funsec mailing list archives

Re: Curious questions...


From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Tue, 25 Oct 2005 13:59:19 +1300

Gary Warner wrote:

oh, i forgot . . . I should mention that my example was in 1987.
if the code gave the desired answer, it was Good Code.
No one did a security check then, because this code would only be used 
by employees. 

"We don't hire bad people" was a pretty common disclaimer back then.

And they also didn't hire stupid users, or users that _ever_ made a 
typo...

Nor use storage media that _ever_ produced a non-detected read error...

Or any of a gazillion other things that result in bad data getting 
where it never should and that have nothing to do with malfeasance...


I think I used to work there too!    8-)


Regards,

Nick FitzGerald

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: