Full Disclosure mailing list archives
Re: Coding securely, was Linux (in)security
From: Valdis.Kletnieks () vt edu
Date: Mon, 27 Oct 2003 00:11:00 -0500
On Sun, 26 Oct 2003 23:07:18 EST, Bill Royds <full-disclosure () royds net> said:
such as OpenSSH has been found to have security problems. If you look at security advisories, find out how many come from Ada code. C makes it hard to write secure code.
I wasn't aware there was enough of a code base of actual Ada programs out in the wild for there to be statistically valid results. I gave up on any prospects of Ada when the DoD dropped the requirement that the compiler and runtime support libraries pass the test suite for exception handling because otherwise *no* compilers would validate. Given this, and the truly huge and byzantine nature of the *rest* of the language, I'm not convinced that Ada was actually any good for writing *secure* code. Think about how many programs have had bugs because programmers didn't understand how *their particular* C++ compiler (in the current version, as opposed to the version 6 months ago) handled constructors, and consider that Ada was even worse. True, it may have been safe against simple buffer overflows, but a breeding ground for more subtle bugs caused by misunderstanding the semantics of *all* the language features.
Attachment:
_bin
Description:
Current thread:
- Coding securely, was Linux (in)security, (continued)
- Message not available
- Coding securely, was Linux (in)security Paul Schmehl (Oct 26)
- RE: Coding securely, was Linux (in)security Chris Eagle (Oct 26)
- Re: Coding securely, was Linux (in)security Brett Hutley (Oct 26)
- RE: Coding securely, was Linux (in)security Chris Eagle (Oct 26)
- Re: Coding securely, was Linux (in)security Brett Hutley (Oct 26)
- Off topic programming thread Mortis (Oct 26)
- Re: Off topic programming thread Bill Weiss (Oct 27)
- Re: Off topic programming thread Chris Smith (Oct 27)
- RE: Coding securely, was Linux (in)security Paul Schmehl (Oct 26)
- Re: Coding securely, was Linux (in)security Bill Royds (Oct 26)
- Re: Coding securely, was Linux (in)security Valdis . Kletnieks (Oct 26)
- Re: Coding securely, was Linux (in)security Brett Hutley (Oct 26)
- RE: Coding securely, was Linux (in)security Chris Eagle (Oct 26)
- RE: Coding securely, was Linux (in)security Steve Wray (Oct 27)
- Re: Coding securely, was Linux (in)security Gregory A. Gilliss (Oct 27)
- Re: Coding securely, was Linux (in)security Valdis . Kletnieks (Oct 28)
- Re: Coding securely, was Linux (in)security Gregory Steuck (Oct 28)
- Re: Coding securely, was Linux (in)security Valdis . Kletnieks (Oct 29)
- Re: Coding securely, was Linux (in)security Ben Laurie (Oct 29)
- Re: Coding securely, was Linux (in)security Sebastian Herbst (Oct 29)
- Re: Coding securely, was Linux (in)security Valdis . Kletnieks (Oct 29)