Great Circle Associates Firewalls
(March 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: creating secure code
From: Remy NONNENMACHER <remy @ synx . com>
Date: Thu, 13 Mar 1997 19:54:09 -0100 (GMT)
To: Bret Watson <bwa @ usa . net>
Cc: firewalls @ greatcircle . com
In-reply-to: <v03007803af4d15b32765 @ [134 . 7 . 108 . 43]>

On Thu, 13 Mar 1997, Bret Watson wrote:

> >> You guys do realize that a compiler/language is NOT responsible for
> >>creating secure code -- don't you?
> >> IT'S THE DEVELOPER'S JOB. NOT THE LANGUAGE.

--> You're false !!

> 
> But if you are going to have A or B level applications/OS then the compiler
> has to be secure too. Remember secure at this level means - does not break
> for any reason. Personally I wouldn't use MS VC++ for a military program
> even if I was the world's best programmer and I had specs written in Z,
> would you?
> 

--> You're right !!

> Cheers,
> 
> Bret
> 
> Bret Watson & Associates    bwa @
 usa .
 net
> phone +61 41 4411 149 fax +61 9 454 6042
> Computer & Information Security  Consultants
> 
> 
> 

I can't even remember how many time i spent with buggy optimizing 
compilers, all from M$, that works fine with optimization EXPLICITLY 
disabled. So, Even with the best review of the code, a compiler can 
introduce bug !!

(For fun : i guess what compiler was used for, let's say, NT.... hum....).
(For fun (2) : SCO continue using old M$ code in their C comps....)

No flame, please, i only guess about fiability of Firewall products 
compiled with (possibly) bad compilers.



References:
Indexed By Date Previous: Re: NT Disk Shares
From: james @ mail . th . net (James Triplett)
Next: Re: Firewall and "single point of failure" issue
From: "Kelly E. Gibbs" <kgibbs @ best . com>
Indexed By Thread Previous: Re: creating secure code
From: Bret Watson <bwa @ usa . net>
Next: Re: creating secure code
From: "Frank O'Dwyer" <fod @ brd . ie>

Google
 
Search Internet Search www.greatcircle.com