3 ms·
> Vulnerabilities happen from wrong function calls, yes, but also through using the wrong types of calls for the particular purpose. Which is detectable throug
by SomeStupidPoint 9y ago
> Vulnerabilities happen from wrong function calls, yes, but also through using the wrong types of calls for the particular purpose.
Which is detectable through static analysis of the type signatures -- at least to the point of ensuring that a threat assessment document includes a section on what they did there.
That's my point -- why doesn't my IDE auto-generate a template threat assessment report to share with security as part of my code review process? ...why does it rely on me understanding the possible threats, rather than clearly expressing what data I use and letting security set flags on what I should watch?
That sounds like a lack of tooling -- because there's not a technical reason.
- IncRnd 9y ago>> Vulnerabilities happen from wrong function calls, yes, but also through using the wrong types of calls for the particular purpose. > Which is detectable through static analysis of the type signatures -- at least to the point of ensuring that a threat assessment document includes a section on what they did there. I don't think you read prior to replying. Type signatures are orthogonal to the purpose of code. Just because a call is made to XTS don't convey that disk encryption is used. That is the issue that you glossed over. An IDE only has enough information to threat model an application correctly if it had enough information to write the application in the first place.