SEPostgres
SEPostgres
Posted Sep 15, 2011 4:58 UTC (Thu) by dpquigl (guest, #52852)In reply to: SEPostgres by Cyberax
Parent article: PostgreSQL 9.1 released
[1]http://web.nvd.nist.gov/view/vuln/search-results?query=JR...
[2]http://blog.cr0.org/2010/04/javacalypse.html
Posted Sep 15, 2011 12:52 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (3 responses)
Additionally, JVM's trust model and Code Access Security in CLR are braindead and should die.
Posted Sep 15, 2011 18:58 UTC (Thu)
by dlang (guest, #313)
[Link] (2 responses)
Posted Sep 15, 2011 20:30 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (1 responses)
There will be problems with insecurely JIT-ed machine code, but I believe they can also be solved.
Posted Sep 22, 2011 4:53 UTC (Thu)
by cmccabe (guest, #60281)
[Link]
But lets assume that "this time is different" and you really succeed in rewriting absolutely everything in ${LANGUAGE}. Well, once you have this perfect operating system (we'll assume it's bug-free, despite being written by humans), running on perfect hardware which somehow exists, you'll still get hacked.
Why? Because you'll give a login to someone who has a password sniffer installed on his computer. Or put his password on a post-it note near the monitor. Or who uses the same login for multiple accounts, one of which gets hacked. Or who uses a password that can be guessed. Or who you never should have trusted in the first place. Or any one of the million ways that your security can be breached that have nothing to do with what language your operating system is written in.
SEPostgres
SEPostgres
SEPostgres
SEPostgres