Black Hat Briefings, Japan 2006 [Audio] Presentations from the security conference

Paul Bohm: Taming Bugs: The art and science of writing secure code (English)

June 4, 2006

If you give a thousand programmers the same task and the same tools, chances are a lot of the resulting programs will break on the same input. Writing secure code isn't just about avoiding bugs. Programming is as much about People as it is about Code and Techniques. This talk will look deeper, beyond the common bug classes, and provide explanations for why programmers are prone to making certain mistakes. New strategies for taming common bug sources will be presented. Among these are TypedStrings for dealing with Injection Bugs (XSS, SQL, ...), and Path Normalization to deal with Path Traversal. neither hosts nor alters podcast files. All content © its respective owners.