Search the web
Sign In
New User? Sign Up
palm-dev-forum
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Real people. Real stories. See how Yahoo! Groups impacts members worldwide.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Re: When will they realize they are providing an operating system   Message List  
Reply | Forward Message #68862 of 92429 |
RE: When will they realize they are providing an operating system


> Most all major corporations throughout the world are using code without
> auditing it themselves, and this includes OSSS.

Most major corporations are regularly exploited externally and
internally on a regular basis because of insufficient security measures at
the application, OS, and hardware level to secure their own data. Just
because it doesn't make it to 'news.com' doesn't mean it isn't happening.
I've dealt with this dozens of times at a previous job at a very large
proprietary pharmeceutical company.

Nobody is advocating making the code "free", or publically
accessible. I said "open", which means access to it should be available.
Whether that access is through NDAs, or other methods that do not require
restrictive licensing, that's all that matters.

> See http://news.com.com/2100-1001-830130.html, where you will discover
> that "...the programs are getting audited a lot less than people think".

A moot point. Nimda is still pounding machines across the internet
every single day. I get 30-50 new hosts _IN MY SUBNET_ a week. How long ago
were people told to patch their machines against this? 7 months?

Auditing seems to happen when a problem is found, not when an
application is designed. This is 2002, and it's time to start thinking about
scalable, secure, distributed applications. You can't put security in a
black box anymore. Everyone's learned their lessons already by getting
burned by companies like Microsoft, Oracle, and others.

> For example, Sendmail has been open source for 20 years, and people have
> found more vulnerabilities in it every year of that 20 years.

Security is a process, not a program.

That being said, sendmail is developed by a company, with employees
and an agenda. Just because I find a hole, or an exploitable section of
code, and report it, is no guarantee that _ANYTHING_ will be done about it
(witness any of the hundreds of still-open holes in that OS from our friends
in Redmond)

My point is that auditing ensures data security more than "assuming"
that an application is secure. Everyone should be learning their lessons now
after getting burned by all the "spyware" in applications these days from
RealPlayer, Windows Media Player, :CueCat, and others.



/d



--
For information on using the Palm Developer Forums, or to unsubscribe, please
see http://www.palmos.com/dev/tech/support/forums/



Sat Feb 23, 2002 2:58 am

hacker@...
Send Email Send Email

Forward
Message #68862 of 92429 |
Expand Messages Author Sort by Date

... Can you go into a bit more depth of the term "hide"? What exactly are you "hiding", and what is the technical hurdle that necessitated closing it off from...
David A. Desrosiers
hacker@...
Send Email
Feb 22, 2002
11:59 pm

I'm really not the right person to answer your questions, and I'm sure I'll make some mistakes, but here goes anyway... The decision to disallow access to...
Peter Epstein
Peter.Epstein@...
Send Email
Feb 23, 2002
12:09 am

... Good God. "Hide" here doesn't mean closing things off from public view. It means hiding implementation behind defined interfaces, so that it's hidden from...
John Marshall
johnm@...
Send Email
Feb 23, 2002
1:39 am

... AIA for the OT remark: This is classic hyperbole and wishful thinking, probably by an open source afficionado. Most all major corporations throughout the...
Joe
free_email_account@...
Send Email
Feb 23, 2002
1:50 am

... Most major corporations are regularly exploited externally and internally on a regular basis because of insufficient security measures at the application,...
David A. Desrosiers
hacker@...
Send Email
Feb 23, 2002
3:00 am

... Then call it abstraction. You know how I'm going to react to the word "hide" anyway ;-) ... We agree. -- For information on using the Palm Developer...
David A. Desrosiers
hacker@...
Send Email
Feb 23, 2002
3:03 am

... Another term that is often used is "information hiding", which is somewhat different from abstraction. When the term "hide" is used in connection with...
Jim Cooper
jcooper@...
Send Email
Feb 23, 2002
9:49 am

Guy, Gals whoever reads this please keep one thing in mind that has helped the Palm be what it is today. When the OS couldn't do what the developer needed to...
Clifford Jones
cjones@...
Send Email
Mar 7, 2002
7:28 pm

"Clifford Jones" <cjones@...> wrote in message news:79106@palm-dev-forum... ... The problem is, that is exactly what is being closed off right...
Richard M. Hartman
hartman@...
Send Email
Mar 14, 2002
10:27 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help