[SC-L] interesting presentation

from dawson engler's group: http://www.stanford.edu/~engler/softmc03-talk.pdf evaluates various checkers in various settings.

[SC-L] opinion, ACM Queue: Buffer Overrun Madness

are buffer overruns. These would be minor irritations but for the world's addiction to the weakly typed programming languages C and its derivative C++.

[SC-L] [paper] Model Checking One Million Lines of C Code

that model checking is practical and useful for detecting security weaknesses at large scale in real, legacy systems.

[SC-L] Former cybersecurity czar: Code-checking tools needed

http://www.computerworld.com/securitytopics/security/story/0,10801,97988,00.html By Grant Gross DECEMBER 02, 2004 IDG NEWS SERVICE WASHINGTON -- Software

Re: [SC-L] Managing the insider threat through code obfuscation

? the biggest threat internally isn't the one or two people per thousand who can and will do this, it's the much larger number of people who wont use exploit development techniques to access things they shouldn't. bytecode obfuscation does nothing to stop that.