WebApp Sec mailing list archives

Re: Prevent security bypass


From: Adrian Wiesmann <awiesmann () swordlord org>
Date: Thu, 6 Feb 2003 19:53:16 +0100

I'm having a hard time buying this argument, mainly because .NET is
entirely new code. 

My complete ACK. I even have those sentences in my head coming from MS
marketeers themselfs stating that rebooting after software installation
would be not be seen with W2k anymore...

*cough*

If the poster isn't already tied to .NET, having them move to an immense
new chunk of beta-quality code seems like a dubious suggestion, IMO.

It's one of the main problems I often see in my work. Often developers use
those technologies of which a marketeer/evangeliste praied that it would
solve a special problem, but unfortunately the deepness of knowhow is then
often missing. This brings in new security problems... 

A problem can be solved with nearly every technology, the question is what
the problem is about and what are the needs.

And anyway. I still got not enough info from the first poster about what
he really wants to do and what the needs are to be able to tell him the
best solution...

Regards,
Adrian Wiesmann


Current thread: