
Yesterday's keynote at the 28th Chaos Computer Congress (28C3) by Meredith Patterson on "The Science of Insecurity" was a tour-de-force explanation of the formal linguistics and computer science that explain why software becomes insecure, and an explanation of how security can be dramatically increased. What's more, Patterson's slides were outstanding Rageface-meets-Occupy memeshopping. Both the video and the slides are online already.
Hard-to-parse protocols require complex parsers. Complex, buggy parsers become weird machines for exploits to run on. Help stop weird machines today: Make your protocol context-free or regular!
Protocols and file formats that are Turing-complete input languages are the worst offenders, because for them, recognizing valid or expected inputs is UNDECIDABLE: no amount of programming or testing will get it right.
A Turing-complete input language destroys security for generations of users. Avoid Turing-complete input languages!
Patterson's co-authors on the paper were her late husband, Len Sassaman (eulogized here) and Sergey Bratus.
LANGSEC explained in a few slogans
I write books. My latest is a YA science fiction novel called Homeland (it's the sequel to Little Brother). More books: Rapture of the Nerds (a novel, with Charlie Stross); With a Little Help (short stories); and The Great Big Beautiful Tomorrow (novella and nonfic). I speak all over the place and I tweet and tumble, too.
MORE: ccc • computer science • Funny • happy mutants • linguistics • occupy • Science • security • web theory
More at Boing Boing
-
http://twitter.com/LennStar_de LennStar
-
tw1515tw
-
http://twitter.com/jmtd Jonathan Dowland
-
KWillets
-
-
http://www.mrericsir.com MrEricSir
-
http://www.pappp.net/ PAPPP
-
http://twitter.com/maradydd Meredith L Patterson
-
martian_bob
-
-
-
-
mypalmike
-
http://twitter.com/maradydd Meredith L Patterson
-
Lizanne Connelly
-
http://twitter.com/timClicks Tim McNamara
-
-
http://twitter.com/alexstapleton Alex Stapleton
-
digi_owl
-
-
-
scruss
-
digi_owl
-
-
Spinkter
-
http://twitter.com/alexstapleton Alex Stapleton
-
-
billstewart
-
-
asuffield
-
http://twitter.com/zeroanaphora แอ็ะปปี้
-
http://twitter.com/maradydd Meredith L Patterson
-
bardfinn
-
PrettyBoyTim
-
digi_owl
-
-
digi_owl
-
-
-
http://twitter.com/maradydd Meredith L Patterson
-
http://twitter.com/Kythera Kythera of Anevern
-
-
http://noctilucent-studios.blogspot.com/ Noctilucent Studios
-
Stooge
-
http://noctilucent-studios.blogspot.com/ Noctilucent Studios
-
bardfinn
-
digi_owl
-
-
Paul Davis
-
eraserbones
-
-
-
-
Jorpho
-
http://twitter.com/groxx Groxx
-
Stooge
-
-
http://twitter.com/timClicks Tim McNamara
-
lysdexia
-
-
-
http://noctilucent-studios.blogspot.com/ Noctilucent Studios
-
s2redux
-
David Llopis
-
willu
-
http://twitter.com/timClicks Tim McNamara
-
willu
-
-
-
http://twitter.com/timClicks Tim McNamara
-
willu
-
-
DewiMorgan










Hard-to-parse protocols require complex parsers. Complex, buggy parsers become weird machines for exploits to run on. Help stop weird machines today: Make your protocol context-free or regular!
