Re: Writing Secure Code...
Chris <[email protected]> Wed, 19 Jan 2005 08:29:54 -0500
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I have been reading the list for awhile, I think its time I comment. :) Yes, DJB's djbdns is a 'pretty secure' application. But thats only when you compare it to other DNS packages available, such as BIND, and take into consideration what its code is being audited for. However DJB only makes his security guarntee with certain vulnerabilities in mind. You can read his security guarantee here http://cr.yp.to/djbdns/guarantee.html A 100% secure application is nearly impossible, this is true. But this does not mean an application cannot be immune to a class of particular vulnerabilities (stack overflows for example). But with features comes complexity and eventually more vulnerable code. Tommorow a new class of vulnerabilities could emerge, and with it could come advisories for djbdns. MLS is the best line(s) of defense. Just my two cents. Chris -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQFB7mDQXpi1p4x0qXsRAokfAKCF/S9Z05iRmMZr+4zVTe4aZQB1cQCgo6bM oddTtllYgK5Ae9k679Pfb/Q= =mQHv -----END PGP SIGNATURE-----