3 ms·
Security problems are bugs, sure. But a different kind. Security is a non-functional requirement. In an analogy with construction, each room is a functional re
by partycoder 9y ago
Security problems are bugs, sure. But a different kind. Security is a non-functional requirement.
In an analogy with construction, each room is a functional requirement, and non-functional requirements are the materials you used to build, which can be considered some sort of quality attribute.
And just like in construction, if after building a house you are given more strict seismic requirements, fire prevention, etc... you might need to rebuild the entire house.
- dfox 9y agoLarge class of security problems are also functional bugs in the sense that valid input causes incorrect behavior or should not be accepted as valid. This includes most instances of XSS and many instances of SQLI or buffer overflows.
- lostboys67 9y agoNope the largest class of security problems are caused by the Users
- pessimizer 9y agoIs a room any more a functional requirement than security? A roof keeps the rain off, walls keep the wind out and keep things private, but rooms are more containers than requirements. And if closing a door at the right angle causes the roof to fall in, that's a failure of function.
- qznc 9y agoMy understanding of functional requirement is that it is binary. Function is either there or not. A non-functional requirement can sometimes be measured, but not in a yes or no fashion. For example, frames per second is non-functional. Things are no secure or insecure in general, thus non-functional. You can turn non-functional into function requirement if you specify a boundary. For example, a 60 frames per second requirement is functional. For security, you can require "secure under certain attacker models" to make it functional. Example: Is Signal communication secure, if you assume the attacker can only read data on the server? There is an answer and it is probably "no". That does not mean, Signal is secure in general. An attacker which can access your phone breaks the security. (It is also not really binary, because someone might find a hole somewhere in the future, but for practical purposes, we can assume the crypto holds)
- alanfranzoni 9y ago> My understanding of functional requirement is that it is binary Not so easy. 1) Very often (too often) functional requirements are poorly worded, and they leave things open to interpretation or to implied meanings. Example: "as user Foo, when authenticated in I should be able to open and modify all the documents I own, so that I can amend them". Does such user story look good? Probably; but it says nothing about the "contrasting" stories. A lot of times there won't be a story that says... "as user Foo, when non-authenticated I shouldn't be able to see any document by anybody". or "as user Foo, I should be able to see and modify my documents and only my documents" so if a non-authenticated user or a different user has access to your docs, you aren't probably breaking a functional requirements, but it's probably not how the system was meant to behave by most stakeholders. 2) Very often the functional requirements are OK for the sweet spot, but break on corner cases; so many people just won't notice what's wrong.
- deleted 9y ago[deleted]
- provost 9y ago> Things are no secure or insecure in general, thus non-functional. I would disagree with this assertion. A really common phrase in the infosec community is that "Security is not binary"
- fusiongyro 9y agoAre you literate? Go back and reread the first sentence of the comment you are replying to.
- partycoder 9y agoThere are varying degrees of precipitation and wind speed that a roof can support. Those can vary and can be specified as requirements as well.