Re: RISKS: Princeton discovers another Netscape security flaw

17 Dec
2003
17 Dec
'03
11:17 p.m.
At 23:48 3/24/96, Perry E. Metzger wrote:
When you build something large and complex, and you require that the entire thing work for you to be secure, there are just too many failure modes.
That just about sums it up. Chisel these in granite: o Thou shall not execute untrusted code. Java or no Java. o Privileges that an user doesn't have can't be abused. o The only safe firewall is a non-networked computer. o A feature that doesn't exist won't introduce security holes. Yes, I know that there is a balance between functionality and security. Where to draw the line depends on the application. -- Lucky Green <mailto:shamrock@netcom.com> PGP encrypted mail preferred.
7876
Age (days ago)
7876
Last active (days ago)
0 comments
1 participants
participants (1)
-
shamrock@netcom.com