Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Results, Not Resolutions
Bruce Schneier and Adam Shostack , SecurityFocus 2002-01-24

A guide to judging Microsoft's security progress.

Comments Mode:
Results, not Resolutions 2002-01-24
Anonymous
The numerous APIs (have a look at, for example, ntifs.h) that accept null terminated buffers with nary a buffer size argument in sight, or that accept buffers of such buffers (terminated by another null) would seem to invite problems over time. I would argue that when we see alteration in these APIs so that buffer size can be tracked internally, then we have evidence that someone is thinking about a system whose internals are MAINTAINABLY not subject to overflow errors. Yes, you can find many overflow problems at a point in time, but changing the APIs to include the necessary checking information (and of course using it in the code) will keep problems from creeping in whenever internals tweaks are made.

This is not to denigrate the excellent suggestions in the article; I agree with those. This is just another proof point.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/315/10087#10087
Results, not Resolutions 2002-01-24
Gary McGraw
Results, Not Resolutions 2002-01-24
David Litchfield (2 replies)
Results, Not Resolutions 2002-01-24
davep (at) pitt (dot) edu [email concealed] (1 replies)
Results, Not Resolutions 2002-01-25
Nicholas Harring
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-24
Anonymous (1 replies)
Results, Not Resolutions 2002-01-24
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Well, to conclude: Use Java, M$ 2002-01-25
Anonymous (1 replies)
Well, to conclude: Use Java, M$ 2002-01-25
Trithemius (1 replies)
Well, to conclude: Use Java, M$ 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
BMaximus
SOAP Recommendation is Silly 2002-01-25
Anonymous (1 replies)
SOAP Rec is correct 2002-01-26
Anonymous
Almost right on the compensation 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Chris
Regarding macros in documents... 2002-01-25
Anonymous
Things getting out of hand here? 2002-01-26
Toni Heinonen
Microkernel smog 2002-01-27
Grumpf
Inaccuracies and crazy talk 2002-01-28
Anonymous
Results, Not Resolutions 2002-01-28
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus