adding system cron jobs" to the list, that is really
 a subset of software running as root, but perhaps less commonly
 considered?

Steve
-- 


Ruby Jobs
Java Jobs
Jobs in California
more...
what
job title, keywords
where
city, state, zip
jobs by job search
Search:
Java, servers, webhosting, windows, cisco ...
more...
<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
encryption.gpg....    ietf.rfc822/199...    freebsd.devel.i...    lang.haskell.li...    mail.squirrelma...    web.zope.plone....    yellowdog.gener...    text.xml.xalan....    recreation.phot...    kde.devel.educa...    hardware.bus.ca...    printing.ghosts...    voip.peering/20...    assembly/2006-0...    org.user-groups...    culture.interne...    network.i2p/200...    boot-loaders.ya...    xfree86.render/...    qnx.openqnx.dev...    jakarta.velocit...    user-groups.pal...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe