![]() |
![]() |
#12 | |
Bamboozled!
"๐บ๐๐ท๐ท๐ญ"
May 2003
Down not across
1165710 Posts |
![]() Quote:
Note, however, that some backdoors are much more subtle than others and may be very difficult indeed to spot. Something which leaks a single bit of keymat once every few network transactions would be most unlikely to be spotted in a blackbox investigation. Properly done, it would be very difficult to discover even with full access to source code. The leaking code would quite probably look like a subtle bug of the sort which people make through carelessness all the time. An ex-colleague of mine, now also ex-MSR Cambridge, yesterday posted the following statement to a security mailing list to which we both subscribe: Any sufficiently advanced malice is indistinguishable from incompetence.I can provide illustrations of the similar statement Any sufficiently advanced incompetence is indistinguishable from malice.and did so on the same mailing list. Paul |
|
![]() |
![]() |
![]() |
#13 |
Aug 2006
5,987 Posts |
![]()
I read a paper perhaps a year ago on this subject, and it seemed to support Paul's statement. (I don't imagine anyone knows the paper?)
|
![]() |
![]() |
![]() |
#14 |
Jun 2003
7×167 Posts |
![]() |
![]() |
![]() |
![]() |
#15 |
Undefined
"The unspeakable one"
Jun 2006
My evil lair
3·17·131 Posts |
![]()
Hacking to break stuff versus programming to make stuff, while they do overlap a small amount, are still mostly different skill sets. Usually programmers concentrate strongly on getting the damn thing working. While hackers are concentrating on getting a working thing to work in different ways than it was intended. So the developers are probably not the best people to be finding the faults. It needs a fresh eye without the preconceptions about what the code is designed to do.
|
![]() |
![]() |
![]() |
#16 |
"Richard B. Woods"
Aug 2002
Wisconsin USA
22×3×641 Posts |
![]()
When I was programming, my biggest mistakes and embarrassments were related to my unjustified assumptions. When I was testing someone else's code, it was all-too-easy to find such flaws.
|
![]() |
![]() |
![]() |
Thread Tools | |
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
mprime on OpenBSD 4.1 | robo_mojo | PrimeNet | 5 | 2008-05-04 12:49 |
Running the client under OpenBSD 3.3 | _ArJaN_ | NFSNET Discussion | 8 | 2004-05-05 13:42 |