TranceAddict Forums

TranceAddict Forums (www.tranceaddict.com/forums)
- Canada - Toronto & Southern Ont.
-- Firefox aims for 10 percent of Web surfers
Pages (5): « 1 2 3 4 [5]


Posted by loca on Nov-12-2004 20:17:

quote:
Originally posted by rabbitjoker
Just one day after the Mozilla Foundation released Firefox 1.0, the group has revealed that prior versions of the open-source browser pose a security threat to users. According to information released by Mozilla, multiple security holes have been plugged in all beta versions of Firefox to correct flaws that could lead to security bypass, exposure of sensitive data, privilege escalation and DoS (denial of service) attacks.

Research firm Secunia rates the vulnerabilities as "moderately critical". Mozilla warned that successful exploits could also detect the presence of local files, spoof the file download dialog, or gain escalated privileges on vulnerable machines

------------------------------------

People bitch and moan about MS security this, MS security that...

Face it folks - an computer that is connected to another via any means is vulnerable.

IMO - There is no reason to change browsers simply for security purposes (if you have XP-SP2 installed).


Few things, the reason they're finding tons of security exploit is because mozilla is actually rewarding people who find them, so people are going in there and finding them.
Also, those are moderately critical vulnarablities, as opposed to extremely critical, which surface in IE fairly often. In addition, i might add that these vulnerablities surfaced in previous versions of mozilla, in other words, the beta versions. IE gets critical vulnerabilties in versions that are out of beta and on the market.


Posted by DigiNut on Nov-13-2004 02:04:

In Firefox, "multiple security holes" means about 3. Compare that to about 300 in Internet Explorer.

There have been buffer overflow exploits in Linux kernels too, but the point is, they are found quickly, fixed quickly, and patches (or in the case of Firefox, new versions) are released immediately. And as stated earlier, the particular "holes" in Firefox are not gaping holes that "might allow an attacker to take control of your computer" (surely everybody is intimately familiar with those words by now from using Windows/IE).

"Vulnerable" isn't one of these black and white terms that you can say a computer either is or is not. Security comes in 256 full-colour hues of tightness. Firefox is an off-white, while IE is jet black.


Posted by Your Mother on Nov-13-2004 14:27:

quote:
Originally posted by DigiNut
Oh no doubt about that, and that's why I peg the blame at 50/50. You have to be fair though, it's really hard for management to make good hiring decisions when colleges and universities are churning out 50,000 graduates a year who write code like

Form5->ListBox3->Items->Objects[atoi(substr(Form1->Edit2->Text, 4, strlen(Form1->Edit2->Text)))]->QR = App_QR1 + lfunc(x - 5, y+z) + 3,

where App_QR1 is declared as a global variable in a unit called "misc.h", which consists of about 100 different totally unrelated variables and functions with equally cryptic names like "pkStFrmShMLA" and "int getMRblkT(PChar *P)" and is in the include section of EVERY SINGLE source file in the ENTIRE PROJECT. Gee, you're having trouble finding the reason you're getting 13 consecutive access violations when you click the "File" menu? I WONDER WHY!!!

So sure, managers have to hire good programmers, but I think when they're confronted with 50 interviews in a row with guys who can barely remember how to write a "hello world" program let alone write a worker thread, they just assume that all the candidates are like that and give up.

I got a kick out of this essay, by a Microsoft MVP:
http://www.flounder.com/bricks.htm

Goes to show you the quality of labour these days. It's really sad, and yes, part of the problem lies with lazy short-sighted managers, but a MUCH bigger part of the problem lies with the crummy world of academia.

And code is NOT either "decent" or "not decent", there are certainly gray areas. Sometimes you have to cut corners to meet deadlines, but knowing which corners to cut is an art too! Some pieces you can afford to hack together, others you can't. Cut every corner and you'll eventually wind up going in circles.



You talk like there's a wealth of real programming talent out there which is total bullshit. It sometimes takes companies up to 6 months to find a really good programmer that can contribute to their team as a whole.

And to blame it on the way the schools teach is a load of crap too... The best schools in the world still pump out shitty programmers. Are you trying to tell me MIT, Berkeley, Stanford, Carnegie Mellon... have shitty educations? Or aren't doing things right? They still produce alot of junk along with the good programmers that make it through.

Being a good programmer is 50% passion, 25% patience, and 25% knowledge. Alot of the people who graduate with a CS education just lack the passion.

-Your Mother


Posted by rabbitjoker on Nov-13-2004 14:32:

quote:
Originally posted by Your Mother
Alot of the people ... just lack the passion.


Posted by Your Mother on Nov-13-2004 16:59:

quote:
Originally posted by DigiNut

Form5->ListBox3->Items->Objects[atoi(substr(Form1->Edit2->Text, 4, strlen(Form1->Edit2->Text)))]->QR = App_QR1 + lfunc(x - 5, y+z) + 3,

where App_QR1 is declared as a global variable in a unit called "misc.h", which consists of about 100 different totally unrelated variables and functions with equally cryptic names like "pkStFrmShMLA" and "int getMRblkT(PChar *P)" and is in the include section of EVERY SINGLE source file in the ENTIRE PROJECT. Gee, you're having trouble finding the reason you're getting 13 consecutive access violations when you click the "File" menu? I WONDER WHY!!!


When shit like this happens, you are just as much to blame. Where is your testing infrastructure and test code to make sure problems like this don't occur. Why wasn't the developer educated about the importance of writing test classes to exercise this code. Why isn't the developer reprimanded for things like this. Why wasn't it code reviewed? Even if this is a fabricated example, you've obviously seem similar real examples. If so, then why didn't you explain to the person who wrote it what is wrong with it?

-Your Mother


Posted by loca on Nov-13-2004 18:48:

quote:

Microsoft probing reported flaws in Windows XP SP2

Microsoft Corp. yesterday said it is investigating claims that several new vulnerabilities have been found in Windows XP Service Pack 2 by security firm Finjan Software Inc. in San Jose. Finjan on Tuesday announced that it had found as many as 10 "serious" flaws in SP2.

...

"By exploiting all vulnerabilities discovered in SP2 by Finjan, attackers can silently and remotely take over an SP2 machine when the user simply browses a Web page," the company said in a statement.



Full article here

Once again proving that IE's marriage into the OS leaves windows like (to quote someone else) "a piece of swiss cheese".


Posted by rabbitjoker on Nov-13-2004 20:35:

quote:
Originally posted by LoCa
Once again proving that IE's marriage into the OS leaves windows like (to quote someone else) "a piece of swiss cheese".


Selective quoting, huh?

You left out this part:

"Our early analysis indicates that Finjan's claims are potentially misleading and possibly erroneous regarding the breadth and severity of the alleged vulnerabilities in Windows XP SP2," the Microsoft statement said.

If any valid vulnerability is found in Windows XP SP2, Microsoft said it will take "immediate and appropriate action to help protect customers."


Posted by loca on Nov-13-2004 23:09:

quote:
Originally posted by rabbitjoker
Selective quoting, huh?

You left out this part:

"Our early analysis indicates that Finjan's claims are potentially misleading and possibly erroneous regarding the breadth and severity of the alleged vulnerabilities in Windows XP SP2," the Microsoft statement said.

If any valid vulnerability is found in Windows XP SP2, Microsoft said it will take "immediate and appropriate action to help protect customers."


I posted the link to the article didn't i?
And of course MS is going to deny it right now. Are you kidding me? With FireFox having come out not more than a week ago, they're not going to go out and say that their browser is the cause for XP SP2 users having to fear their pc being taken over. God knows i'd deny it too if i were them.


Posted by DigiNut on Nov-14-2004 00:54:

quote:
Originally posted by Your Mother
You talk like there's a wealth of real programming talent out there which is total bullshit. It sometimes takes companies up to 6 months to find a really good programmer that can contribute to their team as a whole.

And to blame it on the way the schools teach is a load of crap too... The best schools in the world still pump out shitty programmers. Are you trying to tell me MIT, Berkeley, Stanford, Carnegie Mellon... have shitty educations? Or aren't doing things right? They still produce alot of junk along with the good programmers that make it through.

Being a good programmer is 50% passion, 25% patience, and 25% knowledge. Alot of the people who graduate with a CS education just lack the passion.

-Your Mother

The best schools in the world like MIT pump out a *few* shitty programmers, but don't try to tell me that they pump out as many shitty programmers as Queen's or Ryerson (sorry Rye kids, but it's the truth).

But if you're trying to corner me here, don't bother, because I'll come right out and say it: the problem is with the entire computer science program in general, no matter which school it's at. The fact of the matter is that programming is 50% engineering and 50% art, and 0% science. And being a good programmer is 50% passion, 25% patience, 5% knowledge, and 20% problem solving skills (i.e. the ability to REASON through complex tasks). It's taught wrong almost everywhere, as if textbook knowledge could somehow help a person to write real-world programs. Textbook knowledge is great for giving people *ideas* but testing in university should concentrate on solving UNFAMILIAR problems with logic and creativity, not parrotting information they read in a book.

And this:
quote:
When shit like this happens, you are just as much to blame. Where is your testing infrastructure and test code to make sure problems like this don't occur. Why wasn't the developer educated about the importance of writing test classes to exercise this code. Why isn't the developer reprimanded for things like this. Why wasn't it code reviewed? Even if this is a fabricated example, you've obviously seem similar real examples. If so, then why didn't you explain to the person who wrote it what is wrong with it?

You really like getting on my case just for the sake of getting on my case, don't you?

#1. I NEVER SAID that the company and its management was not at fault. I said that the programmers deserve equal blame, that's all.

#2. Yes, I have experienced code like this:

Once was during a 1-month work term where I took 3 days to write a VBA script in Excel that parsed the same information out of a series of text/XL files as the VB program written by their two $60-an-hour Russian programmers which had been under construction for 6 months, still wasn't finished, and was buggy as hell. In hindsight, 3 days was a pretty long time, but that was 5 years ago and I was inexperienced. I was a low-level student intern. I told the managers that the situation was ridiculous. I showed my code to the programmers and told them to copy and paste if they really wanted to. But ultimately nothing got changed.

The department was a reporting department, not a programming department - they didn't have code reviews, or knowledgeable managers. I did what I could, but honestly, how can you blame totally non-technical managerial types for not realizing that their programmers suck? You seem to have forgotten that many programmers are not necessarily hired by software companies. They're hired internally by departments who need custom software but don't know anything about software. These programmers should never have gotten their degrees if they couldn't figure out how to parse a text file. These departments are *essentially* subcontracting, and if I hire a building contractor to put a deck in my backyard, I expect them to know what the fuck they're doing - I don't have the know-how to review their plans myself and I definitely don't have the time or patience to send the plans out to 5 other contractors and pay them to make sure the plans are OK.

That was the only time I saw it at a workplace, because all of my other projects have involved me being the sole or lead developer. The main other times I see it are people asking me on MSN or by e-mail what's wrong with their code, and I essentially have to respond to them, "EVERYTHING!" And sure, I try to explain to them why it would take a miracle for their code to run, but the problem is, these people don't have the REASONING SKILLS to understand what I'm telling them. They don't understand why I snicker at the GOTO statement on line 253. And they think 1000 lines of code is a HUGE project. They went to university, learned the SYNTAX of some particular language and a few algorithms out of a textbook, and got their degree. And the worst part of it is, a lot of these programmers think they are "l33t", they think they're the shit because they're able to write a crummy virus/IRC bot in Visual Basic or write a "Hello world, the current time is 8:00 PM" ASP script for their l33t GeoCities web page.

Don't get me started on the quality of programmers. It IS the fault of the universities, and if you doubt that, you need only look at Japan. Their productivity standard is what, something like 200 lines of code per hour with full documentation? I can't even manage that on some days. People are taught differently there, it's as simple as that.

Obviously it's the fault of the companies too, and you don't need to twist my arm to get me to see that. There's no excuse for an actual software company having dumbass non-technical managers. There's no excuse for not having code reviews. There's no excuse for not firing programmers who are not only unproductive but actually hurt the productivity of the rest of their team by writing code that's just going to have be scrapped and rewritten later. And there's no excuse for hiring these people in the first place without making sure they understand simple concepts, like What Is A Pointer and What Are The Fundamental OOP Principles (most grads can wrap their minds around inheritance, but almost all of them have serious trouble with the concept of encapsulation).

But does that make it 100% the fault of the companies that hire them? No, it's still partly the fault of the programmers themselves for doing a half-assed job of teaching themselves in university, and it's still partly the fault of the universities for giving these people the legal authority to say they are "Experts" in the field when they can't do the software equivalent of making a Grilled Cheese Sandwich. I have known many CS students in the past, and I can say with the utmost certainty that the attitude of most students is "I don't care about the theory, I just want my degree" and the attitude of most universities is "The class average needs to be 65%, so figure out a way to make that happen". It's a compound problem, and more than one group is to blame.


Pages (5): « 1 2 3 4 [5]

Powered by: vBulletin
Copyright © 2000-2021, Jelsoft Enterprises Ltd.