4 ms·
Windows programmers are familiar with StrSafe.h, https://en.wikipedia.org/wiki/Strsafe.h https://en.wikipedia.org/wiki/Strsafe.h and https://github.com/dotnet/c
by dblock 7y ago
Windows programmers are familiar with StrSafe.h, https://en.wikipedia.org/wiki/Strsafe.h https://en.wikipedia.org/wiki/Strsafe.h and https://github.com/dotnet/coreclr/blob/master/src/pal/inc/strsafe.h https://github.com/dotnet/coreclr/blob/master/src/pal/inc/st... which go a lot further.
Also found https://github.com/mubix/netview/blob/master/banned.h https://github.com/mubix/netview/blob/master/banned.h on Github with a better list.
- WalterGR 7y agoIIRC, StrSafe.h - and much more - came from the development of the Microsoft Security Development Lifecycle (SDL). Code Red was the wake-up call for Microsoft and in February 2002, based on a memo from Bill Gates that first coined the phrase "Trustworthy Computing," Microsoft shutdown Windows development for the first time ever to get a handle on the security issues the products were facing. https://www.itprotoday.com/strategy/story-behind-microsoft-security-development-lifecycle https://www.itprotoday.com/strategy/story-behind-microsoft-s...
- pjmlp 7y agoAdditionally we get to enjoy bounds checked arrays(std::...), and iterators on debug builds, with possibility to selectively enable them in release mode. While Windows by all means still has its security issues, the toolchain is much more security oriented than most FOSS alternatives thanks to the Windows XP wake up call. Android and ChromeOS are probably the mostly locked down alternatives on the FOSS space.
- uncletaco 7y agoTangential but the fact that I had to open up the machine and remove a screw to completely replace ChromeOS with linux bothers the fuck out of me.
- pjmlp 7y agoWell, you can see how they are locking it down with containers sandboxing from an IO talk, by making use of gVisor and a Rust based containers. "Linux for Chromebooks: Secure Development" https://www.youtube.com/watch?v=pRlh8LX4kQI https://www.youtube.com/watch?v=pRlh8LX4kQI
- floatboth 7y agoThat's how secure boot should work. Replacing the root of trust should require serious physical access that can be tamper-evident. And yeah, out of the box, the trust is with the vendor — who else would be trusted in a device that doesn't have an owner yet?
- uncletaco 7y agoI never thought of that. And it makes a lot more sense in that context.
- saagarjha 7y agoMy Chromebook just made me enable developer mode.
- toast0 7y agoDeveloper mode lets you boot another OS, but leaves you open to accidentally wiping your drive if you hit the wrong button on boot. Replacing the firmware is a good idea, you do need to remove the write protect screw, but that really makes sense for some note of physical security.
- saagarjha 7y agoMultiple wrong buttons in a specific sequence, at least on my Chromebook.
- temac 7y agoI don't know, you can use valgrind and fsanitize and ibstdc++ __gnu_debug:: containers or _LIBCPP_DEBUG under libc++. Just know your tools...
- pjmlp 7y agoThe big difference is that on MSVC++ those debugging features are enabled by default on debug builds. File->New C++ Project, already there. Available to everyone, regardless of their compiler switch mastery level. Defaults matter.
- yesmar 7y agoYou can find an up-to-date, authoritative version of banned.h here: https://github.com/x509cert/banned https://github.com/x509cert/banned