While not disagreeing with anything Paul wrote, I wanted to make some
comments about the state of formal verification technology.
Quoting [EMAIL PROTECTED]:
The Orange Book explicitly wanted to include only requirements that
had been shown to be feasible at the time the criteria were written
FYI, interesting article on sandboxing of applications, with quotes
from a few SC-L regulars. Enjoy!
http://reddevnews.com/features/article.aspx?editorialsid=2386
Cheers,
Ken
-
Kenneth R. van Wyk
SC-L Moderator
KRvW Associates, LLC
http://www.KRvW.com
smime.p7s
Description: S/MIME