Comments on: 11 open-source projects certified as secure
Under contract with the Department of Homeland Security, Coverity seeks to establish a new security baseline for open-source applications.
Under contract with the Department of Homeland Security, Coverity seeks to establish a new security baseline for open-source applications.
Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.
Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.
Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.
Add this feed to your online news reader
I know you were really talking about the source code though. Mature projects are usually pretty good.
- Sec Code != Sec App
- by the osd guy January 9, 2008 3:20 PM PST
- What about design flaws?
- Like this Reply to this comment
-
(3 Comments)What about info disclosures?
What about denial of service issues?
What about unxepected parse failures?
What about ...
There is more to secure applications than making sure ur buffers are correctly sized. Static analysis cant fully guarentee that and fuzz testing can only verify the product is as reliable as the fuzzer's randomizor logic.