 |
|
|
|
 |
spinor
Junior tranceaddict
Registered: Nov 2004
Location: Mtl
|
|
|
Nov-12-2004 05:38
|
|
|
 |
 |
loca
the vibe raider

Registered: Apr 2003
Location: Oz
|
|
|
| quote: | Originally posted by rabbitjoker
Just one day after the Mozilla Foundation released Firefox 1.0, the group has revealed that prior versions of the open-source browser pose a security threat to users. According to information released by Mozilla, multiple security holes have been plugged in all beta versions of Firefox to correct flaws that could lead to security bypass, exposure of sensitive data, privilege escalation and DoS (denial of service) attacks.
Research firm Secunia rates the vulnerabilities as "moderately critical". Mozilla warned that successful exploits could also detect the presence of local files, spoof the file download dialog, or gain escalated privileges on vulnerable machines
------------------------------------
People bitch and moan about MS security this, MS security that...
Face it folks - an computer that is connected to another via any means is vulnerable.
IMO - There is no reason to change browsers simply for security purposes (if you have XP-SP2 installed). |
Few things, the reason they're finding tons of security exploit is because mozilla is actually rewarding people who find them, so people are going in there and finding them.
Also, those are moderately critical vulnarablities, as opposed to extremely critical, which surface in IE fairly often. In addition, i might add that these vulnerablities surfaced in previous versions of mozilla, in other words, the beta versions. IE gets critical vulnerabilties in versions that are out of beta and on the market.
___________________
Whatever it may take I keep on trying.
|
|
Nov-12-2004 20:17
|
|
|
 |
 |
Your Mother
Supreme tranceaddict
Registered: Jan 2004
Location: NYC -- Wall Street MOFO
|
|
|
| quote: | Originally posted by DigiNut
Oh no doubt about that, and that's why I peg the blame at 50/50. You have to be fair though, it's really hard for management to make good hiring decisions when colleges and universities are churning out 50,000 graduates a year who write code like
Form5->ListBox3->Items->Objects[atoi(substr(Form1->Edit2->Text, 4, strlen(Form1->Edit2->Text)))]->QR = App_QR1 + lfunc(x - 5, y+z) + 3,
where App_QR1 is declared as a global variable in a unit called "misc.h", which consists of about 100 different totally unrelated variables and functions with equally cryptic names like "pkStFrmShMLA" and "int getMRblkT(PChar *P)" and is in the include section of EVERY SINGLE source file in the ENTIRE PROJECT. Gee, you're having trouble finding the reason you're getting 13 consecutive access violations when you click the "File" menu? I WONDER WHY!!!
So sure, managers have to hire good programmers, but I think when they're confronted with 50 interviews in a row with guys who can barely remember how to write a "hello world" program let alone write a worker thread, they just assume that all the candidates are like that and give up.
I got a kick out of this essay, by a Microsoft MVP:
http://www.flounder.com/bricks.htm
Goes to show you the quality of labour these days. It's really sad, and yes, part of the problem lies with lazy short-sighted managers, but a MUCH bigger part of the problem lies with the crummy world of academia.
And code is NOT either "decent" or "not decent", there are certainly gray areas. Sometimes you have to cut corners to meet deadlines, but knowing which corners to cut is an art too! Some pieces you can afford to hack together, others you can't. Cut every corner and you'll eventually wind up going in circles. |
You talk like there's a wealth of real programming talent out there which is total bullshit. It sometimes takes companies up to 6 months to find a really good programmer that can contribute to their team as a whole.
And to blame it on the way the schools teach is a load of crap too... The best schools in the world still pump out shitty programmers. Are you trying to tell me MIT, Berkeley, Stanford, Carnegie Mellon... have shitty educations? Or aren't doing things right? They still produce alot of junk along with the good programmers that make it through.
Being a good programmer is 50% passion, 25% patience, and 25% knowledge. Alot of the people who graduate with a CS education just lack the passion.
-Your Mother
|
|
Nov-13-2004 14:27
|
|
|
 |
 |
Your Mother
Supreme tranceaddict
Registered: Jan 2004
Location: NYC -- Wall Street MOFO
|
|
|
| quote: | Originally posted by DigiNut
Form5->ListBox3->Items->Objects[atoi(substr(Form1->Edit2->Text, 4, strlen(Form1->Edit2->Text)))]->QR = App_QR1 + lfunc(x - 5, y+z) + 3,
where App_QR1 is declared as a global variable in a unit called "misc.h", which consists of about 100 different totally unrelated variables and functions with equally cryptic names like "pkStFrmShMLA" and "int getMRblkT(PChar *P)" and is in the include section of EVERY SINGLE source file in the ENTIRE PROJECT. Gee, you're having trouble finding the reason you're getting 13 consecutive access violations when you click the "File" menu? I WONDER WHY!!! |
When shit like this happens, you are just as much to blame. Where is your testing infrastructure and test code to make sure problems like this don't occur. Why wasn't the developer educated about the importance of writing test classes to exercise this code. Why isn't the developer reprimanded for things like this. Why wasn't it code reviewed? Even if this is a fabricated example, you've obviously seem similar real examples. If so, then why didn't you explain to the person who wrote it what is wrong with it?
-Your Mother
|
|
Nov-13-2004 16:59
|
|
|
 |
 |
|  |
All times are GMT. The time now is 18:59.
Forum Rules:
You may not post new threads
You may not post replies
You may not edit your posts
|
HTML code is ON
vB code is ON
[IMG] code is ON
|
|
|
|
|
|
Contact Us - return to tranceaddict
Powered by: Trance Music & vBulletin Forums
Copyright ©2000-2026, Jelsoft Enterprises Ltd.
Privacy Statement / DMCA
|