Re: Securing and taming an existing language
Bill Frantz <[email protected]> Tue, 24 Feb 2015 13:10:24 -0800
| Newsgroups | gmane.comp.lang.e.general |
|---|---|
| Message-ID | <r422Ps-1075i-4F6D433E58D04ADC81D6861965E514CD@Williams-MacBook-Pro.local> |
On 2/24/15 at 10:12 AM, [email protected] (Mark S. Miller) wrote: >[+David, +Adrian, +Tyler] > > >Joe-E taming of Java: https://code.google.com/p/joe-e/wiki/Taming >Javadoc of Joe-E taming of Java: http://www.cs.berkeley.edu/~daw/joe-e/api/ > >E taming of Java: >http://www.combex.com/papers/darpa-review/security-review.html#taming >http://www.erights.org/elib/legacy/taming.html >Javadoc of E taming of Java: http://www.erights.org/javadoc/index.html > >Although Joe-E's taming was inspired by E's taming, it was purposely done >without reference to the particular E taming decisions so that we could >compare them afterwards and learn from their differences. Unfortunately, >AFAIK, no one has yet done this comparison, though it would still be >interesting. I have always been concerned that taming involves many human decisions, each subject to human error. Comparing two independent taming projects seems like a good way of finding out how error prone these decisions actually are. If there are very few discrepancies, then we can have some confidence that humans can actually tame. If there are a lot, including dangerous items that passed one taming example, but not the other, then watch out. Cheers - Bill --------------------------------------------------------------------------- Bill Frantz |"After all, if the conventional wisdom was working, the 408-356-8506 | rate of systems being compromised would be going down, www.pwpconsult.com | wouldn't it?" -- Marcus Ranum