Hi, all!

On Tue, Aug 22, 2006 at 01:28:13PM -0400, Chris Blask wrote:

> o "You don't know what you don't know."

Which leads directly to Marcus' well known rant about positive
security models.

> You cannot make even any *one* Thing in security "perfect"

You can. You can code an HTTP server that does nothing but
serve static documents in (my guess) less than 1000 lines of
C and you can prove a program of this size to be correct.

Customers tend to favour "off the shelf solutions", though.
IIRC this once led to another one of Marcus' rants ;-)

punkt.de GmbH Internet - Dienstleistungen - Beratung
Vorholzstr. 25 Tel. 0721 9109 -0 Fax: -100
76137 Karlsruhe http://punkt.de
firewall-wizards mailing list