3 ms·
That introduction is not an irrelevant link. It is a link to a bug that admittedly everyone was talking about at the time, but also a bug that was in an open-so
by pascal_cuoq 12y ago
That introduction is not an irrelevant link. It is a link to a bug that admittedly everyone was talking about at the time, but also a bug that was in an open-source library, and that would have been found if the method that was being applied to PolarSSL had been applied to Apple's SSL implementation.
Seriously, one step of the method is “look at every snippet of code that was not visited by the analyzer and explain why it wasn't visited”. One particular usage of a multi-purpose library may always leave you with seemingly unreachable code (that is in fact only useful for other usages of the library), so the presence of such unreachable code cannot be considered a bug, but verifying a library in the way one usage of PolarSSL was verified means each instance of unreachable code is justified.
(The “goto fail” bug could have been found in many other ways, and I admit that makes my using it as an introduction slightly tangential, but it is not my job to advertise all these other ways—some of which are already recognized and easy to apply by a company the size of Apple.)