comp.lang.ada
 help / color / mirror / Atom feed
From: "Nasser M. Abbasi" <nma@12000.org>
Subject: Re: Does Ada need a 'secure coding standard' as well?
Date: Sat, 28 May 2011 12:38:56 -0700
Date: 2011-05-28T12:38:56-07:00	[thread overview]
Message-ID: <irrj0h$6cb$1@speranza.aioe.org> (raw)
In-Reply-To: op.vv7go1jvule2fv@douda-yannick

On 5/28/2011 12:06 PM, Yannick Duchêne (Hibou57) wrote:

>
> Except that, there already exist to some Ada subset, or profiles. One of
> the most common is the one which is required with SPARK. Here again, no
> need to setup some rules and ask the authors to follow these rules and
> nothing else, as these are already checked by the SPARK Checker.
>

That was my initial reaction to when I saw those rules,
is that a well designed secure language, would not need such rules
(or much of then any them) for a programmer to remember, since
the compiler will check and reject code written which is 'not secure'
as it will be something not allowed at the language level itself.

But when I said that in the Java newsgroup I got screamed at :)

Most of the rules seem to target handling strings, where,
as one would expect, most of the security problems can sneak in.

The funny thing, is that Java 7 just added a switch on string  !

http://www.vineetmanohar.com/2011/03/new-java-7-feature-string-in-switch-support/

So, may be now more rules needs to be added for the programmer
to remember when using this new feature added by the language,
so they can use it in 'secure' way.

--Nasser



  reply	other threads:[~2011-05-28 19:38 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-05-28 18:53 Does Ada need a 'secure coding standard' as well? Nasser M. Abbasi
2011-05-28 19:06 ` Yannick Duchêne (Hibou57)
2011-05-28 19:38   ` Nasser M. Abbasi [this message]
2011-05-28 19:45     ` Yannick Duchêne (Hibou57)
2011-05-28 19:32 ` Ludovic Brenta
2011-05-31 16:59   ` Simon Clubley
2011-05-31 17:51     ` AdaMagica
2011-05-31 18:54       ` Simon Clubley
2011-05-28 21:37 ` Simon Wright
2011-05-29 13:29   ` Mark_Ngbapai
2011-05-29 13:58     ` Simon Wright
2011-05-29 14:04 ` Yannick Duchêne (Hibou57)
2011-05-29 14:05   ` Yannick Duchêne (Hibou57)
2011-05-30 10:25   ` J-P. Rosen
2011-05-29 15:23 ` Maciej Sobczak
2011-05-29 15:53   ` Yannick Duchêne (Hibou57)
2011-05-30 10:27     ` J-P. Rosen
2011-05-29 21:03   ` Florian Weimer
replies disabled

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox