 |
|
| |
|
 |
 |
at Global Oneness Community.
Share your dreams and let others help you with the interpretation!
Dream Sharing Forum
|
 |
Daniel J. Bernstein - Software security |  | Daniel J. Bernstein - Software security: Encyclopedia II - Daniel J. Bernstein - Software security |  | In the autumn of 2004, Bernstein began teaching one of the first formal university-level courses about computer software security, titled "UNIX Security Holes". The 16 members of the class discovered 91 new UNIX security holes. Bernstein, long a promoter of the idea that full disclosure is the best method to promote software security and founder of the securesoftware mailing list, publicly announced 44 of them with sample exploit code. This received some pre ...
See also:Daniel J. Bernstein, Daniel J. Bernstein - Software security, Daniel J. Bernstein - Mathematics |  | | Daniel J. Bernstein, Daniel J. Bernstein - Mathematics, Daniel J. Bernstein - Software security |  | |
|  |  | Daniel J. Bernstein: Encyclopedia II - Daniel J. Bernstein - Software security
Daniel J. Bernstein - Software security
In the autumn of 2004, Bernstein began teaching one of the first formal university-level courses about computer software security, titled "UNIX Security Holes". The 16 members of the class discovered 91 new UNIX security holes. Bernstein, long a promoter of the idea that full disclosure is the best method to promote software security and founder of the securesoftware mailing list, publicly announced 44 of them with sample exploit code. This received some press attention and rekindled a debate over full disclosure.
No security holes have been found in Bernstein's own software, qmail and djbdns, despite their widespread use and a US$5000 reward for qmail and a US$500 reward for djbdns. Some security professionals believe that one of these bugs (an integer overflow) does qualify as a security hole, because it could lead to remote root compromise when qmail is installed on certain rare 64-bit systems.
Bernstein believes it is possible to write secure software if the programmer is sufficiently dedicated. Thus believing that the widespread prevalence of security holes results from programmer laziness and incompetence, Bernstein argues:
Immediate full disclosure, with a working exploit punishes the programmer for his bad code. He panics; he has to rush to fix the problem; he loses users.
You're whining that punishment is painful. You're ignoring the effect that punishment has on future behavior. It encourages programmers to invest the time and effort necessary to eliminate security problems. 3
Bernstein has recently explained that he is pursuing a strategy to "produce invulnerable computer systems". Bernstein plans to achieve this by putting the vast majority of computer software into an "extreme sandbox" that prevents it from doing anything besides transforming input into output and by writing bugfree replacements (like qmail and djbdns) for the remaining components that need additional privileges. He concludes: "I won’t be satisfied until I've put the entire security industry out of work." 4
As of Spring 2005, Bernstein is teaching a course on "High Speed Cryptography"5. Bernstein demonstrated new results against AES in the same time period.6
Other related archives10-29, 1971, 2004, AES, Adi Shamir, As of Spring 2005, Atkins sieve, Bernstein v. United States, Bruce Schneier, EFF, FFT, FFTW, First Amendment, IMAP, Internet Mail 2000, POP3, Paul Vixie, RSA, SMTP, UNIX, University of Illinois at Chicago, Usenet, Wietse Venema, algorithms, asymptotic, benchmarking, cryptologist, djbdns, encryption, full disclosure, integer overflow, libraries, license-free software, mathematician, mathematics, prime numbers, professor, programmer, qmail, sieve, sieve of Eratosthenes
 Adapted from the Wikipedia article "Software security", under the G.N U Free Docmentation License. Please also see http://en.wikipedia.org/wiki |
|
« Back
|
Search the Global Oneness web site |
|
|
|
|
 |
Sneak-Peek of Global Oneness Community
Hi friend! The Global Oneness Community, the place for information and sharing about Oneness is not really launched yet (you will see there is still some clean up to do) ...but it is now open for a sneak-peek! And if you wish - please register and become one of the very first members to do so! Jonas
Forum Home,
Articles,
Photo Gallery,
Videos,
News,
Sitemap
...and much more!
|