Bernstein on Preventive Security
Friday, November 16th, 2007Dan Bernstein (also known as djb, the mastermind who wrote QMail, recently wrote a paper discussing methods of ensuring security. The approach is unique: his notion of security is not based on posthumous investigation such as minimizing privileged code and intrusion detection systems, but on a methodology transcending all phases of engineering an application that employs methods that disallow the engineer to write code that can be exploited. It is located at http://cr.yp.to/qmail/qmailsec-20071101.pdf.
