<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-9074318.post6984541732609163299..comments</id><updated>2011-08-23T05:39:20.128-04:00</updated><category term='physicsenvy'/><category term='education'/><category term='publiceducation'/><category term='cryptography'/><category term='DNS'/><category term='tools'/><category term='cyberwar'/><category term='NAC'/><category term='FUD'/><category term='CNE'/><category term='books'/><category term='apple'/><category term='lexicon'/><category term='congress'/><category term='ex-tip'/><category term='groupthink'/><category term='fbi'/><category term='malware'/><category term='DefCon'/><category term='identitytheft'/><category term='privacy'/><category term='phreaking'/><category term='art'/><category term='BlackHat'/><category term='usereducation'/><category term='socialengineering'/><category term='browsers'/><category term='nerdery'/><category term='interface'/><category term='IW'/><category term='encryption'/><category term='scams'/><category term='AI'/><category term='analysis'/><category term='rss'/><category term='windows'/><category term='email'/><category term='physics'/><category term='cctv'/><category term='DEP'/><category term='hype'/><category term='blogs'/><category term='humor'/><category term='ieee'/><category term='visualization'/><category term='research'/><category term='personal'/><category term='security'/><category term='flyclear'/><category term='politics'/><category term='lecturing'/><category term='SANS'/><category term='dhs'/><category term='music'/><category term='games'/><category term='government'/><category term='legal'/><category term='identitymanagement'/><category term='overclassification'/><category term='philosophy'/><category term='cloud'/><category term='forensics'/><category term='fullpacketcapture'/><category term='certification'/><category term='antivirus'/><category term='economics'/><category term='ids'/><category term='disclosure'/><category term='CNA'/><category term='dod'/><category term='quotes'/><category term='CND'/><category term='epic'/><category term='eVoting'/><category term='architecture'/><category term='usaf'/><category term='markets'/><category term='periodicals'/><title type='text'>Comments on Security in Industry and Academia: EWD on Information Security</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.cloppert.org/feeds/6984541732609163299/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9074318/6984541732609163299/comments/default'/><link rel='alternate' type='text/html' href='http://blog.cloppert.org/2008/12/ewd-on-information-security.html'/><author><name>Michael Cloppert</name><uri>http://www.blogger.com/profile/04478065709387726187</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_yh9qMmyzuAU/SLNxci-ikKI/AAAAAAAAACA/Jlpc9eYMRkM/S220/Picture+1.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-9074318.post-5129370444815168721</id><published>2008-12-08T20:11:00.000-05:00</published><updated>2008-12-08T20:11:00.000-05:00</updated><title type='text'>Dean,&lt;br&gt;&lt;br&gt;Absolutely agreed that there are prac...</title><content type='html'>Dean,&lt;BR/&gt;&lt;BR/&gt;Absolutely agreed that there are practical limitations to contend with, but I think viewing unproven code as a fall-back position or lower-quality product is a good start.  Just like anything in security, the ideal is unreachable, but this gives a very concise, understandable point we can aim at.  Also remember that in this sense we are speaking of the science of computers.  Theoretical computer science can be as far removed from practical development as applied physics can be from theoretical physics.  But the theory shapes the understanding of the practitioners and future applications, and it is at that low of a level that I feel Dijkstra is correct in suggesting we re-evaluate the science.&lt;BR/&gt;&lt;BR/&gt;For a sub-discipline that's made provable algorithms work, see: cryptography.  Cryptographers can quickly point to just where their algorithms are and aren't provable.  They know and understand the risks at a level rarely matched by other practitioners of computer science.  No, all of our cryptographic systems aren't proven completely correct or sound, but going through the exercise of proof reveals where they may fail.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9074318/6984541732609163299/comments/default/5129370444815168721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9074318/6984541732609163299/comments/default/5129370444815168721'/><link rel='alternate' type='text/html' href='http://blog.cloppert.org/2008/12/ewd-on-information-security.html?showComment=1228785060000#c5129370444815168721' title=''/><author><name>Michael Cloppert</name><uri>http://www.blogger.com/profile/04478065709387726187</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_yh9qMmyzuAU/SLNxci-ikKI/AAAAAAAAACA/Jlpc9eYMRkM/S220/Picture+1.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cloppert.org/2008/12/ewd-on-information-security.html' ref='tag:blogger.com,1999:blog-9074318.post-6984541732609163299' source='http://www.blogger.com/feeds/9074318/posts/default/6984541732609163299' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-883995086'/></entry><entry><id>tag:blogger.com,1999:blog-9074318.post-7223341727140621565</id><published>2008-12-08T10:21:00.000-05:00</published><updated>2008-12-08T10:21:00.000-05:00</updated><title type='text'>It was an excellent read, and he's a genius, if on...</title><content type='html'>It was an excellent read, and he's a genius, if only for search algorithms and leading the charge to stop using GOTO statements.&lt;BR/&gt;&lt;BR/&gt;That said, we're talking about a man who didn't own or regularly use a computer until he needed one for email and web browsing.  He didn't spend any time in the corporate world, and there's a significant cost/benefit analysis that you'd have to do before trying to implement his work.  &lt;BR/&gt;&lt;BR/&gt;For example, mathematically provable code is *not* easy to write.  It's often easier in languages that aren't commonly used; Lisp and ML come to mind.  It requires a level of rigor that many programmers simply aren't capable of, either.&lt;BR/&gt;&lt;BR/&gt;Or, I think from the code-generation standpoint, provable code is useful for applications that *must* be perfect, but outside of that, it's a very questionable business move.&lt;BR/&gt;&lt;BR/&gt;Although admittedly, there's a much stronger argument for it on the security side of the fence.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9074318/6984541732609163299/comments/default/7223341727140621565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9074318/6984541732609163299/comments/default/7223341727140621565'/><link rel='alternate' type='text/html' href='http://blog.cloppert.org/2008/12/ewd-on-information-security.html?showComment=1228749660000#c7223341727140621565' title=''/><author><name>Dean Jackson</name><uri>http://www.blogger.com/profile/05862185746791036769</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cloppert.org/2008/12/ewd-on-information-security.html' ref='tag:blogger.com,1999:blog-9074318.post-6984541732609163299' source='http://www.blogger.com/feeds/9074318/posts/default/6984541732609163299' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-704401806'/></entry></feed>
