walt wrote:
Okay, that's why I asked -- I didn't know that. But why take a year to break a secure hash when you can use a buffer overrun to gain access to ten thousand Windows machines in a few minutes ;o)
Same can be said of the hundreds of thousands of Apache installations out there. And Microsoft really works on those kind of issues, but they're not something their third party developers can work on (as far as Microsoft-code is concerned). Microsoft however can give advises to those developers about secure practices, and no doubt buffer overflow issues have been mentioned to them for several years now. It's only because of 'recent' policy change that you actually see Microsoft publishing this.
Cheers,
--
-- Thomas E. Spanjaard
[EMAIL PROTECTED]
signature.asc
Description: OpenPGP digital signature
