[Techtalk] Theory vs. practice

Jenn Vesperman jenn at anthill.echidna.id.au
Mon Jan 14 19:28:30 EST 2002


On Mon, 2002-01-14 at 18:12, Julie wrote:

> A lot of what's out there today in terms of "practice" has very
> little to do with formal security theory and more to do with really
> bad coding.  For example, most of the security problems we see are
> coding errors -- buffer overflows, parameter checking, software
> races, and the like.  

Yes, but programmers aren't being taught how to avoid these coding
errors, or what errors to avoid.



Jenn V.
-- 
    "Do you ever wonder if there's a whole section of geek culture 
        	you miss out on by being a geek?" - Dancer.

jenn at anthill.echidna.id.au     http://anthill.echidna.id.au/~jenn/





More information about the Techtalk mailing list