Quoting ljknews <ljkn...@mac.com>: > At 5:49 PM -0500 5/6/09, Brad Andrews wrote: > >> Try a few of the PC-Lint bugs, if you ever wrote C/C++ code. >> They can be really hard to figure out, > > And yet people keep choosing those programming languages.
They offer quite a bit of power in exchange for the danger. A steak knife can be dangerous, but I would greatly prefer it over a butter knife if I am eating a steak. :) I also believe some Java security flaws can be just as difficult to figure out. Some aren't, but why would secure code review be such a challenge if it was so easy? Brad _______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________