Version: 2008

the osd guy's community profile

About me

My posting summary

  • Comments: 1
1 to 1 of 1
Sort by: Show results per page

My comments

  • Sec Code != Sec App
    What about design flaws?
    What about info disclosures?
    What about denial of service issues?
    What about unxepected parse failures?
    What about ...

    There is more to secure applications than making sure ur buffers are correctly sized. Static analysis cant fully guarentee that and fuzz testing can only verify the product is as reliable as the fuzzer's randomizor logic. In reply to: "11 open-source projects certified as secure"

    January 9, 2008

    0 replies