Secure Coding mailing list archives

Re: Open Source failure analysis tool released for Linux


From: ljknews <ljknews () mac com>
Date: Fri, 15 Oct 2004 18:17:06 +0100

At 8:23 AM -0400 10/15/04, Kenneth R. van Wyk wrote:

I believe that we don't do enough to analyze and learn from software failures.  

I believe the industry as a whole does plenty to analyze software
failures, particularly considering how little is done to avoid
those errors.  Added analysis in the face of near-zero remediation
would be useless.

How many times do we see "buffer overflow" as the cause, yet even on
this mailing list people still defend the use of languages that not
only permit but actually promote such errors.
-- 
Larry Kilgallen







Current thread: