Re: Writing Secure Code...

Chris <[email protected]> Wed, 19 Jan 2005 08:29:54 -0500
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I have been reading the list for awhile, I think its time I comment.  :)

Yes, DJB's djbdns is a 'pretty secure' application. But thats only
when you compare it to other DNS packages available, such as BIND, and
take into consideration what its code is being audited for. However
DJB only makes his security guarntee with certain vulnerabilities in
mind.  You can read his security guarantee here
http://cr.yp.to/djbdns/guarantee.html

A 100% secure application is nearly impossible, this is true. But this
does not mean an application cannot be immune to a class of particular
vulnerabilities (stack overflows for example). But with features comes
complexity and eventually more vulnerable code. Tommorow a new class
of vulnerabilities could emerge, and with it could come advisories for
djbdns.

MLS is the best line(s) of defense.

Just my two cents.

Chris
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFB7mDQXpi1p4x0qXsRAokfAKCF/S9Z05iRmMZr+4zVTe4aZQB1cQCgo6bM
oddTtllYgK5Ae9k679Pfb/Q=
=mQHv
-----END PGP SIGNATURE-----