Needed: code auditors
Posted Feb 5, 2004 18:37 UTC (Thu) by
kfiles (subscriber, #11628)
Parent article:
Needed: code auditors
It seems that distributed proofreaders has filled a very similar need in the Gutenberg project. The problem that was faced there was that most people were daunted by the task of reviewing entire books or even chapters, and therefore the progress of Gutenberg was relatively slow.
DP (http://www.pgdp.net) makes it easy for individuals to read over a page of scenned text at a teim, whenever they have a free moment. The result has been a record amount of free text added to the project over the last 1-2 years.
Perhaps a Distributed Kernel Auditors project could do the same for C code: provide small snippets (with linked context if needed) for C coders with spare time to pore over, looking for buffer exploits, pointer dereferences, file descriptor misuse, etc. Like DP, it could provide guidlines on patterns of dangerous coding, multiple levels of proofreading, etc.
Providing the right tool for the job is a key to the success of any such effort.
--kirby
(
Log in to post comments)