Firewall Wizards mailing list archives

Re: Re: Code Red: What security specialist don't mention in warnings(Frank Knobbe)


From: Damir Rajnovic <gaus () cisco com>
Date: Tue, 07 Aug 2001 20:59:11 +0100

Hi there,

At 09:59 07/08/2001 -0400, Marcus J. Ranum wrote:
Safety technology is _consistently_ one of the last things we apply to
any new technology. And we usually apply it only after the lack has been
clearly documented, and it's obvious that a high level of damage results
from not applying it reasonably consistently.

I would just like to add that the usual response from vendors is that
they are under time-to-market pressure and that people are paying for
new features but not for the security. Despite working for a vendor
I would say that it is not completely true. It is just that writing 
a code is still more a craft then a documented and tested process.

It is relatively easy with a "classical" engineering. You know how
thick wall must be in order to withstand such-and-such force. And people
are learning that in the university. The consequence is that we are
having more bridges that are usable then collapsed ones.

We do not have such standards for writing a code. Every person is
discovering all mistakes for itself.

Cheers,

Gaus
==============
Damir Rajnovic <psirt () cisco com>, PSIRT Incident Manager, Cisco Systems
<http://www.cisco.com/warp/public/707/sec_incident_response.shtml>
Phone: +44 7715 546 033
4 The Square, Stockley Park, Uxbridge, MIDDLESEX UB11 1BN, GB
==============
There is no insolvable problems. Question remains: can you 
accept the solution? 

_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://list.nfr.com/mailman/listinfo/firewall-wizards


Current thread: