Very interesting counterpoint to the recent Symantec paper about the TCP/IP stack in Windows Vista.

  1. Valer BOCAN says:

    I have just finished reading the mentioned paper. While printing it for offline reading I thought to myself that Vista may be plagued with bugs and the Symantec folks did a good job and uncovered them for Microsoft’s (and our) benefit. To my surprise, the paper seemed to reveal a steady growth in quality of the implementation across the beta builds, which is very good, in spite of some acid remarks on authors’ part.

    Although we’re some 6-7 months before the release date and I won’t expect a mature networking stack in Vista right away, however I do believe that the Trustworthy Computing Initiative finally pays off. Michael has some of the merit here.

  2. nksingh says:

    Any comments on the following: http://developer.apple.com/documentation/Security/Conceptual/SecureCodingGuide/index.html?

    Just looking at the MSDN site, there is some stuff in http://msdn.microsoft.com/security/securecode/default.aspx, but it is not so complete.  Your book is great, but not everyone has it.  The msdn site talks more about security features than secure coding practices.

    -A t- who attended your SDL talk.


