Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Save the Net, Sue a Software Maker
David Banisar, 2001-12-17

Safety standards and civil liability made automobiles safe. It can work for software too.

Comments Mode:
Save the Net, Sue a Software Maker 2001-12-17
Sean, bremerton Wa (4 replies)
Re: Sean 2002-01-06
guest@netpixies.net
Save the Net, Sue a Software Maker 2002-01-12
An old codger that used to be proud of his profession.
Sean, your argument is vacuous. You admit that there are so many bugs and security windows that lawyers would get rich and the software industry would be destroyed if we start holding software companies responsible for their bugs. You further declare that there are so many bugs that malpractice insurance cost would bankrupt all but the largest software houses. Are you and your ilk so shallow that you believe that e-commerce will continue to grow utilizing such an unreliable and insecure software foundation?
Son, My Company was helping design and writing on-line real-time operating systems before you were probably born. When we designed, (not after we coded and tested) operating systems we had three unvarying rules: 1. No user shall ever be allowed to violate the operating system code. (Both hardware and software protection were used). 2. No user shall ever be allowed to access any other users data without tacit permission or user stupidity. 3. System software MTBF (mean time between failures) were required to be measured in months or years. If we could not assure that our design would satisfy these three rules, we dumped it and started over.
We Beta tested our software with consoles for free usage spread over the UC and Stanford labs and dorms as well as in engineering offices and homes. Our users were students bent on breaking our system by bringing it down or taking it over. The two IBM Class A time-sharing operating systems that we (An outside IBM ten man firm) designed, coded, and tested, was utilized by business, government, and over eighty universities worldwide for over twenty five years with no recorded penetrations of the operating system or by code breaking into another users data. The first live paying user test at the IBM operating Center in San Francisco operated 24/7 for three and a half weeks with hundreds of simultaneous users before the first OS bug was found. It did not bring down the system. It affected only one user. We, the designers and developers, were contracted to stay aboard for over a year to teach our IBM employee replacements and to act as the front line troubleshooters. The OS had less that a million lines of machine language code and was thus manageable for the long-long term.
That, young man, is how you produce a largely bug free OS product and achieve reliability, security, and trustworthiness among your users.
IBM paid us to write and publish our tenets, design principles, and techniques. We lectured and presented papers. These were the classes and professional papers that your generation seems to have slept through. Or are you just fundamentally flawed and irresponsible?

Signed, An old codger that used to be proud of his profession.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/47/9840#9840
Save the Net, Sue a Software Maker 2001-12-17
System High
Save the Net, Sue a Software Maker 2001-12-17
Jesse (1 replies)
Save the Net, Sue a Software Maker 2001-12-17
philw (1 replies)
Save the Net, Sue a Software Maker 2001-12-18
Anonymous (1 replies)
Save the Net, Sue a Software Maker 2001-12-18
Robert A. Matern (3 replies)
Save the Net, Sue a Software Maker 2001-12-18
Brad Freeman
Save the Net, Sue a Software Maker 2001-12-18
kbrown@nospam.com (2 replies)
Save the Net, Sue a Software Maker 2001-12-19
Robert A. Matern
Save the Net, Sue a Software Maker 2001-12-18
theX (2 replies)
Save the Net, Sue a Software Maker 2001-12-19
Robert A. Matern
Save the Net, Sue a Software Maker 2001-12-18
Anonymous (1 replies)
Save the Net, Sue a Software Maker 2001-12-19
Bill reilly
Save the Net, Sue a Software Maker 2001-12-18
Anonymous (1 replies)
Save the Net, Sue a columnist 2001-12-19
Anonymous (1 replies)
Save the Net, Sue a columnist 2001-12-20
Anonymous (1 replies)
Save the Net, Sue a columnist 2001-12-31
Annoyed Reader
Save the Net, Sue a Software Maker 2001-12-19
I Speak from Experience
Save the Net, Sue a Software Maker 2001-12-19
Rob John (1 replies)
Legal Clarifications... 2001-12-19
BillReilly
Sue Tim Burners Lee 2001-12-21
Anonymous
OS and App tools NOT ready for Prime time= lawsuit city! 2001-12-21
we are years away from having tools that coders can use safely (ex: SELinux and CycloneC)! (1 replies)
Save the Net, Sue a Software Maker 2001-12-29
Anonymous (1 replies)
Save the Net, Sue a Software Maker 2001-12-30
Sean Ackley <securityfocus@ackind.net>
Sue them ALL!!! 2001-12-31
JeffM (1 replies)
Get a brain... 2002-01-04
Matt Hargraves
Save the Net, Sue a Software Maker 2002-01-11
Blacksheep







 

Privacy Statement
Copyright 2009, SecurityFocus