846 karma · joined September 25, 2013
What de Raadt means to say is, generally speaking, you can't build security on top of bad code. No amount of patching, sandboxing, or whatever will help. Security comes from quality and Xen (like Linux) is very lacking in quality.
https://en.wikipedia.org/wiki/Close-packing_of_equal_spheres (We memorized this stuff in chemistry class and I never saw it again so I may be completely wrong.)
Europe could decide to open their borders, and they would be fine. The US deals with much larger migrations every year. Or they could decide to close the borders, and they would be fine too.
Instead they do some schizophrenic dance in between. Some borders open, some closed. Broadcast to the world that people are welcome, and greet them with fences...
Decide and do. Stop talking about how it makes you feel.
/*@ loop invariant i;
loop invariant j >= 0;
loop assigns j, eol;
*/
for (j = 0; j < (size_t) i; j++) {
if (read_buffer[j] == '\n') {
eol = 1;
j++;
break;
}
}
Loop invariants are part of the ACSL specification language, and they can be verified automatically with Frama-C. http://frama-c.com/acsl.htmlThey ask you about wine and gambling. Say, "In them is great sin and [yet, some] benefit for people. But their sin is greater than their benefit."
-- 2:219 http://quran.com/2/219
Keep in mind that the Quran was revealed piece by piece over two decades. The later parts add to the earlier parts. That can be a source of ambiguity to Western readers (not to mention that the chapters are not in chronological order), which is why it's important to understand it as a whole rather than its individual verses or chapters.
People here defend VC because they think they too will get rich quick, but they won't, and in the meantime they will be very stressed and nasty on the Internet. Welcome to HN.
What's the difference between GCC deleting parts of your code, and an attacker hacking into the source code repository and deleting those parts of the code?
The C standards committee addressed the problem in 2009 with memset_s. [0] The GNU developers reject patches and state they hope this feature is never implemented. [1]
The bug fix is to stop using GCC for sensitive code. Use CompCert instead. https://github.com/AbsInt/CompCert
[0] http://www.open-std.org/jtc1/sc22/wg14/www/docs/n1381.pdf
[1] https://sourceware.org/ml/libc-alpha/2014-12/threads.html#00...
I doubt eight bytes is enough for cryptography...
If you need random bytes in Python, use os.urandom:
secret = os.urandom(32)
https://docs.python.org/2/library/os.html#os.urandomI wouldn't use it everywhere, but in small, important functions, it's well worth it.
Here's the classic example of reading into a buffer: https://github.com/eliteraspberries/ttyprompt/blob/master/ge... From those few annotations, Frama-C is able to determine that there are no buffer overflows there.
This attack on Turkey is an example of Russian "active measures."
Edit: By the way, the entire tr TLD is managed by a single DNS server at METU. That was the target of the attack.
https://github.com/AbsInt/CompCert
It's free for non-commercial use. I've used it for several months now to build things like Tor. I haven't noticed any disadvantage compared to GCC or Clang.
Will renaming a function or two fix my bad behaviour?
The answer to "Should I use Math.random or X" is neither! I should be using a cryptography library like SJCL or tweetnacl-js:
WhatsApp can just turn off encryption when they want, without users knowing:
That's probably what happened in June:
"Investigators said earlier they had detained 16 people in the anti-terror raids after working with U.S. authorities to monitor suspects' communications on WhatsApp Inc.'s messaging service."
http://www.bloomberg.com/news/articles/2015-06-08/belgium-ar...
func += (inout left: Vector2D, right: Vector2D) {
left = left + right
}
https://developer.apple.com/library/ios/documentation/Swift/...