On TechRepublic: Linux desktops have tanked: Get over it
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 20 of 24:
Next »
« Previous
Nice thought, but irrelevant
The "thousands of eyes" is irrelevant to this defect.

Why? Because this isn't something it's likely that developers would have ever spotted. This type of problem is a problem of architecture and design, not coding or implementation.

It took a mathematician to spot the possibility and devise the tests. The original designers, given a flash of foresight to the scope and breadth of the modern internet (which they can be forgiven for failing to foresee) might have double-checked their algorithms to make sure that sequence-numbers weren't guessable; but with 20:20 hindsight, all we can do is guess at *that*.

And actually, it can be argued that "thousands of eyes" were part of the solution, here. People have been looking at the TCP stack for many years, but only now has Paul [?] Watson found this defect. He found it, because he was able to have unfettered access to the stack. The myriad commercial developers who've worked on the TCP stack over the decades haven't spotted it; it's logical to assume that the probability of this ever having been found would *decrease* if it were a close-source, proprietary application....
Posted by: escoles@...   Posted on: 04/21/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Why dont we blame Microsoft for this one too  mojoman_x@... | 04/20/04
Some idiot will try, stay tuned...  No_Ax_to_Grind | 04/20/04
Hmmm....  bchesmer | 04/20/04
For THIS TCP issue MS  michael-t | 04/20/04
Microsoft users the BSD TCP/IP network stack.  B.O.F.H. | 04/20/04
That's nice to know  toadlife | 04/20/04
OSX is...  B.O.F.H. | 04/21/04
BSD Stack and Microsoft  toadlife | 04/21/04
Methinks thou dost protest...too much  escoles@... | 04/21/04
What's sauce for the goose  John Dulles | 04/21/04
Go ahead...  kray_z | 04/20/04
Most of us are safe  KTLA | 04/20/04
Are you a Mike Cox wannabe?  d_jedi | 04/21/04
WRONG!  jrbeaman | 04/21/04
[retroactive sarcasm alert]  escoles@... | 04/21/04
Get over yourself  drichards1953 | 04/21/04
Dumb Post of the Day  ShadeTree | 04/21/04
Not to mention...  rapson | 04/21/04
Time after time  ShadeTree | 04/21/04
Nice thought, but irrelevant  escoles@... | 04/21/04
It is just as likely...  ShadeTree | 04/21/04
SSafer or more prone: Both, but ultimately safer  escoles@... | 04/21/04
Unfortunately the history of ...  ShadeTree | 04/21/04
But then, history is only *what's written* (Or, 'Security by Ignorance')  escoles@... | 04/21/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here