Re: bill gates' claim about security vulnerabilities per LOC inUnix versus Windows
"Kenneth R. van Wyk" <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Organization | Effing Manor |
| Message-ID | <[email protected]> |
On Wednesday 05 November 2003 15:12, Michael Howard wrote: > I think y'all are missing important point - the goal, overtime, should be > to reduce the incidence of such bugs appearing in the code... To do that > you have to train people, because let's be frank, this stuff isn't taught > in school, and you need to build a process that fosters building secure > code... I completely concur with you on that. The point that I (and Mark Graff) pointed out in our response to Mr. Gates (see http://www.theage.com.au/ articles/2003/11/03/1067708112226.html) is that his comments did not appear to take into account the security of _application_ code. He seemed to imply that patching and firewalls are sufficient to keep attacks at bay, but an SQL insertion attack, for example, can walk right past both of those if the application isn't up to par. Cheers, Ken van Wyk