Daniel Bernstein: ten years of qmail security
[Posted November 3, 2007 by corbet]
Daniel J. Bernstein has posted
a paper looking back at
the security of qmail [PDF], ten years after 1.0 came out.
"
In retrospect, some of qmail's "security" mechanisms were half-baked
ideas that didn't actually accomplish anything and that could have been
omitted with no loss of security. Other mechanisms have been responsible
for qmail's successful security track record. My main goal in this paper is
to explain how this difference could have been recognized in advance--how
software-engineering techniques can be measured for their long-term
security impact."
(
Log in to post comments)