Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a very good strategy for getting dangerous security flaws. BIND's security has improved dramatically since they went all-out on assertions; at least 1/3 of the "crash" bugs would have been remote code execution without the protective crashing.


sure, that's one of the tradeoffs. For some types of software, that's a dominant consideration. For others, it has little or no relevance.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: