Experts reveal top 25 programming blunders
Posted on 13 Jan 2009 at 09:26
A forum of the world's leading security experts has published the top 25 most dangerous programming errors.
The group, spearheaded by the US National Security Agency, hopes that exposing the programming flaws will result in more secure software and better teaching of computing students.
"Now, with the top 25, we can spend less time working with police after the house has been robbed and instead focus on getting locks on the doors before it happens," says Paul Kurtz, a principal author of the US National Strategy to Secure Cyberspace.
Experts from Microsoft, Oracle and Symantec were amongst the panel of more than 30 security specialists. The group reportedly agreed on the top 25 flaws relatively quickly, although not before "some heated discussion".
The group hopes that corporate buyers will demand written assurances that software is free of all 25 bugs before making purchases in the future. "Certification shifts responsibility to the vendor for correcting the errors and for any damage caused by those errors," claims the SANS Insitute, which managed the top 25.
Whether software companies will be prepared to accept such liability awaits to be seen.
The top 25 errors include failure to control code injection (which has been responsible for many high-profile attacks over the past 18 months), improper access controls and use of broken cryptography algorithms.
The full list of the top 25 errors is available here. The list will be regularly updated.
Author: Barry Collins
advertisement
- 10 ways to boost traffic to a WordPress blog
- Reaction to the Apple iPad: ten days later
- How to switch off Virgin Media's mobile broadband image compression
- Infotec/Ricoh: here not to help
- TomTom 940T vs iPhone TomTom: a real road test
- Nvidia Fermi update: they have names!
- Twitter oven lets you have your cake and tweet it
- Where online businesses go terribly wrong
- Google Nexus One: first look review
- Dreading the move to ADSL
- The hidden treasures of Sysinternals
- Microsoft must stop silently installing browser plugins
- Crack the Microsoft Server 2008 Core with CoreConfig
- Forget Windows: SMBs should try Snow Leopard Server
- Poking into Facebook security
- Has Microsoft shot itself in the foot with Security Essentials?
- Smashing the BlackBerry myths
- Has Microsoft solved our stylesheet woes with Super Preview?
- Automated printing of SQL Server Reports
- Setting up iSCSI on a desktop PC
advertisement
Printed from www.pcpro.co.uk


