Re: Securing and taming an existing language

Bill Frantz <[email protected]> Tue, 24 Feb 2015 13:10:24 -0800
Newsgroups gmane.comp.lang.e.general
Message-ID <r422Ps-1075i-4F6D433E58D04ADC81D6861965E514CD@Williams-MacBook-Pro.local>
On 2/24/15 at 10:12 AM, [email protected] (Mark S. Miller) wrote:

>[+David, +Adrian, +Tyler]
>
>
>Joe-E taming of Java: https://code.google.com/p/joe-e/wiki/Taming
>Javadoc of Joe-E taming of Java: http://www.cs.berkeley.edu/~daw/joe-e/api/
>
>E taming of Java:
>http://www.combex.com/papers/darpa-review/security-review.html#taming
>http://www.erights.org/elib/legacy/taming.html
>Javadoc of E taming of Java: http://www.erights.org/javadoc/index.html
>
>Although Joe-E's taming was inspired by E's taming, it was purposely done
>without reference to the particular E taming decisions so that we could
>compare them afterwards and learn from their differences. Unfortunately,
>AFAIK, no one has yet done this comparison, though it would still be
>interesting.

I have always been concerned that taming involves many human 
decisions, each subject to human error. Comparing two 
independent taming projects seems like a good way of finding out 
how error prone these decisions actually are. If there are very 
few discrepancies, then we can have some confidence that humans 
can actually tame. If there are a lot, including dangerous items 
that passed one taming example, but not the other, then watch out.

Cheers - Bill

---------------------------------------------------------------------------
Bill Frantz        |"After all, if the conventional wisdom was 
working, the
408-356-8506       | rate of systems being compromised would be 
going down,
www.pwpconsult.com | wouldn't it?" -- Marcus Ranum