Secure Programming
Charging customers on security Sep 23 2004 05:16PM
King Pang (kingpang gmail com) (6 replies)
Re: Charging customers on security Sep 29 2004 02:25PM
Bart Lansing kohls com
Re: Charging customers on security Sep 28 2004 12:26AM
Thor (thor hammerofgod com)
RE: Charging customers on security Sep 27 2004 05:24PM
Yvan Boily (yboily seccuris com)
RE: Charging customers on security Sep 27 2004 01:47PM
Chris Matthews (cmatthews xn com) (1 replies)
Re: Charging customers on security Sep 27 2004 04:36PM
King Pang (kingpang gmail com) (3 replies)
Re: Charging customers on security Sep 28 2004 09:51AM
Andreas Krügersen (phoenix wyverex-cave net)
RE: Charging customers on security Sep 28 2004 09:00AM
Koen Vingerhoets (koen vingerhoets ubench be)
RE: Charging customers on security Sep 27 2004 05:53PM
Chris Matthews (cmatthews xn com)
Re: Charging customers on security Sep 27 2004 08:37AM
exon (exon home se)
Re: Charging customers on security Sep 26 2004 10:40PM
wirepair (wirepair roguemail net) (7 replies)
Re: Charging customers on security Sep 27 2004 04:20PM
Adam Shostack (adam homeport org) (1 replies)
Re: Charging customers on security Sep 28 2004 08:33PM
S. M. (vel sympatico ca)
Re: Charging customers on security Sep 27 2004 03:18PM
Jeff Williams (jeff williams aspectsecurity com)
Re: Charging customers on security Sep 27 2004 01:57PM
ovi (marioara alexandru tin it) (2 replies)
Re: Charging customers on security Sep 28 2004 03:12AM
Glynn Clements (glynn clements virgin net) (2 replies)

ovi wrote:

> It's ridiculous. What are you saying ?? If I as a client, don't pay you for
> having a stable and secure program you sell me a buggy one???? Not even M$ is
> thinking this way anymore, although they continue to sell buggy OS.

There's nothing ridiculous about the cost to the client reflecting the
development costs. Implementing security features takes time and
therefore costs money.

Validating inputs requires effort. Testing for and handling errors
requires effort. Authentication, encryption and lots of other things
which may improve security all require effort.

Depending upon the environment in which the software will be used,
there may or may not be any point in expending that effort.

E.g. a command-line utility which isn't setuid and which is only
accessible by users with shell access may not need to be concerned
with buffer overruns. There's nothing which I can achieve by injecting
shellcode into one of my own processes which I can't achieve by just
compiling/installing and running an equivalent program.

[The situation is different if the user may be blindly feeding
"untrusted" data to the program. In that case, the program is
"accessible" to the creators of such data.]

If you are developing software for commercial publication (the
Microsoft model), then it may be used in a large number of different
environments, and many of those environments will require that the
software is robust against "unexpected" inputs.

But not all software fits this model. A lot of software is bespoke,
i.e. it is developed for a specific client for a specific purpose, and
will only be used in a specific context. It's entirely possible that
it doesn't need to deal with unexpected cases, because you are sure
that the only people who will ever use it won't be deliberately trying
to break it. In that situation, expending additional effort on
security issues is unjustified.

--
Glynn Clements <glynn.clements (at) virgin (dot) net [email concealed]>

[ reply ]
RE: Charging customers on security Sep 28 2004 10:31PM
Yvan Boily (yboily seccuris com)
Re: Charging customers on security Sep 28 2004 08:29PM
Wesley Shields (wxs csh rit edu) (1 replies)
Re: Charging customers on security Sep 29 2004 05:39PM
Jesper Anderson (jesper pobox com) (1 replies)
RE: Charging customers on security Sep 29 2004 09:21PM
Yvan Boily (yboily seccuris com)
RE: Charging customers on security Sep 27 2004 04:24PM
Koen Vingerhoets (koen vingerhoets ubench be)
RE: Charging customers on security Sep 27 2004 01:07PM
Jediah (rife madeinmaine org)
RE: Charging customers on security Sep 27 2004 07:45AM
Yoav Nir (ynir checkpoint com)
Re: Charging customers on security Sep 27 2004 04:42AM
Michael E.Conlen (meconlen obfuscated net)
Re: Charging customers on security Sep 27 2004 04:33AM
Steve Friedl (steve unixwiz net)


 

Privacy Statement
Copyright 2010, SecurityFocus