« Quick Supporting Links... | Main | Call Your Congresscritter: Copyrights and Financial Aid? »

Excellent Secure Coding Paper

D.J. Bernstein, author of qmail and professor at U-Chicago, has released a new paper on qmail security. Though ostensibly about qmail, it's really an exposé on secure coding practices. In the paper, he identifies three fundamental approaches that will met "users' security requirements" within a given program:
1) eliminate bugs
2) eliminate code
3) eliminate trusted code

There's nothing I can say here that isn't better said by DJB in his paper. As such, I highly recommend reading it right away. It's very short (10 pages including the page of references) and very accessible. You do not need to be a programmer or a CompSci major to understand what he is saying.


TrackBack

TrackBack URL for this entry:
http://www.secureconsulting.net/MT/mt-tb.cgi/454

Post a comment

About

This page contains a single entry from the blog posted on November 6, 2007 6:19 PM.

The previous post in this blog was Quick Supporting Links....

The next post in this blog is Call Your Congresscritter: Copyrights and Financial Aid?.

Many more can be found on the main index page or by looking through the archives.

Creative Commons License
This weblog is licensed under a Creative Commons License.