oss-sec mailing list archives
Re: Thoughts on Shellshock and beyond
From: Tracy Reed <treed () ultraviolet org>
Date: Thu, 9 Oct 2014 10:34:49 -0700
On Wed, Oct 08, 2014 at 05:11:43PM PDT, David A. Wheeler spake thusly:
It's trivial to implement a language (say Lisp) inside Haskell, and then hand data to that implementation to be executed.
Sure, but at least with Haskell (and the like) you have to make it very explicit that this is what you want to do. A lot of our problems seem to come from the mixing happening by accident.
But mixing code with data is probably an *overused* approach, given the risks that come with it.
Right. Which is why it should be a little more work to do and require that it be made explicit that the mixing is what is intended.
We need to help developers know what is safe, and what is less safe. Then they can avoid easily-avoided problems, and know when they have extra work to do.
Educating developers will be equally hard as switching to safer languages but at least it is something people will stomache getting started on. -- Tracy Reed, RHCE Digital signature attached for your safety. Copilotco PCI/HIPAA/SOX Compliant Secure Hosting 866-MY-COPILOT x101 http://copilotco.com
Attachment:
_bin
Description:
Current thread:
- Re: Thoughts on Shellshock and beyond, (continued)
- Re: Thoughts on Shellshock and beyond David A. Wheeler (Oct 07)
- Re: Thoughts on Shellshock and beyond Michal Zalewski (Oct 07)
- Re: Thoughts on Shellshock and beyond Stephane Chazelas (Oct 08)
- Re: Re: Thoughts on Shellshock and beyond Michal Zalewski (Oct 08)
- Re: Thoughts on Shellshock and beyond Tim (Oct 08)
- Re: Thoughts on Shellshock and beyond Michal Zalewski (Oct 08)
- Re: Thoughts on Shellshock and beyond David A. Wheeler (Oct 08)
- Re: Thoughts on Shellshock and beyond Tracy Reed (Oct 08)
- Re: Thoughts on Shellshock and beyond Tim (Oct 08)
- Re: Thoughts on Shellshock and beyond David A. Wheeler (Oct 08)
- Re: Thoughts on Shellshock and beyond Tracy Reed (Oct 09)
- Re: Thoughts on Shellshock and beyond David A. Wheeler (Oct 09)
- Re: Thoughts on Shellshock and beyond Pavel Labushev (Oct 09)
- Message not available
- Re: Thoughts on Shellshock and beyond Florian Weimer (Oct 10)
- Re: Thoughts on Shellshock and beyond Pavel Labushev (Oct 11)
- Message not available
- Re: Thoughts on Shellshock and beyond Florian Weimer (Oct 12)
- Re: Thoughts on Shellshock and beyond John Haxby (Oct 12)
- Re: Thoughts on Shellshock and beyond Pavel Labushev (Oct 14)
- Re: Thoughts on Shellshock and beyond Sven Kieske (Oct 09)
- Re: Thoughts on Shellshock and beyond Michal Zalewski (Oct 09)
- Re: Thoughts on Shellshock and beyond Sven Kieske (Oct 09)