fsfe-uk
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Fsfe-uk] Re: BBC TV: Click: Free=beer and facebook-flaming


From: MJ Ray
Subject: [Fsfe-uk] Re: BBC TV: Click: Free=beer and facebook-flaming
Date: Sun, 18 May 2008 12:14:34 +0100
User-agent: Heirloom mailx 12.2 01/07/07

Florian Weimer <address@hidden> wrote: [...]
> These days, there's hardly any widely used piece of proprietary software
> for which you can't get the source code.

I wasn't aware of this.  The Norton Security tools on Windows cause
some associates of mine many problems.  Even if the apparent bugs
can't be fixed, knowing the precise details of how it worked with
help.  Where can they get the source code?

[...]
> It's also not clear if source code availability is that helpful for
> uncovering security bugs.

Would either the recent openssl/debian zero-entropy mistake or the
openssl dangerous use of uninitialised memory have been uncovered
without source code availability?

It seems to me that closed security software is a bit dangerous.
Treating it as a black box and prodding it with different inputs and
outputs is an inadequate way of testing it, not really checking.

Regards,
-- 
MJ Ray (slef)
Webmaster for hire, statistician and online shop builder for a small
worker cooperative http://www.ttllp.co.uk/ http://mjr.towers.org.uk/
(Notice http://mjr.towers.org.uk/email.html) tel:+44-844-4437-237




reply via email to

[Prev in Thread] Current Thread [Next in Thread]