TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Dramatically Reducing Software Vulnerabilities [pdf]

77 点作者 neiesc超过 8 年前

6 条评论

Animats超过 8 年前
Those are the usual answers. But they&#x27;re too broad.<p>A good way to look at the problem is that trusted software needs to be far less vulnerable, and untrusted software needs to be kept in a cage where it can&#x27;t make trouble.<p>On the untrusted side, all games, for example, should be caged or sandboxed. (Yes, this breaks some intrusive anti-cheat mechanisms. Tough.) Applications on phone-type platforms should have far fewer privileges, (Yes, that breaks some ad networks. Tough.)<p>Until somebody with enough power to make it stick takes a hard-ass position and sets standards, there&#x27;s not going to be progress. It would be progress if AT&amp;T or Comcast or Verizon deployed secure routers, for example.
评论 #13246979 未加载
评论 #13248436 未加载
评论 #13246883 未加载
评论 #13247965 未加载
tyingq超过 8 年前
Fairly in-depth. I&#x27;m surprised though, at the generally positive tone around containers&#x2F;docker. No mention of the the current widespread practice of containers running as root. Nothing about the relative lack of protection against local kernel exploits escaping the container, etc.<p>Was expecting something a little more balanced on the topic.
评论 #13246768 未加载
ctz超过 8 年前
I don&#x27;t really understand why this doesn&#x27;t cover memory safety.
评论 #13246662 未加载
评论 #13246659 未加载
评论 #13245887 未加载
PaulHoule超过 8 年前
It seems like I am seeing something about SAT solvers almost every day now.
gravypod超过 8 年前
Some of these are great, some of these are OK, and some of these are horrible ideas. I wish instead of &quot;studies&quot; we did RFCs
评论 #13245919 未加载
评论 #13245859 未加载
godmodus超过 8 年前
&quot;A weakness is an undesired characteristic of a system’s requirements, design or implementation [Black11a]. This definition excludes:<p>* ...<p>* insider malfeasance, such as exfiltration by Edward Snowden&quot;<p>Heh.
评论 #13246513 未加载