From owner-freebsd-chat@FreeBSD.ORG Tue Jun 29 20:35:43 2004 Return-Path: Delivered-To: freebsd-chat@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E86E716A4CE for ; Tue, 29 Jun 2004 20:35:43 +0000 (GMT) Received: from faceman.servitor.co.uk (faceman.servitor.co.uk [80.71.15.146]) by mx1.FreeBSD.org (Postfix) with ESMTP id AE49B43D3F for ; Tue, 29 Jun 2004 20:35:43 +0000 (GMT) (envelope-from wiggy@servitor.co.uk) Received: from wiggy by faceman.servitor.co.uk with local (Exim 4.30) id 1BfPL6-000HrW-2F; Tue, 29 Jun 2004 21:36:24 +0100 Date: Tue, 29 Jun 2004 21:36:24 +0100 From: Paul Robinson To: Kevin Lyons Message-ID: <20040629203624.GW34683@iconoplex.co.uk> References: <40E1A6C0.2040406@ofdengineering.com> <40E1B3B5.1020906@palisadesys.com> <40E1B7A3.3040409@ofdengineering.com> <20040629201433.GV34683@iconoplex.co.uk> <40E1D15B.5040605@ofdengineering.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <40E1D15B.5040605@ofdengineering.com> Sender: Paul Robinson cc: freebsd-chat@freebsd.org Subject: Re: "TrustedBSD" addons X-BeenThere: freebsd-chat@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Non technical items related to the community List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 29 Jun 2004 20:35:44 -0000 On Tue, Jun 29, 2004 at 03:30:19PM -0500, Kevin Lyons wrote: > Is there an ACM or IEEE article that quantifies this? You can not write an accurate assessment of potential vulnerabilites, only discovered ones. It does not take a genius to work out that it only takes one line of badly written code to introduce a vulnerability. It does not take a genius to realise that badly written code is as much a management issue as any other. It certainly does not take a genius to asset that well written code impregnable code is well written and impregnable no matter how many lines of code it is made up of. > >"Of late"? You've *JUST* noticed? Wow. :-) > > I will rephrase, I noticed enough to finally comment. Even so. :-) -- Paul Robinson http://www.iconoplex.co.uk/